T09 · Insecure Skill Coding Practices
- Location
src/sardis_openclaw/server.py:68- Finding
Caller-Controlled API Destination Exposes Bearer Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This real-money payment skill is purpose-aligned, but its packaged server can forward bearer API keys to a caller-supplied URL and execute financial actions without enforcing the declared controls.
Review carefully before installing or deploying. Use only tightly scoped Sardis API keys, do not expose the included skill server without authentication, remove caller control of API destinations, require explicit human approval for payments, bridges, card issuance, and policy changes, and pin dependencies before production use.
src/sardis_openclaw/server.py:68Caller-Controlled API Destination Exposes Bearer Credentials
src/sardis_openclaw/server.py:62Declared Skill Permissions Are Not Enforced
src/sardis_openclaw/skills/payment.py:22Payment Execution Omits Documented Policy, Approval, and Input Controls
pyproject.toml:25Security-Sensitive Dependencies Are Not Reproducibly Pinned
Although parts of the static finding are imprecise, the underlying security issue is real: the skill enables wallet-affecting payment execution while declaring no explicit permissions. In a money-moving skill, absence of clearly declared write scopes makes the operational trust boundary ambiguous and increases risk of accidental or unauthorized fund movement.
Although parts of the static finding are imprecise, the underlying security issue is real: the skill enables wallet-affecting payment execution while declaring no explicit permissions. In a money-moving skill, absence of clearly declared write scopes makes the operational trust boundary ambiguous and increases risk of accidental or unauthorized fund movement.
Although parts of the static finding are imprecise, the underlying security issue is real: the skill enables wallet-affecting payment execution while declaring no explicit permissions. In a money-moving skill, absence of clearly declared write scopes makes the operational trust boundary ambiguous and increases risk of accidental or unauthorized fund movement.
Although parts of the static finding are imprecise, the underlying security issue is real: the skill enables wallet-affecting payment execution while declaring no explicit permissions. In a money-moving skill, absence of clearly declared write scopes makes the operational trust boundary ambiguous and increases risk of accidental or unauthorized fund movement.
Although parts of the static finding are imprecise, the underlying security issue is real: the skill enables wallet-affecting payment execution while declaring no explicit permissions. In a money-moving skill, absence of clearly declared write scopes makes the operational trust boundary ambiguous and increases risk of accidental or unauthorized fund movement.
Although parts of the static finding are imprecise, the underlying security issue is real: the skill enables wallet-affecting payment execution while declaring no explicit permissions. In a money-moving skill, absence of clearly declared write scopes makes the operational trust boundary ambiguous and increases risk of accidental or unauthorized fund movement.
Although parts of the static finding are imprecise, the underlying security issue is real: the skill enables wallet-affecting payment execution while declaring no explicit permissions. In a money-moving skill, absence of clearly declared write scopes makes the operational trust boundary ambiguous and increases risk of accidental or unauthorized fund movement.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
"""Policy update skill."""
from __future__ import annotations
from typing import Any
The README advertises payment execution and card issuance but does not prominently warn that these actions can move real funds or create real-world spending instruments. In an agent-skill context, this omission increases the chance that an integrator or downstream agent treats examples as low-risk automation, leading to irreversible financial actions or unintended purchases.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
---
### 💰 [sardis-balance](./skills/sardis-balance/SKILL.md) - Read-Only Balance & Analytics
Safe, read-only skill for monitoring wallet balances and spending patterns.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
---
### 💰 [sardis-balance](./skills/sardis-balance/SKILL.md) - Read-Only Balance & Analytics
Safe, read-only skill for monitoring wallet balances and spending patterns.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
---
### 🛡️ [sardis-policy](./skills/sardis-policy/SKILL.md) - Spending Policy Management
Create and manage spending policies using natural language or structured rules.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
---
### 🛡️ [sardis-policy](./skills/sardis-policy/SKILL.md) - Spending Policy Management
Create and manage spending policies using natural language or structured rules.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
---
### 💳 [sardis-cards](./skills/sardis-cards/SKILL.md) - Virtual Card Management
Issue and manage virtual cards for real-world purchases.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
---
### 💳 [sardis-cards](./skills/sardis-cards/SKILL.md) - Virtual Card Management
Issue and manage virtual cards for real-world purchases.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Check balance (sardis-balance)
curl -X GET https://api.sardis.sh/v2/wallets/{wallet_id}/balance \
-H "Authorization: Bearer $SARDIS_API_KEY"
# Create policy (sardis-policy)
This example demonstrates a live payment POST to the production API without an adjacent warning that it can move real funds and may be irreversible. In the context of an agent payment skill, providing a production-ready command so prominently increases the risk of accidental execution, especially if copied into automation or interpreted by another system as safe example behavior.
-d '{"name": "Daily Limit", "description": "Max $500/day"}'
# Execute payment (sardis-payment)
curl -X POST https://api.sardis.sh/v2/payments \
-H "Authorization: Bearer $SARDIS_API_KEY" \
-H "Content-Type: application/json" \
-d '{"wallet_id": "wallet_123", "to": "0x...", "amount": "25.00", "token": "USDC"}'
The card issuance example triggers creation of a spending instrument through the production API and is shown without strong cautionary framing. In this context, an agent or user could treat the snippet as routine setup and unintentionally provision cards with real spending authority, creating financial exposure and follow-on fraud or misuse risk.
-d '{"wallet_id": "wallet_123", "to": "0x...", "amount": "25.00", "token": "USDC"}'
# Issue virtual card (sardis-cards)
curl -X POST https://api.sardis.sh/v2/cards \
-H "Authorization: Bearer $SARDIS_API_KEY" \
-H "Content-Type: application/json" \
-d '{"agent_id": "agent_123", "spending_limit": {"daily": "500.00"}}'
The README states policy enforcement and 'No approval flow bypassing' as principles, but it does not clearly require human approval for sensitive financial actions. In an autonomous-agent payment context, emphasizing policy-only controls can normalize unattended decision-making for money movement, which is risky if policies are broad, misconfigured, or manipulated.
All skills enforce these security principles:
1. **Policy-First**: Always check spending policy before payment
2. **Never Bypass**: No approval flow bypassing
3. **Fail Closed**: Deny by default on policy violations
4. **Audit Everything**: Complete transaction logging
5. **Read-Only When Possible**: Use `sardis-balance` for monitoring
The skill performs sensitive network operations to a payment API but declares no explicit tool scope or allowed-tools/permissions. In a payment context, missing capability scoping is dangerous because an agent can invoke outbound network actions without a clearly declared least-privilege boundary, increasing the chance of unauthorized payment, balance, or transaction-history access.
The skill requires curl, an API key, and a local config for a third-party payment service, establishing that it transmits sensitive payment-related data off-platform. External transmission is expected for this kind of integration, but in a financial skill it is inherently sensitive because wallet identifiers, transaction metadata, and authorization tokens may be exposed if invocation is not tightly controlled.
- SARDIS_API_KEY
- SARDIS_WALLET_ID
bins:
- curl
config:
- ~/.sardis/config.json
primaryEnv: SARDIS_API_KEY
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
**CRITICAL - ALWAYS ENFORCE:**
- ALWAYS check spending policy before payment execution
- NEVER bypass approval flows for transactions
- NEVER hardcode wallet addresses or private keys
- ALWAYS log transaction attempts for audit trail
- ALWAYS verify recipient address format
This documented payment execution request sends wallet ID, recipient address, amount, token, chain, and purpose to an external API under a bearer token. Because it initiates fund movement, compromise or misuse could directly cause unauthorized transfers and irreversible financial impact.
# Execute a payment (policy automatically enforced)
curl -X POST https://api.sardis.sh/v2/payments \
-H "Authorization: Bearer $SARDIS_API_KEY" \
-H "Content-Type: application/json" \
-d '{
Balance queries transmit wallet identifiers and authorization data to an external service, exposing sensitive financial metadata. While read-only, repeated or unauthorized access can leak account holdings and support targeted fraud or privacy violations.
# Get wallet balance
curl -X GET https://api.sardis.sh/v2/wallets/$SARDIS_WALLET_ID/balance \
-H "Authorization: Bearer $SARDIS_API_KEY"
Policy check requests send wallet, amount, vendor, and token information to the external API, disclosing intended purchase behavior and financial controls. Although non-executing, this still exposes sensitive intent and can aid profiling or leakage of spending constraints.
# Check if payment would be allowed WITHOUT executing
curl -X POST https://api.sardis.sh/v2/policies/check \
-H "Authorization: Bearer $SARDIS_API_KEY" \
-H "Content-Type: application/json" \
-d '{
No suspicious patterns detected.