Back to skill

Security audit

ClawWatch

Security checks for vulnerabilities and agentic risk

Overview

The skill’s watchlist behavior is coherent, but it depends on an unpinned external CLI package and under-explains local data and API-key handling.

Review the external `clawwatch` package before installing, preferably use an isolated virtual environment, and avoid entering API keys through shell commands on shared machines. Be aware that watchlist, cached price data, and possibly configuration may persist under ~/.clawwatch.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:57
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 57–62
Vulnerability Type: Unverified and unpinned package installation
Risk Level: Medium

Vulnerable Code Snippet:

bash
## Installation

```bash
pip install clawwatch
# No API keys needed for crypto! Works out of the box.
# Optional: set CoinCap key for higher rate limits
clawwatch config --coincap-key YOUR_KEY  # optional
text

### Technical Analysis

The skill instructs users or agents to install `clawwatch` from pip without specifying an exact version, package hash, trusted repository URL, or verified publisher identity. The project contains no dependency lockfile or local implementation that would allow the installed executable to be compared with audited source code.

Consequently, package resolution is mutable: the code installed by the same command can change over time. If the package name is controlled by an unintended publisher, the package distribution is compromised, or a later release becomes malicious, installation may execute arbitrary package build or installation logic. Subsequent `clawwatch` commands would then run the package's executable under the identity of the invoking user.

The nearby API-key configuration instruction increases the potential sensitivity of the installed program because it may receive and store a CoinCap key. The CLI documentation also describes a Finnhub key and files beneath `~/.clawwatch`, although the audited project does not include the executable implementation needed to verify how those values are handled.

### Attack Path

1. An attacker compromises the resolved `clawwatch` package, its publisher account, or the relevant package-distribution channel, or publishes malicious code in a future version.
2. A user or agent follows `SKILL.md` and runs `pip install clawwatch`.
3. pip resolves the current mutable release because no version or cryptographic hash is pinned.
4. Malicious build hooks, in
...[truncated 1012 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically reviewed release, for example clawwatch==X.Y.Z.
  2. Record and enforce cryptographic hashes using a requirements file and pip install --require-hashes.
  3. Document the authoritative package repository, source repository, publisher identity, and release-signing or provenance information.
  4. Include the executable source in the audited project or link each pinned release to immutable, reviewable source.
  5. Use a lockfile generated from reviewed dependencies and verify all transitive dependencies.
  6. Install the package in an isolated virtual environment with minimum filesystem and credential access.
  7. Avoid exposing API keys through command-line arguments where they may appear in shell history or process listings. Prefer a protected configuration file, operating-system credential store, or securely read environment variable.
  8. Add automated dependency-integrity and provenance checks to the release process before updating the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says to use the skill when the user asks about their watchlist, wants to add/remove assets, check prices, set price alerts, or get a market overview. Phrases like 'check prices' and 'get a market overview' are broad and there are no exclusions or scope limits explaining when this skill should not activate versus other finance or analysis skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly documents reading and relying on cached files in the user's home directory, but does not warn that watchlist contents and recent price data are stored locally. This can create privacy and data-handling risk because other local processes or users on a shared system may access sensitive portfolio interests or inferred financial behavior if file permissions are weak or users are unaware of persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI reference documents options for supplying API keys directly on the command line but gives no warning about how those credentials are stored or exposed. Passing secrets via CLI flags can leak them through shell history, process listings, logs, or insecure local config storage, which is especially relevant for a finance-related tool that uses third-party market data accounts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The quick-reference table includes both German and English user utterances and command examples, but the document does not state how the skill chooses response language or that language follows user preference. This can create an implicit language-policy issue if the skill responds in a language the user did not choose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.