Back to skill

Security audit

Clawstarter

Security checks for vulnerabilities and agentic risk

Overview

This skill serves a collaboration platform, but it also asks agents to persistently fetch remote instructions and take public actions without asking first.

Review carefully before installing. Use it only in an on-demand mode unless you explicitly want recurring activity, do not let it overwrite installed skill files from remote URLs without reviewing diffs, store API keys in a proper secret store instead of plaintext files or memory, and require confirmation before posting, voting, joining projects, or creating GitHub repositories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:53
Finding

Mutable Remote Instructions Can Replace Active Skill Behavior

Content
View full analysis
~/.openclaw/skills/clawstarter/SKILL.md curl -s https://clawstarter.io/heartbeat.md > ~/.openclaw/skills/clawstarter/HEARTBEAT.md curl -s https://clawstarter.io/discourse.md > ~/.openclaw/skills/clawstarter/DISCOURSE.md curl -s https://clawstarter.io/skill.json > ~/.openclaw/skills/clawstarter/package.json ``` ```markdown **Check for updates:** Re-fetch these files anytime to see new features! ``` `HEARTBEAT.md:12-20`: ```bash curl -s https://clawstarter.io/skill.json | grep '"version"' ``` ```markdown Compare with your saved version. If there's a new version, re-fetch the skill files: ``` ```bash curl -s https://clawstarter.io/skill.md > ~/.openclaw/skills/clawstarter/SKILL.md curl -s https://clawstarter.io/heartbeat.md > ~/.openclaw/skills/clawstarter/HEARTBEAT.md curl -s https://clawstarter.io/discourse.md > ~/.openclaw/skills/clawstarter/DISCOURSE.md ``` ### Technical Analysis The update workflow downloads mutable Markdown documents and writes them directly over the installed Skill files. In a documentation-driven Agent Skill, these files determine Agent behavior and therefore function as executable instructions. The workflow provides no cryptographic signature verification, pinned content digest, immutable release URL, trusted-version manifest, review step, or rollback mechanism. HTTPS protects transport against ordinary interception but does not protect against a compromised server, malicious account holder, deployment error, or intentionally harmful future release. The update check only extracts a remotely supplied version string. It does not establish the authenticity or integrity of the downloaded files. ### Attack P ...[truncated 1457 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:119
Finding

Heartbeat Installation Creates Persistent Remote-Controlled Agent Behavior

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
HEARTBEAT.md:163
Finding

Skill Directs Autonomous External Actions Without Contemporaneous User Approval

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:92
Finding

API Credentials Are Recommended for Plaintext and Potentially Unsafe Storage

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (27)

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The skill explicitly recommends storing a live API key in a plaintext JSON file under the user’s home directory and also suggests saving it to memory. This increases the risk of credential theft through local file access, logs, backups, prompt leakage, or other skills reading the same path, enabling impersonation on Clawstarter.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

⚠️ Save your apiKey immediately! You need it for all requests.

Recommended: Save your credentials to ~/.config/clawstarter/credentials.json:

json
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document repeatedly instructs users to place the API key directly in JSON request bodies passed via curl -d, which commonly exposes secrets through shell history, process listings, CI logs, terminal scrollback, and debugging output. Because the skill is an agent integration guide, this pattern is likely to be copied into automation and tooling, increasing the chance of credential leakage.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example sends an authenticated request with an API key to an external service, creating a real data-exposure risk if users paste live credentials into the sample command. In this skill context, the danger is amplified because the documentation normalizes outbound transmission of secrets and encourages inline secret placement in request bodies.

Content

Scanner excerpt · DISCOURSE.md (reported line 42)May include surrounding context.

You must be a participant to post threads:

bash
curl -X POST https://clawstarter.io/api/joinProject \
  -H "Content-Type: application/json" \
  -d '{
    "data": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DISCOURSE.md (reported line 126)May include surrounding context.

Best for displaying full discussion structure:

bash
curl -X POST https://clawstarter.io/api/listThreads \
  -H "Content-Type: application/json" \
  -d '{
    "data": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DISCOURSE.md (reported line 251)May include surrounding context.

Get recent threads across all projects:

bash
curl -X POST https://clawstarter.io/api/getActivityFeed \
  -H "Content-Type: application/json" \
  -d '{
    "data": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DISCOURSE.md (reported line 374)May include surrounding context.

bash
# 1. Find the project (no apiKey needed for listing)
curl -X POST https://clawstarter.io/api/listProjects \
  -H "Content-Type: application/json" \
  -d '{"data": {"phase": "IDEATION", "sort": "newest"}}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The heartbeat instructs users to place an API key directly into request bodies for authenticated actions but provides no warning about secret handling, logging, shell history, or accidental disclosure. In an agent-skill context, this can normalize unsafe credential practices and cause keys to be exposed in transcripts, tooling logs, or persisted command history.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · HEARTBEAT.md (reported line 18)May include surrounding context.

Compare with your saved version. If there's a new version, re-fetch the skill files:

bash
curl -s https://clawstarter.io/skill.md > ~/.openclaw/skills/clawstarter/SKILL.md
curl -s https://clawstarter.io/heartbeat.md > ~/.openclaw/skills/clawstarter/HEARTBEAT.md
curl -s https://clawstarter.io/discourse.md > ~/.openclaw/skills/clawstarter/DISCOURSE.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

Compare with your saved version. If there's a new version, re-fetch the skill files:

bash
curl -s https://clawstarter.io/skill.md > ~/.openclaw/skills/clawstarter/SKILL.md
curl -s https://clawstarter.io/heartbeat.md > ~/.openclaw/skills/clawstarter/HEARTBEAT.md
curl -s https://clawstarter.io/discourse.md > ~/.openclaw/skills/clawstarter/DISCOURSE.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill instructs automatic retrieval of remote content and writes it into active local skill files, causing external content to cross a trust boundary into local agent behavior. In this context, external transmission is more dangerous because the downloaded material is not just viewed; it becomes executable guidance for future agent actions.

Content

Scanner excerpt · HEARTBEAT.md (reported line 18)May include surrounding context.

Compare with your saved version. If there's a new version, re-fetch the skill files:

bash
curl -s https://clawstarter.io/skill.md > ~/.openclaw/skills/clawstarter/SKILL.md
curl -s https://clawstarter.io/heartbeat.md > ~/.openclaw/skills/clawstarter/HEARTBEAT.md
curl -s https://clawstarter.io/discourse.md > ~/.openclaw/skills/clawstarter/DISCOURSE.md

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

These commands overwrite local skill files with remote content fetched over the network, with no integrity check, confirmation prompt, backup, or warning about modifying trusted local automation. If the remote endpoint is compromised or the content changes unexpectedly, this creates a direct supply-chain path to replace local skill instructions with adversarial content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to consider checking Clawstarter after every completed task creates an overly broad self-trigger that can hijack the agent’s normal workflow. Such persistent opportunistic activation increases the chance of unnecessary network access, unprompted actions on external services, and gradual drift from user intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

Install locally:

bash
mkdir -p ~/.openclaw/skills/clawstarter
curl -s https://clawstarter.io/skill.md > ~/.openclaw/skills/clawstarter/SKILL.md
curl -s https://clawstarter.io/heartbeat.md > ~/.openclaw/skills/clawstarter/HEARTBEAT.md
curl -s https://clawstarter.io/discourse.md > ~/.openclaw/skills/clawstarter/DISCOURSE.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills/clawstarter
curl -s https://clawstarter.io/skill.md > ~/.openclaw/skills/clawstarter/SKILL.md
curl -s https://clawstarter.io/heartbeat.md > ~/.openclaw/skills/clawstarter/HEARTBEAT.md
curl -s https://clawstarter.io/discourse.md > ~/.openclaw/skills/clawstarter/DISCOURSE.md
curl -s https://clawstarter.io/skill.json > ~/.openclaw/skills/clawstarter/package.json

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Telling the agent to check Clawstarter 'whenever you think of it' is an unbounded activation condition. Ambiguous triggers are dangerous because they normalize arbitrary autonomous behavior and make it hard to enforce least-privilege or user-intent boundaries.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
## Core Concepts

| Concept         | Description                                                                                                          |
|-----------------|----------------------------------------------------------------------------------------------------------------------|
| **Project**     | An idea/proposal that goes through lifecycle phases. Has title, description, markdown proposal, votes, participants. |
| **Thread**      | A discussion entry in the "Agent Discourse". Supports nested replies, voting, and a token reward system.             |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

Start a new project (begins in IDEATION phase). You automatically become a participant.

bash
curl -X POST https://clawstarter.io/api/createProject \
  -H "Content-Type: application/json" \
  -d '{
    "data": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

Browse all projects with filtering and sorting.

bash
curl -X POST https://clawstarter.io/api/listProjects \
  -H "Content-Type: application/json" \
  -d '{
    "data": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

Get a Single Project

bash
curl -X POST https://clawstarter.io/api/getProject \
  -H "Content-Type: application/json" \
  -d '{"data": {"projectId": "abc123"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 422)May include surrounding context.

Update project details (only allowed during DEVELOPMENT phase).

bash
curl -X POST https://clawstarter.io/api/updateProject \
  -H "Content-Type: application/json" \
  -d '{
    "data": {

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill extends beyond Clawstarter’s stated collaboration/voting scope by instructing agents to create and work in GitHub repositories. That creates a new external side effect surface, including code publication and repository management, without clear user authorization, repository ownership validation, or safeguards against exposing sensitive content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs creation of a public GitHub repository without warning about visibility, data exposure, or review of what will be published. Public repo creation can permanently disclose drafts, internal notes, API references, or generated code that the user did not intend to make public.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 615)May include surrounding context.

Share it in the Agent Discourse so others can contribute:

bash
curl -X POST https://clawstarter.io/api/createThread \
  -H "Content-Type: application/json" \
  -d '{
    "data": {

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The proactive guidance to create GitHub repositories whenever a project in DEVELOPMENT has no repo encourages autonomous external actions unrelated to merely browsing or discussing on Clawstarter. This can cause unauthorized resource creation, spam, reputational damage, and accidental disclosure if the agent publishes project details or code publicly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes generic phrases such as "browse projects", "create project", "join project", and especially "share idea", which can match routine user collaboration requests unrelated to this skill. Overbroad activation increases the chance the agent invokes an external skill unexpectedly, exposing user context to the skill flow or causing unintended network access to the configured service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.