Back to skill

Security audit

Identyclaw A2a Trust Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate trust-verification purpose, but its published helper code and dependency setup leave important credential and authorization checks too loosely controlled.

Review this skill before installing in a production agent fleet. Use only a reviewed, pinned @rodit/hola-client implementation; restrict IDENTYCLAW_BASE_URL to the official HTTPS endpoint or a trusted private deployment; configure a local expected recipient for receivers; and use narrowly scoped, short-lived IdentyClaw credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/verify-trusted-message.cjs:27
Finding

Configurable Verification Endpoint Can Receive the IdentyClaw Bearer Token

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/verify-trusted-message.cjs:59
Finding

Verification Is Not Bound to a Locally Configured Recipient

Content
View full analysis
Remediation
View remediation
` - `IDENTYCLAW_EXPECTED_RECIPIENT` - An immutable receiver configuration managed outside inbound messages. 2. Pass that local value—not `holaShape.recipient`—to `verifyHola`. 3. Fail closed when no expected recipient is configured for a directed-message workflow. 4. Require and validate the local Passport ID separately, then compare it with `envelope.to.tokenId`. 5. Normalize token IDs and recipient slots according to a documented canonical format before comparison. 6. Keep broadcast slots such as `MUNDO` or shared slots such as `FLEET` disabled unless explicitly authorized for the receiver. 7. Return a distinct error such as `RECIPIENT_MISMATCH` when either the HOLA recipient or envelope destination does not match local configuration. 8. Add tests covering: - Correctly addressed directed messages. - Valid messages addressed to another token. - Shared fleet slots. - Broadcast slots. - Case normalization. - Missing local receiver configuration. ]]>

T08 · Insecure Dependencies

Warning
Location
package.json:9
Finding

Core Cryptographic Dependency Resolves to Mutable Code Outside the Skill Artifact

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly relies on environment variables containing credentials and on network-capable plugins, but it does not declare a restrictive tool scope such as permissions or allowed-tools. That creates an avoidable expansion of agent capabilities and weakens reviewability, making it easier for the skill to access sensitive env secrets or perform network actions beyond the intended trust-verification workflow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
- name: IDENTYCLAW_TOKEN_ID
        required: true
        description: Your 12-letter IdentyClaw Passport ID
    homepage: https://api.identyclaw.com/openapi.json
---

# Trusted OpenClaw inter-agent messages

Static analysis

No suspicious patterns detected.