Back to skill

Security audit

Billions Network - Verified Agent Identity

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its identity-management purpose, but it handles private keys and signed identity proofs in ways that need careful review before installation.

Install only if you are comfortable with this skill creating or importing cryptographic identities, storing unencrypted private keys under your home directory, and sending signed identity material or verification links through OpenClaw. Prefer generating a dedicated low-value key, avoid passing real private keys on the command line, verify recipients before linking, and review file permissions and dependency updates first.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/shared/storage/base.js:8
Finding

Plaintext Private Keys Are Stored Without Enforced Restrictive Permissions

Content
View full analysis
entry.alias === args.alias); if (index >= 0) { keys[index].privateKeyHex = args.key; } else { keys.push({ alias: args.alias, privateKeyHex: args.key }); } await this.writeFile(keys); } ``` ### Technical Analysis The key store serializes private keys directly into JSON as `privateKeyHex`. The shared storage implementation creates the `$HOME/.openclaw/billions` directory and its files without explicitly setting restrictive permission modes. Consequently, the actual permissions depend on the process umask and any pre-existing directory permissions. On a multi-user host or in an environment with an unsafe umask, `kms.json` or the temporary `kms.json.tmp` file may be readable by other local principals. The temporary file contains the same plaintext secrets as the final file. Renaming it does not correct its access mode because the renamed file retains the temporary file's permissions. The Skill documentation confirms that `kms.json` contains unencrypted private keys, making this a security boundary rather than ordinary application data. ### Attack Path 1. A user executes `createNewEthereumIdentity.js`, causing a pri ...[truncated 1315 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/verifySignature.js:18
Finding

Signed Verification Challenges Can Be Replayed Indefinitely

Content
View full analysis
entry.did === did); if (index >= 0) { // Update existing entry entries[index] = { did, challenge, created_at }; } else { // Add new entry entries.push({ did, challenge, created_at }); } await this.writeFile(entries); } async getChallenge(did) { const entry = await this.find(did); return entry?.challenge; } ``` `scripts/verifySignature.js:18-22,37-58`: ```js // Get the stored challenge const challenge = await challengeStorage.getChallenge(args.did); if (!challenge) { console.error(`Error: No challenge found for DID: ${args.did}`); console.error("Generate a challenge first with generateChallenge.js"); process.exit(1); } // Create JWS packer and unpack token const jws = new JWSPacker(kms, resolveDIDDocument); const basicMessage = await jws.unpack(byteEncoder.encode(args.token)); // Verify the sender if (basicMessage.from !== args.did) { console.error( `Error: Invalid from: expected from ${args.did}, got ${basicMessage.from}`, ); process.exit(1); } // Verify the challenge matches const payload = basicMessage.body; if (payload.message !== challenge) { console.error( `Error: Invalid signature: challenge mismatch ${payload.message} !== ${challenge}`, ); process.exit(1); } outputSuccess("Signature verified successfully"); ``` ### Technical Analysis Challenge records include a `created_at` value, but verification retrieves only the challenge text. It never checks the record's age. A successfully verified challenge is also not deleted, marked ...[truncated 1861 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/createNewEthereumIdentity.js:24
Finding

Existing Private Keys Are Accepted Through Process Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (42)

Known Vulnerable Dependency: shell-quote==1.8.3 — 2 advisory(ies): CVE-2026-13311 (shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)); CVE-2026-9277 (shell-quote quote() does not escape newlines in object .op values)

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

shell-quote 1.8.3 has reported issues including quadratic-complexity parsing DoS and newline escaping weaknesses in object operator values. In an agent skill, any library tied to shell command construction is especially sensitive because malformed escaping can contribute to command injection chains or policy bypass if commands are assembled from semi-trusted input.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: shell-quote==1.8.3 — 2 advisory(ies): CVE-2026-13311 (shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)); CVE-2026-9277 (shell-quote quote() does not escape newlines in object .op values)

Critical
Category
Supply Chain
Confidence
97% confidence
Finding

shell-quote 1.8.3 is reported with critical advisories including a quadratic-complexity denial-of-service issue in parse() and improper newline escaping in quote() object operator values. If this skill ever parses or constructs shell command fragments from untrusted data, an attacker could cause resource exhaustion or command-structure manipulation; the identity/authentication context raises concern because agent-facing inputs may be attacker-controlled.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 97)May include surrounding context.

md
| `identities.json`  | Identity metadata                               |
| `defaultDid.json`  | Active DID and associated public key            |
| `challenges.json`  | Per-DID challenge history                       |
| `credentials.json` | Verifiable credentials                          |

### Subprocess Execution Safety

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The stated purpose focuses on identity operations, but the skill also instructs direct outbound messaging via openclaw and implies shell/script execution. That mismatch is dangerous because users or orchestration layers may authorize it as a passive identity utility while it can actively transmit signed artifacts or identity-linked data to another party.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.


name: verified-agent-identity description: Billions/Iden3 authentication and identity management tools for agents. Link, proof, sign, and verify. metadata: { "category": "identity", "clawbot": { "requires": { "bins": ["node", "openclaw"] } }} homepage: https://billions.network/

When to use this Skill

Lets AI agents create and manage their own identities on the Billions Network, and link those identities to a human owner.

  1. When you need to link your agent identity to an owner.
  2. When you need sign a challenge.
  3. When you need link a human to the agent's DID.
  4. When you need to verify a signature to confirm identity ownership.
  5. When use shared JWT tokens for authentication.
  6. When you need to create and manage decentralized identities.

After installing the plugin run the following commands to create an identity and link it to your human DID:

bash
cd scripts && npm install && cd

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill explicitly documents storage of unencrypted private keys in kms.json alongside credentials and identity metadata in a predictable path under the user's home directory. If the agent, another skill, or a local attacker can read that directory, they can steal signing keys and credentials, fully impersonate the identity, and compromise authentication workflows.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
- `kms.json` - **CRITICAL**: Contains unencrypted private keys
- `defaultDid.json` - DID identifiers and public keys
- `challenges.json` - Authentication challenges history
- `credentials.json` - Verifiable credentials
- `identities.json` - Identity metadata
- `profiles.json` - Profile data

Known Vulnerable Dependency: ws==8.18.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

ws 8.18.0 is a real vulnerable dependency with advisories for memory disclosure and memory-exhaustion denial of service. In an agent identity/authentication skill, websocket connectivity may be exposed to untrusted peers or upstream services, making resource exhaustion and data exposure more operationally significant.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

brace-expansion 2.0.2 has multiple denial-of-service issues involving pathological patterns that can trigger excessive computation or memory use. Even if only used transitively in tooling-style paths, agent environments that process untrusted patterns or filenames can still be destabilized.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

fast-uri 3.1.0 is reported vulnerable to URI parsing ambiguities including host confusion and potential SSRF-enabling normalization bugs. In an identity/authentication skill that may fetch or resolve remote resources such as DIDs, schemas, or issuer metadata, URI parsing flaws can materially increase attack surface.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==7.5.10 — 1 advisory(ies): CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
96% confidence
Finding

ws 7.5.10 has a denial-of-service issue related to fragmented frames and tiny chunks, allowing attackers to consume memory disproportionately. If any exposed websocket client/server path interacts with untrusted endpoints, this can cause service instability or outage.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: jsonpath==1.2.1 — 1 advisory(ies): CVE-2026-1615 (jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Express)

High
Category
Supply Chain
Confidence
95% confidence
Finding

jsonpath 1.2.1 is reported to allow arbitrary code injection through unsafe evaluation of JSONPath expressions. Even though it appears under peer/tooling-related dependencies, any runtime path that evaluates attacker-controlled expressions would create severe code-execution risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: minimatch==5.1.6 — 3 advisory(ies): CVE-2026-27904 (minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regu); CVE-2026-26996 (minimatch has a ReDoS via repeated wildcards with non-matching literal in patter); CVE-2026-27903 (minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adja)

High
Category
Supply Chain
Confidence
92% confidence
Finding

minimatch 5.1.6 has several ReDoS-style issues where crafted glob patterns trigger catastrophic backtracking or combinatorial behavior. While often seen in build/tooling chains, an agent processing user-controlled patterns or filenames could be forced into CPU exhaustion.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: underscore==1.13.6 — 1 advisory(ies): CVE-2026-27601 (Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS)

High
Category
Supply Chain
Confidence
90% confidence
Finding

underscore 1.13.6 is vulnerable to unlimited recursion in functions like _.flatten and _.isEqual, enabling denial of service with deeply nested structures. If this path is reachable with untrusted JSON or message payloads, an attacker can crash or stall the agent process.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==5.29.0 — 12 advisory(ies): CVE-2026-1525 (Undici has an HTTP Request/Response Smuggling issue); CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-1527 (Undici has CRLF Injection in undici via `upgrade` option) +9 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

undici 5.29.0 has multiple reported HTTP parsing and request/response handling flaws, including smuggling and queue-poisoning classes of bugs. This is particularly relevant in an identity skill that may fetch remote DID documents, schemas, or verifier resources over HTTP, where attacker-controlled endpoints can influence protocol handling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

ws 8.17.1 is affected by the same memory disclosure and memory exhaustion issues noted for nearby ws versions. Because websocket traffic is inherently network-facing, these bugs can be exercised remotely when the dependency is used in reachable communication paths.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The bootstrap code stores sensitive credential and identity material in predictable local files such as credentials.json, identities.json, profiles.json, and kms.json. In an agent identity-management skill, these assets are highly sensitive: if local filesystem access is obtained by another process, user, container breakout, or misconfigured volume mount, an attacker could steal credentials, impersonate identities, or tamper with trust state.

Content

Scanner excerpt · scripts/shared/bootstrap.js (reported line 54)May include surrounding context.

js
function newDataStorage(ethStateStorage) {
  return {
    credential: new CredentialStorage(
      new IdentitiesFileStorage("credentials.json"),
    ),
    identity: new IdentityStorage(
      new IdentitiesFileStorage("identities.json"),

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run npx clawhub@latest install ..., which fetches and executes the latest published package version at install time rather than a pinned, reviewed version. This creates a supply-chain risk: if the package is compromised or a breaking/malicious update is published, users may execute attacker-controlled code simply by following the documented command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This installation command again uses npx clawhub@latest, causing execution of whatever package version is current on the registry at the time the command is run. In a security-sensitive identity-management skill, that raises the danger because installation may grant access to local files, secrets, and identity material if the upstream package is ever hijacked.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill documents capabilities that access sensitive local state ($HOME/.openclaw/billions) and perform networked messaging, but it does not declare explicit tool scope or permissions boundaries. In an agent environment, missing scope declarations can cause the host or operator to underestimate the skill's access, increasing the chance of unintended execution with broader privileges than expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs transmission of signed challenges, JWS tokens, and verification messages to other parties but does not clearly warn that these artifacts may reveal identity relationships, enable replay attempts in weak integrations, or create durable linkage between human and agent identities. Absent clear privacy/security warnings, users may unknowingly authorize sensitive disclosures.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example trigger phrase for linking identity is broad enough to match ordinary conversation, which can cause an agent to initiate sensitive identity-linking and signing flows without strong user intent verification. In this skill's context, that could lead to accidental disclosure of identity proofs or unintended association of an agent DID with an external party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code sends a sensitive verification/pairing URL directly to a recipient without any in-band warning, consent check, or contextual disclosure. Pairing URLs in identity flows can trigger high-trust wallet actions or verification ceremonies, so delivering them as a raw direct message increases phishing, confusion, and social-engineering risk if the recipient cannot clearly distinguish the message’s purpose and trust boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code initializes file-backed storage for key material via KeysFileStorage("kms.json"), which means sensitive cryptographic material is written to disk. Similar file-backed storage is also used for credentials, identities, DIDs, and challenges, but the file contains no confirmation prompt, user-facing log, or warning comment disclosing that sensitive data will be persisted locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The delete() method removes an identity record and persists the filtered result back to storage, which is a destructive operation affecting stored data. The code provides no confirmation, logging, or explanatory warning comment/docstring about this deletion behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code persists private keys directly to a local JSON file and later exposes them via list(), indicating the secrets are stored in plaintext with no encryption, access control, or warning to the caller. In an identity/authentication skill, compromise of these keys can enable account impersonation, unauthorized signing, and long-term identity takeover, making the issue more dangerous than generic local storage of non-sensitive data.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:134