Back to skill

Security audit

Ghost Protocol OpenClaw Pay

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-built for Ghost/x402 payments, but it needs review because it handles real wallet signing keys and payment data with several under-scoped safety controls.

Install only in a trusted server runtime using a dedicated low-balance signer key, never pass the private key on the command line, keep it in protected secret storage, prefer dry-run first, restrict base URLs to trusted HTTPS Ghost endpoints, and review/pin the npm dependency graph before using this for real payments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
bin/create-wire-job-from-quote.mjs:19
Finding

Arbitrary Base URL Allows Sensitive Workflow Data to Be Redirected

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
bin/call-x402.mjs:37
Finding

Private Signing Keys Can Be Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:16
Finding

Payment and Signing Dependencies Are Not Reproducibly Pinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The quickstart requires users to provide a raw private key via an environment variable but does not include any warning or handling guidance for sensitive credential storage. In a payment and on-chain transaction skill, this increases the risk that operators paste secrets into shell history, commit them to dotfiles, expose them in process listings, or reuse production keys unsafely, which could lead to wallet compromise and unauthorized fund transfers.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

md
## Contents

- `openclaw.plugin.json` - plugin descriptor with local skill path
- `skills/openclaw-ghost-pay/SKILL.md` - skill instructions for OpenClaw
- `bin/get-payment-requirements.mjs` - MCP-based payment requirement lookup
- `bin/call-x402.mjs` - real `x402` client helper for merchant endpoints
- `bin/report-x402-settlement.mjs` - manual merchant-signed settlement report helper for GhostRank fallback/recovery

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that GHOST_SIGNER_PRIVATE_KEY is required for paid calls, but the safety warning is minimal and appears only later in the document. In a payment-signing skill, this can lead users to paste a hot private key into insecure places, misunderstand that real-value signatures will be produced, or run example commands against live merchant endpoints without appreciating custody and spending risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill requires access to a highly sensitive environment variable, GHOST_SIGNER_PRIVATE_KEY, but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an unnecessary trust gap: an agent/runtime may expose environment access more broadly than intended, increasing the chance of secret misuse, accidental disclosure, or unauthorized paid transaction execution. The skill context makes this more dangerous because it is explicitly designed to perform real payment and settlement actions, so compromise of the signer key directly enables financial abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script accepts a signer private key from a CLI argument or environment variable and uses it to create a signer for payment-enabled requests. Although it checks for presence, there is no user-facing warning, comment, or prompt explaining that a sensitive credential is being consumed for signing/payment operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code performs an outbound HTTP request using a user-provided URL and may send arbitrary headers and JSON body content, which can include user or system data. The script has validation and a dry-run mode, but it does not display any confirmation, warning, or explanatory comment before transmitting data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code sends wallet/address identifiers and principal amount to a remote HTTP endpoint via POST, which is a safety-relevant network transmission. The file includes neither a confirmation prompt nor any user-facing disclosure such as a comment, docstring, or log message explaining that these values will be sent off-box.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code POSTs settlement telemetry including payerIdentity, optional payerAddress, paymentReference, requestId, and metadata to a remote endpoint. While the script name suggests reporting, there is no visible confirmation prompt, log message, or comment/docstring in this file warning that potentially sensitive payment-related data will be transmitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script reads configuration from environment variables, including the remote base URL and timeout, and later uses that configuration to make a network call. There is no visible disclosure in this file that environment-provided settings may influence where user-supplied data is transmitted.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency uses a caret range rather than an exact pinned version, which permits automatic installation of newer minor/patch releases. This weakens build reproducibility and increases supply-chain risk because a compromised or regressed upstream release could be pulled in without explicit review.

Content

Scanner excerpt · package.json (reported line 16)May include surrounding context.

json
"wire:status": "node ./bin/get-wire-job-status.mjs"
  },
  "dependencies": {
    "viem": "^2.21.0",
    "x402": "^1.1.0",
    "x402-fetch": "^1.1.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The x402 package is unpinned, so installs may resolve to different releases over time, making it impossible to guarantee which code is executed. In this skill's context, that is more concerning because the package is directly related to payment and x402 transaction flows, so upstream compromise or unintended behavior could affect real payment execution.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
},
  "dependencies": {
    "viem": "^2.21.0",
    "x402": "^1.1.0",
    "x402-fetch": "^1.1.0"
  }
}

Unverifiable Dependency: x402 has 1 known advisory(ies) (GHSA-3j63-5h8p-gf7c (x402 SDK vulnerable in outdated versions in resource servers for builders)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

There is a known advisory affecting some x402 versions, and because the manifest does not pin the package, the actual installed version cannot be verified as safe or vulnerable from this file alone. Given that this skill explicitly executes real x402 payment calls and settlement reporting, uncertainty around a payment SDK with a known advisory materially raises risk.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The x402-fetch dependency is specified with a caret range, allowing silent drift to newer releases at install time. This creates a software supply-chain exposure and reduces auditability, especially for code that performs external network and payment-related fetch operations.

Content

Scanner excerpt · package.json (reported line 18)May include surrounding context.

json
"dependencies": {
    "viem": "^2.21.0",
    "x402": "^1.1.0",
    "x402-fetch": "^1.1.0"
  }
}

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
bin/call-x402.mjs:37

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
bin/report-x402-settlement.mjs:66