Back to skill

Security audit

Coclaw

Security checks for vulnerabilities and agentic risk

Overview

The skill is a marketplace helper, but its buyer script trusts service endpoints returned by a remote directory and its payment and SSRF documentation overstates what the code enforces.

Review carefully before installing. Use --list and --dry-run first, verify the selected service ID, endpoint, and price, and do not submit secrets, private documents, source code, or business data unless you trust the listing and Coclaw directory. In payment-enabled environments, treat service calls as potentially payment-bearing and require explicit approval before spending USDC.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/call_service.py:118
Finding

Untrusted Marketplace Endpoint Enables Server-Side Request Forgery and User Input Disclosure

Content
View full analysis
list[dict[str, Any]]: response = http_json("GET", f"{API_BASE_URL}/v1/openclaw/listings") if not isinstance(response, list): raise RuntimeError("Unexpected listings response") return response ``` ```python def call_service(endpoint: str, service_id: str, input_payload: dict) -> dict[str, Any]: req = request.Request( url=endpoint, method="POST", data=json.dumps({"service_id": service_id, "input": input_payload}).encode( "utf-8" ), headers={"content-type": "application/json"}, ) try: with request.urlopen(req, timeout=120) as resp: return json.loads(resp.read().decode("utf-8")) ``` ```python listing = select_listing(args.service_id) endpoint = listing.get("endpoint", "") service_id = listing.get("listing_id", "") ``` ```python result = call_service(endpoint, service_id, input_payload) ``` ### Technical Analysis The script retrieves listing records from the remote Coclaw API and treats the listing's `endpoint` field as a trusted request destination. It does not verify: - That the URL uses HTTPS. - That its normalized hostname is the approved Coclaw agent hostname. - That its port and path match the intended service. - That it does not resolve to a loopback, private, link-local, or reserved address. - That redirects remain on an approved destination. - That the selected endpoint is authorized to receive the supplied input. The untrusted endpoint is passed directly to `urllib.request.Request` and then to `request.urlopen`. The POST body contains both the selected service identifier and the complete user-provided input payload. The issue ...[truncated 2968 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims buyers can browse listings, perform x402 payment, invoke supplier endpoints, and receive results, but the analyzed behavior reportedly does not implement those capabilities. This mismatch is dangerous because users and orchestrators may trust the documentation and authorize the skill for payment-bearing or external-service workflows it does not safely or transparently perform, creating room for deceptive operation, unsafe assumptions, or later code substitution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares network-relevant behavior and references remote API and agent endpoints, but it does not declare any explicit tool scope or permissions. This weakens least-privilege controls and makes it harder for a host or reviewer to understand and constrain what external access the skill expects, increasing the chance of unintended network use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes a flow where a facilitator settles USDC on-chain after a 402 challenge, but it does not provide an explicit warning that buy-side use can trigger real payment settlement. In a payment-enabled context, missing disclosure can lead users to invoke the skill without understanding they may spend funds, which is especially risky because the workflow is presented as streamlined and automatic.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.