Back to skill

Security audit

Clawnema

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its virtual-cinema purpose, but its wallet payment path is under-scoped and should be reviewed before installation.

Install only if you trust the Clawnema backend and the awal wallet toolchain, and avoid running generated payment commands unless the amount, network, and recipient are independently verified. The package should ideally pin the wallet CLI version, validate backend payment fields strictly, refuse unknown wallet addresses, and move session tokens out of URLs before normal use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
clawnema.ts:135
Finding

Backend-Controlled Values Are Interpolated into a Wallet Payment Command

Content
View full analysis
\`\n\n` + `The TX hash will be in the JSON output (look for \`transactionHash\` or \`hash\` field).`; ``` ### Technical Analysis The wallet address and ticket price originate from the backend `/now-showing` response. That response is cast to `any`, and the `Theater` interface supplies compile-time types only; it does not validate the received values at runtime. Both values are inserted directly and without quoting into a shell command: ```bash npx awal@latest send --json ``` A compromised or malicious backend could return shell metacharacters in either field. If an Agent or user executes the generated command through a shell, those metacharacters could alter the command or append another command. The wallet allowlist check is not enforced. When th ...[truncated 1433 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Wallet Operations Use an Unpinned Runtime Package

Content
View full analysis
npx awal@latest auth verify ``` ```md npx awal@latest balance ``` ```ts return `💳 **Payment required** for "${theater.title}" (${theater.ticket_price_usdc} USDC)\n\n` + `**Recipient:** \`${walletAddr}\`${trusted ? ' (verified Clawnema wallet)' : ''}\n` + warning + `\nConfirm with your owner before paying. Then run:\n` + `\`\`\`\nnpx awal@latest send ${theater.ticket_price_usdc} ${walletAddr} --json\n\`\`\`\n\n` + ``` ### Technical Analysis Every wallet operation uses `npx awal@latest`. The `latest` tag is mutable and can resolve to different package content after the Skill has been audited. `npx` can download and execute the selected package at runtime. This is particularly sensitive because the package is used for wallet authentication, balance inspection, address management, and USDC transfers. An upstream account compromise, malicious release, registry compromise, or unsafe future update could therefore introduce code that runs locally in a financially sensitive context. The project does not pin `awal` in `package.json`, and no lockfile or integrity value for the runtime wallet package is present in the audited files. ### Attack Path 1. An attacker compromises the package publisher, package registry, or a future release associated with the `latest` tag. 2. The Agent invokes an allowed command such as `npx awal@latest auth ...` or `npx awal@latest send ...`. 3. `npx` resolves and downloads the cha ...[truncated 808 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
clawnema.ts:204
Finding

Session Tokens Are Exposed in Request URLs

Content
View full analysis
Remediation
View remediation
`. 2. Alternatively, place credentials in a protected POST body where appropriate, but prefer a standard authorization header. 3. Never include session credentials in paths or query parameters. 4. Validate `CLAWNEMA_BACKEND_URL` during initialization and reject any URL that is not HTTPS, except for explicitly isolated local development. 5. Configure backend and proxy logging to redact authorization data. 6. Use short-lived, narrowly scoped tokens and revoke them reliably when a user leaves a theater. 7. Await and validate the `/leave` response so revocation failures are not silently ignored. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
clawnema.ts:474
Finding

Unvalidated Notification Configuration Is Inserted into a Suggested Shell Command

Content
View full analysis
"\``; } ``` ### Technical Analysis `OWNER_NOTIFY` comes from Skill configuration and is inserted into a shell command without validation, quoting, or escaping. A value containing spaces, shell metacharacters, command substitution, or additional options could change the meaning of the command. The implementation returns the command as text rather than executing it directly. Exploitation therefore depends on the Agent or owner following the instruction through a shell-capable tool. This makes the risk lower than direct command execution, but the generated instruction still crosses a trust boundary and is intended to be acted upon. ### Attack Path 1. An attacker or compromised configuration source changes `OWNER_NOTIFY` to a value containing shell syntax or malicious command-line options. 2. The Agent invokes `summarize` after watching content. 3. The summary embeds the malicious value in the suggested `openclaw message send` command. 4. The Agent or owner executes the generated command in a shell. 5. The injected syntax executes additional commands or redirects the digest to an unintended destination. ### Impact Assessment If the suggested command is executed in a shell, malicious syntax could run with that shell's privileges. Less severe manipulation could redirect viewing summaries to an attacker-controlled channel or modify command options. The implementation itself does not automatically execute this command, and the audited allowed-tool list only expressly grants `awal` commands. Exploitation consequently requires a separate shell exec ...[truncated 43 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (23)

Lp1

High
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill performs multiple outbound network requests via fetch() to a configurable backend and stream/comment endpoints, but the finding indicates this capability is not declared in permissions. Undeclared network access is dangerous because it can bypass expected agent policy review and allow exfiltration, remote instruction retrieval, or unapproved transactions against external services.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · clawnema.ts (reported line 497)May include surrounding context.

ts
} catch {}
  }

  // Clear state
  state.sessionToken = null;
  state.currentTheater = null;
  state.theaterTitle = null;

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · clawnema.ts (reported line 583)May include surrounding context.

ts
return output + buyResult;
  }

  // If payment is needed (non-dev mode), return instructions for the agent
  if (buyResult.includes('Payment required')) {
    return output + buyResult + '\n\nAfter paying, run: `go-to-movies ' +
      (preferredTheater || theater.id) + ' ' + sceneCount + '` again.';

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · clawnema.ts (reported line 623)May include surrounding context.

ts
* Reads configuration from skills.env (if available) or skill config.
 */
export function init(skills: any): void {
  // Read config: skills.env is the primary source (set by OpenClaw runtime from .env files)
  const cfg = skills.env || skills.config || {};
  BACKEND_URL = cfg.CLAWNEMA_BACKEND_URL || 'https://clawnema-backend-production.up.railway.app';
  AGENT_ID = cfg.AGENT_ID || 'openclaw-agent';

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The manifest's allowed-tools explicitly permit multiple Bash(npx awal@latest ...) invocations. Because allowed-tools define what the agent may execute, using @latest here creates a direct supply-chain execution path inside a wallet-enabled skill, increasing the chance of code execution leading to fund loss or credential compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says the skill should be used when asked to 'watch a movie, go to cinema, or experience a livestream,' which are broad everyday phrases likely to match casual user requests. Because the skill can initiate wallet-related flows and external network interactions, accidental invocation could pressure the agent into unnecessary payment or auth steps.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill allows execution of npx awal@latest ... commands, which fetch and run the latest package version at runtime rather than a fixed, reviewed release. Because this skill is authorized to inspect wallet state, authenticate, and send USDC, a compromised or malicious upstream package update could directly lead to credential theft or unauthorized fund movement.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guidance instructs the agent to use the tool whenever a user asks to 'watch a movie', 'go to the cinema', or 'check out a stream', which are ambiguous triggers. In a skill that can connect to a backend, authenticate a wallet, and facilitate USDC transfers, vague activation language raises the risk of unintended or premature engagement with sensitive operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The documented payment flow tells the agent to execute npx awal@latest send after receiving a wallet address from a backend API. Using @latest means the command behavior can change without review, which is especially dangerous in a payment path where malicious code could alter recipients, exfiltrate wallet data, or submit unintended transactions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The prerequisite command npx awal@latest status still executes unpinned remote code. Even though it is read-oriented, runtime package substitution could be abused to fingerprint the environment, exfiltrate authentication state, or mislead the agent about wallet status before later payment steps.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The login flow uses npx awal@latest auth login <email>, which executes mutable third-party code during authentication. If the upstream package is compromised, it could harvest owner email addresses, intercept auth flows, or capture tokens/OTP-related state used to control the wallet.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The OTP verification step uses npx awal@latest auth verify <flowId> <otp-code>, which runs unpinned code while handling a highly sensitive one-time code. A malicious package update could capture OTPs and take over wallet access, enabling subsequent unauthorized transfers.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

npx awal show is referenced without any version pinning, so even the funding UI path depends on mutable code fetched at execution time. While less directly dangerous than send, it can still misdirect users to malicious funding flows or collect sensitive wallet metadata.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill repeats the use of npx awal@latest in operational instructions, reinforcing a pattern of executing unreviewed latest-version wallet tooling. In this skill's context, that is materially riskier because the toolchain can authorize blockchain payments and interact with wallet state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs the agent to use npx awal@latest send, which resolves the latest package version at execution time rather than a pinned, reviewed version. This creates a supply-chain risk: a compromised or malicious upstream release could execute unexpected code or alter payment behavior when the tool is invoked.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This payment instruction again references npx awal@latest send, causing unpinned dependency execution during a funds-transfer workflow. In the context of a payment skill, dynamic resolution is especially risky because a malicious update could redirect funds, capture wallet data, or manipulate transaction output.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The repeated use of npx awal@latest propagates the same supply-chain exposure across the workflow, increasing the chance the agent will execute an unreviewed package. Because the output of that tool is then trusted for tx_hash, compromise could influence the purchase flow end to end.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill automatically posts generated comments to the backend during watchSession without obtaining explicit confirmation at the moment of transmission. This can leak agent identity, behavioral data, and generated content to a third party, and may surprise users who expected passive viewing only.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The command list includes very broad triggers such as "watch" and "summarize", which are common verbs likely to appear in many unrelated user requests. In a skill that can initiate livestream/movie actions, payments, and reporting, this increases the chance of unintended invocation and accidental execution of sensitive behavior.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 22)May include surrounding context.

json
"license": "MIT",
  "dependencies": {},
  "devDependencies": {
    "@types/node": "^25.2.3",
    "ts-node": "^10.9.2",
    "typescript": "^5.9.3"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 23)May include surrounding context.

json
"dependencies": {},
  "devDependencies": {
    "@types/node": "^25.2.3",
    "ts-node": "^10.9.2",
    "typescript": "^5.9.3"
  },
  "openclaw": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
"devDependencies": {
    "@types/node": "^25.2.3",
    "ts-node": "^10.9.2",
    "typescript": "^5.9.3"
  },
  "openclaw": {
    "name": "clawnema",

Static analysis

No suspicious patterns detected.