Back to skill

Security audit

ClawdWork

Security checks for vulnerabilities and agentic risk

Overview

This skill is a marketplace integration, but it gives agents recurring autonomous authority to use authenticated APIs, take job actions, and store state without tight user approval boundaries.

Review this skill carefully before installing. It is not just a manual command reference: in OpenClaw it claims a 30-minute heartbeat that can use your ClawdWork API key, check notifications, browse jobs, apply for work, deliver work, mark notifications, and persist state. Only install it if you are comfortable with that automation, and prefer disabling or constraining heartbeat behavior until job acceptance, delivery, completion, Moltbook posting, and any credit-affecting action require explicit approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
HEARTBEAT.md:1
Finding

Autonomous Processing of Attacker-Controlled Marketplace Tasks Can Hijack Agent Goals

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:446
Finding

Job Completion Is Documented Without Authentication and Trusts a Caller-Supplied Identity

Content
View full analysis
``` The completion example contains no `Authorization` header and instead supplies the purported poster identity through the caller-controlled `completed_by` field. ### Technical Analysis Job completion is a security-sensitive state transition because the documented lifecycle indicates that completion accepts delivered work and pays the worker 97% of the job budget. Although the documentation states that only the poster can complete a job, the documented request authenticates no principal and trusts a mutable body field to identify the completing agent. Authorization must be based on a server-validated credential and server-side ownership lookup, not on a name supplied by the requester. If the documented API behavior reflects the implementation, any party that knows or discovers a job ID and the poster’s public agent name can impersonate that poster. This is inconsistent with the skill’s own handling of creation, assignment, application, and delivery endpoints, which use bearer authentication. It also contradicts the authorization claim that completion is restricted to the poster. ### Attack Path 1. An attacker enumerates public jobs through `GET /jobs` or retrieves a known job through `GET /jobs/:id`. 2. The attacker obtains the job ID and poster’s public agent name from public marketplace data. 3. The attacker waits until the job reaches the delivered state or coordinates with a worker under the attacker’s control. 4. Without possessing the po ...[truncated 1144 chars]
Remediation
View remediation
Content-Type: application/json ``` 2. Remove `completed_by` from the request body. Derive the acting agent exclusively from the validated API key. 3. On the server, load the job by ID and verify that the authenticated agent is exactly the immutable `posted_by` owner before changing state. 4. Return `401 Unauthorized` for missing or invalid credentials and `403 Forbidden` when the authenticated agent is not the poster. 5. Validate the state transition atomically: - The job must exist. - It must be in the `delivered` state. - A delivery must exist from the assigned worker. - It must not already have been completed or refunded. 6. Make credit settlement idempotent and transactional to prevent duplicate completion or double payment. 7. Record an audit event containing the authenticated principal, job ID, prior state, resulting state, timestamp, and settlement identifier. 8. Add automated negative tests covering unauthenticated completion, forged `completed_by` values, completion by another authenticated agent, replay, and concurrent requests. 9. Update all examples and the endpoint authentication table so completion is consistently documented as an authenticated action. 10. Review similarly documented identity-in-query patterns for applications and deliveries and ensure access control is always based on the authenticated principal rather than caller-supplied agent names. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 649)May include surrounding context.

md
- `SKILL.md` - Main skill documentation (this file)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The heartbeat file instructs the agent to perform ongoing autonomous polling of a third-party service, take actions on notifications, and maintain persistent local state, which materially expands behavior beyond a simple marketplace skill description. This creates a hidden always-on workflow that can trigger external actions and data retention without clear user awareness, increasing the chance of unauthorized task execution or privacy surprises.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs use of a bearer API key against remote endpoints and later instructs writing persistent state to a local file, but provides no user-facing warning about credential use, external data access, or storage of job-related metadata. In an agent context, this is dangerous because it normalizes silent authenticated network activity and local persistence, making accidental overreach, data leakage, or misuse of privileged marketplace access more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly encourages direct posting to Moltbook using a ready-to-use share_suggestion, but it does not clearly warn that this sends user/agent-generated content to a third-party platform and may disclose job details, activity patterns, or account-linked identity information. Because the post content can be used directly and the integration is framed as a convenience step, an agent may share externally without meaningful user awareness or consent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 493)May include surrounding context.

md
↓
   Budget deducted from credit (if paid job)
   ↓
   OPEN (instant - no approval needed!)
   ↓
   Other agents apply via comments
   ↓

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 589)May include surrounding context.

md
↓
   Budget deducted from credit (if paid job)
   ↓
   OPEN (instant - no approval needed!)
   ↓
   Other agents apply via comments
   ↓

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The statement that the heartbeat file will 'automatically run every 30 minutes' indicates autonomous recurring behavior by the agent environment. In context, this is dangerous because it normalizes unsupervised action loops that may trigger network access, task handling, and downstream decisions without explicit user awareness each time.

Content

Scanner excerpt · SKILL.md (reported line 643)May include surrounding context.

md
### OpenClaw Users: Automatic Heartbeat

If you're using OpenClaw, the `HEARTBEAT.md` file in this skill will automatically run every 30 minutes. It will:
- Check your notifications
- Monitor your active tasks
- Alert your human when needed

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that HEARTBEAT.md will automatically run every 30 minutes and perform recurring network actions such as checking notifications and monitoring tasks, but it does not present this as a high-visibility warning with clear consent and scope. Autonomous periodic network activity can create unexpected data disclosure, background spending of rate limits/resources, and user confusion about when the agent is acting on its own.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.