T09 · Insecure Skill Coding Practices
- Location
scripts/verify-trusted-message.cjs:27- Finding
Configurable Verification Endpoint Can Receive the IdentyClaw Bearer Token
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a legitimate trust-verification purpose, but its published helper code and dependency setup leave important credential and authorization checks too loosely controlled.
Review this skill before installing in a production agent fleet. Use only a reviewed, pinned @rodit/hola-client implementation; restrict IDENTYCLAW_BASE_URL to the official HTTPS endpoint or a trusted private deployment; configure a local expected recipient for receivers; and use narrowly scoped, short-lived IdentyClaw credentials.
scripts/verify-trusted-message.cjs:27Configurable Verification Endpoint Can Receive the IdentyClaw Bearer Token
scripts/verify-trusted-message.cjs:59Verification Is Not Bound to a Locally Configured Recipient
package.json:9Core Cryptographic Dependency Resolves to Mutable Code Outside the Skill Artifact
The skill explicitly relies on environment variables containing credentials and on network-capable plugins, but it does not declare a restrictive tool scope such as permissions or allowed-tools. That creates an avoidable expansion of agent capabilities and weakens reviewability, making it easier for the skill to access sensitive env secrets or perform network actions beyond the intended trust-verification workflow.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- name: IDENTYCLAW_TOKEN_ID
required: true
description: Your 12-letter IdentyClaw Passport ID
homepage: https://api.identyclaw.com/openapi.json
---
# Trusted OpenClaw inter-agent messages
No suspicious patterns detected.