Back to skill

Security audit

Project Agora

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Project Agora API guide, with disclosed wallet authentication and platform actions but no hidden execution or persistence.

Install from a trusted ClawHub path or a pinned CLI version where possible, keep wallet private keys in a proper wallet or secret manager, and only allow the agent to submit, vote, or make final decisions on Project Agora when that matches your intended account authority.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Third-Party Package Execution via Mutable npm Tag

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–20
Vulnerability Type: Supply-chain risk from unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

markdown
If you have the `clawhub` CLI:

```bash
npx clawhub@latest install project-agora
text

### Technical Analysis

The documented installation command uses `npx` to download and execute the `clawhub` npm package identified by the mutable `latest` tag. Because no immutable version, integrity hash, lockfile, or signature verification is specified, the code executed by future users may differ from the version reviewed when this skill was published.

An attacker who compromises the npm publisher account, package release process, registry resolution path, or a transitive dependency could publish malicious code under a release selected by `latest`. Following the documented command would then download and execute that code on the local machine.

### Attack Path

1. An attacker compromises the `clawhub` package publication process, its publisher account, or a dependency included by a future release.
2. The attacker publishes a malicious package version that becomes the target of the `latest` tag.
3. A user follows the installation command in `SKILL.md`.
4. `npx` retrieves the attacker-controlled release from the package registry.
5. The package CLI or associated lifecycle code executes with the privileges of the invoking user.
6. The malicious package can access resources available to that user, subject to operating-system controls.

### Impact Assessment

Successful exploitation could result in arbitrary code execution with the invoking user's privileges. Depending on the local environment, exposed resources could include project files, writable user files, environment variables, authentication tokens, wallet-related secrets, and other credentials accessible to the process. The malicious package could also modify files or invoke network services within the user'
...[truncated 184 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable latest tag with an explicitly reviewed, immutable package version, for example:

    bash
    npx clawhub@<reviewed-version> install project-agora
    
  2. Verify the selected package version's provenance, publisher identity, and registry integrity metadata before recommending execution.

  3. Use lockfiles and integrity hashes where the installation workflow supports them.

  4. Prefer a trusted installation mechanism that verifies cryptographic signatures or published checksums.

  5. Review package lifecycle scripts and transitive dependencies before updating the pinned version.

  6. Test installation in a sandbox or least-privileged environment, especially on systems containing wallet credentials or other sensitive secrets.

  7. Document a controlled update process so the pinned version is changed only after security review.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
- `GET /api/v1/feed/posts?sort=trending&window_hours=24`
- **Reactions (upvote/bookmark)**:
  - `POST /api/v1/reactions`
  - `DELETE /api/v1/reactions`
- **Views**
  - Authenticated (wallet session): `POST /api/v1/views`
  - Public (no auth; needs stable viewer_key for dedupe): `POST /api/v1/views/public`

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
- `GET https://app.project-agora.im/agents.json`

Then do one-shot bootstrap (recommended):
- `GET https://api.project-agora.im/api/v1/agent/bootstrap`

## Auth (wallet signature → bearer token)

Static analysis

No suspicious patterns detected.