Back to skill

Security audit

Openpump Solana Mcp

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed crypto trading integration, but it gives an agent broad real-money wallet and trading authority with weak technical scoping and a mutable runtime package.

Review this skill carefully before installing. Use only low-balance, revocable, tightly scoped OpenPump credentials if available; avoid @latest startup execution; avoid storing the key in plaintext; and require explicit, transaction-specific approval for buys, sells, transfers, token launches, sniping, market making, and spam launches. The README also says it is not available to US persons, so verify eligibility before use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
workspace-template/openclaw.json:4
Finding

Automatic Execution of an Unpinned Remote npm Package

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
workspace-template/openclaw.json:2
Finding

Excessive Financial and Wallet Tool Privileges Exposed to the Agent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
workspace-template/README.md:58
Finding

Plaintext Persistent Storage of the OpenPump API Key

Content
View full analysis
> ~/.openclaw/.env ``` ``` Related guidance from `workspace-template/SKILLS.md:43-48`: ```markdown Set it as an environment variable: ```bash export OPENPUMP_API_KEY="op_sk_live_YOUR_KEY_HERE" ``` Or add it to your `~/.openclaw/.env` file so it persists across sessions. ``` ### Technical Analysis The documented command appends a live financial-service credential to a plaintext file. It does not: - Create the parent directory with restrictive permissions. - Set a restrictive `umask`. - Verify file ownership or existing permissions. - Apply mode `0600` to the resulting file. - Check whether the file is a symbolic link. - Prevent duplicate secrets from being appended. - Provide rotation or revocation instructions. - Warn against committing, backing up, or logging the file. The effective permissions depend on the user's environment and on whether the file already exists. The key is subsequently inherited by the third-party MCP process configured in `openclaw.json`. The placeholder shown in the project is not itself a leaked live credential. The vulnerability lies in instructing users to replace it with a real key and persist that key without explicit protections. ### Attack Path 1. The user replaces the placeholder with a valid `op_sk_live_` API key. 2. The user runs the documented `echo ... >> ~/.openclaw/.env` command. 3. The key is stored indefinitely in plaintext under ambient filesystem ...[truncated 1106 chars]
Remediation
View remediation
"$HOME/.openclaw/.env" chmod 600 "$HOME/.openclaw/.env" ``` 3. Verify that the destination is a regular file owned by the current user and is not a symbolic link. 4. Avoid including the actual key directly in shell history; use a secure interactive prompt or secret-store command. 5. Ensure `.env` files are excluded from source control, support bundles, logs, and unencrypted backups. 6. Use a narrowly scoped credential with the minimum required permissions. 7. Document key rotation and immediate revocation procedures. 8. Redact authorization headers and environment values from logs and error reports. 9. Use separate read-only and transaction credentials where supported. 10. Clearly warn users that the API key protects access to financial and custodial-wallet functionality. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · workspace-template/README.md (reported line 61)May include surrounding context.

Or add it to your ~/.openclaw/.env file for persistence:

bash
echo 'OPENPUMP_API_KEY=op_sk_live_YOUR_KEY_HERE' >> ~/.openclaw/.env

5. Fund Your Trading Wallet

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document declares a user-supervised execution model requiring approval before trades, but elsewhere defines executable workflows that proceed directly to buy-token/sell-token. In a high-risk trading skill with custody over wallets and token transfers, this inconsistency can cause an agent to execute financial transactions without fresh user consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section says the agent must always get explicit approval before trading, but the later operational workflow omits that gate and can be followed mechanically by an agent. The contradiction is dangerous because trade execution on pump.fun is irreversible and can rapidly lose funds in volatile memecoin markets.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The same approval language is undermined for sells, especially because the document also prescribes automatic exits like stop-losses and time-decay liquidations. Without strict authorization semantics, an agent may liquidate positions or transfer value based on inferred policy rather than confirmed user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill prominently advertises wallet creation and management but does not clearly disclose up front that these are custodial, platform-managed wallets with associated custody and key-management risks. Users may assume they control private keys directly or misunderstand the trust model, which is especially dangerous in a crypto context involving fund transfers, trading, and automated strategies.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance is overly broad because it tells the agent to use the skill for essentially anything involving pump.fun tokens, bundle launches, Jito bundles, and even spam launches. In a high-risk financial skill that can launch tokens, transfer funds, and run autonomous trading actions, broad triggers increase the chance of inappropriate invocation, accidental financial operations, or use in contexts where the user did not explicitly request these dangerous actions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

The heartbeat instructs the agent to run automatically every 30 minutes and explicitly allows trade execution without per-action user approval if the user has previously given broad standing instructions such as auto-executing stop-losses. In a skill that can sell assets and manage wallets, this creates meaningful autonomous financial decision-making risk: stale consent, ambiguous scope of prior authorization, or misclassification of market conditions could trigger irreversible trades without contemporaneous confirmation.

Content

Scanner excerpt · workspace-template/HEARTBEAT.md (reported line 5)May include surrounding context.

md
This checklist runs automatically every 30 minutes when OpenClaw fires the heartbeat timer. Execute every step in order. Do not skip steps even if the previous heartbeat was recent.

> **Important:** All sell/buy actions identified during the heartbeat must be **presented to the user for approval** before execution, unless the user has granted explicit standing instructions for automated exits (e.g., "auto-execute stop-losses").

## Step 1: Check All Open Positions

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · workspace-template/README.md (reported line 17)May include surrounding context.

md
## What This Agent Does NOT Do

- Create new tokens (tools are available but not part of the trading strategy)
- Use multi-wallet bundle operations (single-wallet trading only)
- Transfer SOL externally without explicit user instruction
- Override risk parameters without explicit user instruction

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises real-money blockchain operations including token launches, trading, transfers, market making, sniping, stop-loss automation, and spam launches without any safety notice about irreversible transactions, custody implications, slippage, or loss of funds. In the context of an agent skill, this omission is dangerous because users may treat tool invocation as low-risk automation when it can trigger immediate on-chain actions and financial loss.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The documentation recommends persisting a live API key in an environment variable or a long-lived local env file, which increases the exposure window if the workstation, shell history, logs, backups, or local files are accessed by other processes or users. Because this skill enables financial operations against custodial wallets and trading endpoints, compromise of the key could allow unauthorized trades, transfers, or other account actions.

Content

Scanner excerpt · workspace-template/SKILLS.md (reported line 40)May include surrounding context.

md
1. Sign up or log in
2. Navigate to Dashboard > API Keys
3. Create a new key (starts with `op_sk_live_`)

Set it as an environment variable:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The phrase permitting 'auto-execute stop-losses' introduces autonomous decision-making over financial transactions. While framed as an exception, it still enables the agent to act without per-trade confirmation, which is risky in volatile markets and especially sensitive because wallet tools can directly move user assets.

Content

Scanner excerpt · workspace-template/SOUL.md (reported line 60)May include surrounding context.

md
Then **wait for user confirmation** before calling `buy-token`, `sell-token`, `transfer-sol`, or `transfer-token`.

The only exception: if the user has explicitly granted standing instructions (e.g., "auto-execute stop-losses"), follow those instructions.

After every trade, report:
- Entry price and amount

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The buy workflow is written as an executable runbook and includes a direct buy-token step after checks, but does not include an approval checkpoint in the procedure itself. Agents often prioritize concrete stepwise instructions, so omission of the warning in the operative sequence increases the chance of unauthorized purchases.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The sell workflow directs a full-position exit with tokenAmount: "all" and lacks an explicit warning that the action is irreversible and authorization-dependent. In a custodial trading context, a mechanical liquidation procedure without a confirmation gate can cause unintended loss realization or disputes over agent authority.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file explicitly states that all tools communicate using OPENPUMP_API_KEY but provides no warning about credential sensitivity, storage, logging, or sharing. In a high-risk trading/custodial-wallet skill, this omission increases the chance that users or downstream agents mishandle the API key, which could enable unauthorized trading, wallet actions, or account abuse if exposed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The poll-job documentation says to use cancel-job after spam-launch, but the file later documents a dedicated cancel-spam-launch tool for that workflow. This is a direct contradiction in the skill's own usage guidance and could cause an agent to invoke the wrong cancellation tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.