Back to skill

Security audit

Clawsec Monitor

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local traffic-monitoring proxy with powerful HTTPS inspection, and I did not find hidden data theft or unrelated behavior.

Install only if you intentionally want a local proxy that can inspect agent traffic, including decrypted HTTPS when its CA is trusted. Prefer per-process proxy and CA environment variables, avoid system-wide CA trust on production machines, protect or remove /tmp/clawsec when done, and do not rely on this tool as a guaranteed blocker because the implementation mainly logs detections and has known evasion and PID-handling limitations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
clawsec-monitor.py:570
Finding

Traffic signatures can evade detection across stream boundaries

Content
View full analysis
None: scanned = 0 try: while chunk := await src.read(4096): if scanned < self.max_scan: text = chunk.decode("utf-8", errors="replace") for t in scan(text, direction, dest=dest, max_bytes=self.max_scan, proto=proto): await emit(t) scanned += len(chunk) dst.write(chunk) await dst.drain() ``` The same independent-chunk scanning design is used for the HTTPS MITM inbound path: ```python async def _transport_pipe_inspect(self, src: asyncio.StreamReader, dst_transport, direction: str, dest: str) -> None: """Inspect then write to raw TLS transport (MITM inbound path).""" scanned = 0 try: while chunk := await src.read(4096): if scanned < self.max_scan: text = chunk.decode("utf-8", errors="replace") for t in scan(text, direction, dest=dest, max_bytes=self.max_scan, proto="https"): await emit(t) scanned += len(chunk) dst_transport.write(chunk) ``` The gateway proxy also scans each read independently: ```python async def _pipe(self, src: asyncio.StreamReader, dst: asyncio.StreamWriter, direction: str) -> None: try: while chunk := await src.read(4096): text = chunk.decode("utf-8", errors="replace") for t in scan(text, direction, max_bytes=self.max_scan, proto ...[truncated 2096 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
clawsec-monitor.py:767
Finding

Stale PID reuse can cause termination of an unrelated process

Content
View full analysis
Optional[int]: try: pid = int(_PID_FILE.read_text().strip()) os.kill(pid, 0) return pid except (FileNotFoundError, ValueError, ProcessLookupError, PermissionError): return None ``` The stop command trusts that existence check and signals the PID: ```python def cmd_stop(_: argparse.Namespace) -> None: pid = _pid_running() if not pid: print("Not running.") return os.kill(pid, signal.SIGTERM) print(f"Sent SIGTERM to PID {pid} — waiting for shutdown...", end="", flush=True) for _ in range(50): time.sleep(0.1) if not _pid_running(): print(" stopped.") return print(" timeout, sending SIGKILL.") try: os.kill(pid, signal.SIGKILL) _PID_FILE.unlink(missing_ok=True) except ProcessLookupError: pass ``` ### Technical Analysis A numeric PID is not a stable process identity. Operating systems reuse PIDs after processes exit. `_pid_running()` only checks whether some process currently has the stored PID by calling `os.kill(pid, 0)`. If ClawSec exits without removing its PID file and the PID is subsequently assigned to another process, `cmd_stop()` treats that unrelated process as ClawSec. It sends `SIGTERM` and, if the process remains alive after approximately five seconds, sends `SIGKILL`. No executable path, command line, process start time, random instance token, or other identity attribute is checked before either signal is sent. ### Attack Path 1. ClawSec starts and records its PID in `/tmp/clawsec/monitor.pid`. 2. It terminates abnormally, leaving the PID file behind. 3. The operating system later reuses that PID ...[truncated 960 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.clawsec.txt:1
Finding

Unpinned dependency permits non-reproducible future package resolution

Content
View full analysis
=42.0.0 ``` The installation documentation also resolves the newest available package at installation time: ```bash pip install cryptography ``` ### Technical Analysis The version constraint accepts every future release of `cryptography` with a version greater than or equal to 42.0.0. No exact version or distribution hash is supplied. As a result, two installations performed at different times may resolve different code. The audited source package therefore does not completely determine the code that will execute in the deployed environment. The named package is a legitimate dependency, and no typosquatting or malicious package was identified. The risk is that an unreviewed future release, compromised distribution artifact, dependency-chain incident, or incompatible behavioral change could be incorporated automatically. ### Attack Path 1. A user follows the documented installation command or installs from `requirements.clawsec.txt`. 2. The package resolver contacts the configured Python package index. 3. It selects any release satisfying `>=42.0.0`, normally the newest compatible release. 4. That artifact is downloaded and installed without validation against a project-published hash. 5. If the selected artifact or its dependency chain is compromised, its code executes during normal import or cryptographic operations. Exploitation depends on a compromised package source, artifact, account, mirror, or future release; no such compromise was demonstrated during this audit. ### Impact Assessment The dependency executes with the privileges of the ClawSec process. A malicious resolved package could therefore read or modify files available to that account, access intercepted traffic and generated CA key material, open network connections, or exe ...[truncated 202 chars]
Remediation
View remediation
``` - Generate a lock file containing hashes for all direct and transitive distribution artifacts. - Install with hash enforcement, such as `pip install --require-hashes -r requirements.clawsec.txt`. - Restrict package installation to trusted indexes and use authenticated internal mirrors where appropriate. - Review and update the pinned version on a controlled schedule rather than resolving arbitrary future releases during deployment. - Scan pinned dependencies for known vulnerabilities in CI. - Keep installation instructions consistent with the locked manifest instead of recommending an unconstrained `pip install cryptography`. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (70)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

md
| Category | Examples |
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run_tests.py (reported line 146)May include surrounding context.

python
| Category | Examples |
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run_tests.py (reported line 157)May include surrounding context.

python
| Category | Examples |
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run_tests.py (reported line 159)May include surrounding context.

python
| Category | Examples |
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 131)May include surrounding context.

md
| Category | Examples |
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

md
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run_tests.py (reported line 304)May include surrounding context.

python
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run_tests.py (reported line 305)May include surrounding context.

python
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 132)May include surrounding context.

md
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

md
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run_tests.py (reported line 306)May include surrounding context.

python
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · run_tests.py (reported line 307)May include surrounding context.

python
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 132)May include surrounding context.

md
|---|---|
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

md
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |
| **SSH lateral movement** | New outbound SSH connections to unknown hosts |

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · clawsec-monitor.py (reported line 118)May include surrounding context.

python
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |
| **SSH lateral movement** | New outbound SSH connections to unknown hosts |

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

md
| **AI API key leakage** | `sk-ant-*`, `sk-live-*`, `sk-gpt-*`, OpenAI keys |
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |
| **SSH lateral movement** | New outbound SSH connections to unknown hosts |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

md
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |
| **SSH lateral movement** | New outbound SSH connections to unknown hosts |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

md
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl … \| bash`, `wget … \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |
| **SSH lateral movement** | New outbound SSH connections to unknown hosts |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

md
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl ... \| bash`, `wget ... \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |
| **SSH lateral movement** | New outbound SSH connections to unknown hosts |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

md
| **SSH key exfiltration** | PEM private keys, `ssh-rsa` pubkeys, `.ssh/id_rsa` paths |
| **Sensitive file access** | `/etc/passwd`, `/etc/shadow`, `/etc/sudoers` |
| **Dot-file leakage** | `.env`, `.aws/credentials`, `.netrc`, `.pgpass` |
| **Command injection** | `curl ... \| bash`, `wget ... \| sh`, `eval`, `base64 -d \| sh` |
| **Netcat backdoors** | `nc -e`, `nc -lvp`, reverse shells |
| **SSH lateral movement** | New outbound SSH connections to unknown hosts |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · clawsec-monitor.py (reported line 22)May include surrounding context.

python
HTTPS MITM setup (one-time):
    # After first start, install the generated CA into your trust store:
    # macOS:
    sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/clawsec/ca.crt
    # Linux:
    sudo cp /tmp/clawsec/ca.crt /usr/local/share/ca-certificates/clawsec.crt && sudo update-ca-certificates
    # Then route traffic:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · clawsec-monitor.py (reported line 317)May include surrounding context.

python
HTTPS MITM setup (one-time):
    # After first start, install the generated CA into your trust store:
    # macOS:
    sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/clawsec/ca.crt
    # Linux:
    sudo cp /tmp/clawsec/ca.crt /usr/local/share/ca-certificates/clawsec.crt && sudo update-ca-certificates
    # Then route traffic:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 99)May include surrounding context.

md
HTTPS MITM setup (one-time):
    # After first start, install the generated CA into your trust store:
    # macOS:
    sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/clawsec/ca.crt
    # Linux:
    sudo cp /tmp/clawsec/ca.crt /usr/local/share/ca-certificates/clawsec.crt && sudo update-ca-certificates
    # Then route traffic:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · clawsec-monitor.py (reported line 22)May include surrounding context.

python
HTTPS MITM setup (one-time):
    # After first start, install the generated CA into your trust store:
    # macOS:
    sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/clawsec/ca.crt
    # Linux:
    sudo cp /tmp/clawsec/ca.crt /usr/local/share/ca-certificates/clawsec.crt && sudo update-ca-certificates
    # Then route traffic:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · clawsec-monitor.py (reported line 317)May include surrounding context.

python
HTTPS MITM setup (one-time):
    # After first start, install the generated CA into your trust store:
    # macOS:
    sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /tmp/clawsec/ca.crt
    # Linux:
    sudo cp /tmp/clawsec/ca.crt /usr/local/share/ca-certificates/clawsec.crt && sudo update-ca-certificates
    # Then route traffic:

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.md:112

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
run_tests.py:345

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skill.md:157