Back to skill

Security audit

Billionsnetwork Verified Agent Identity 0.0.2

Security checks for vulnerabilities and agentic risk

Overview

This identity skill is coherent, but it should be reviewed carefully because it stores long-lived private identity keys unencrypted on disk without enforcing private file permissions.

Install only if you are comfortable with this skill creating durable identity keys under $HOME/.openclaw/billions. Treat kms.json like a wallet secret, avoid importing valuable existing private keys with --key, check file permissions after use, and prefer running it on a single-user machine until the key storage is encrypted or permission-hardened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/shared/storage/base.js:28
Finding

Unencrypted Private Keys Stored Without Enforced Owner-Only Permissions

Content
View full analysis
entry.alias === args.alias); if (index >= 0) { keys[index].privateKeyHex = args.key; } else { keys.push({ alias: args.alias, privateKeyHex: args.key }); } await this.writeFile(keys); } ``` The containing directory is also created without an explicit restrictive mode: ```js // scripts/shared/storage/base.js:8-11 async ensureDirectory() { const dir = path.dirname(this.filePath); await fs.mkdir(dir, { recursive: true }); } ``` ### Technical Analysis `KeysFileStorage` serializes private keys as plaintext JSON entries in `$HOME/.openclaw/billions/kms.json`. The generic storage implementation creates the directory and writes the temporary file without specifying owner-only permission modes. The resulting permissions depend on the process umask. Under a common `0022` umask, the directory may be created as `0755` and the key file as `0644`, allowing other local users to traverse the directory and read the unencrypted private keys. The implementation also does not correct insecure permissions on pre-existing directories or files. The temporary file `${this.filePath}.tmp` contains the same sensitive data and is subject to the same permissions. Although renaming the temporary file reduces partial-write risk, it does not protec ...[truncated 1470 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/createNewEthereumIdentity.js:24
Finding

Private Keys Accepted Through Observable Command-Line Arguments

Content
View full analysis
``` ### Technical Analysis An existing Ethereum private key can be supplied using the `--key` command-line option. Command-line arguments are not an appropriate secret-delivery mechanism because they may be exposed through: - Shell history files. - Process-listing and process-inspection interfaces. - Terminal session recording. - Job runners and orchestration telemetry. - Debugging, auditing, or endpoint-monitoring tools. - Wrapper scripts and command logs. The private key grants durable control over the identity, so exposure is substantially more serious than disclosure of a short-lived token. Input validation by `SigningKey` does not mitigate disclosure because the exposure occurs before or while the script processes the argument. ### Attack Path 1. A user follows the documented example and invokes the script with `- ...[truncated 1166 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (43)

Known Vulnerable Dependency: shell-quote==1.8.3 — 2 advisory(ies): CVE-2026-13311 (shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)); CVE-2026-9277 (shell-quote quote() does not escape newlines in object .op values)

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

shell-quote 1.8.3 is flagged for both quadratic-complexity DoS in parse() and newline escaping issues in quote() for object .op values. In a skill that may construct or parse shell-like command strings for agent actions, this is especially dangerous because it can lead to command-injection-adjacent boundary breaks or service degradation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: shell-quote==1.8.3 — 2 advisory(ies): CVE-2026-13311 (shell-quote: Quadratic-complexity Denial of Service in `parse()` (CWE-407)); CVE-2026-9277 (shell-quote quote() does not escape newlines in object .op values)

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

shell-quote 1.8.3 is flagged with advisories for quadratic-complexity denial of service and improper newline escaping in quote()-related behavior. In an agent skill that may process user-controlled command-like strings, this can enable resource exhaustion or unsafe shell argument construction, making the issue more dangerous than in a purely internal-only context.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared purpose is identity management, but the documented behavior also includes sending direct messages through openclaw message send. That hidden communication side effect can be abused to transmit signed tokens, identifiers, or other sensitive data to an attacker-controlled recipient under the guise of a normal identity workflow.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.


name: verified-agent-identity description: Billions/Iden3 authentication and identity management tools for agents. Link, proof, sign, and verify. metadata: { "category": "identity", "clawbot": { "requires": { "bins": ["node", "openclaw"] } }} homepage: https://billions.network/

When to use this Skill

Lets AI agents create and manage their own identities on the Billions Network, and link those identities to a human owner.

  1. When you need to link your agent identity to an owner.
  2. When you need sign a challenge.
  3. When you need link a human to the agent's DID.
  4. When you need to verify a signature to confirm identity ownership.
  5. When use shared JWT tokens for authentication.
  6. When you need to create and manage decentralized identities.

After installing the plugin run the following commands to create an identity and link it to your human DID:

bash
cd scripts && npm install && cd

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs agents to create and store identity material, and later explicitly states that kms.json contains unencrypted private keys, but it provides no up-front warning or consent step before use. This is dangerous because it normalizes generation and long-term storage of highly sensitive keys in plaintext, increasing the likelihood of theft, impersonation, and irreversible identity compromise.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The skill documents access to a directory containing unencrypted private keys, credentials, challenge history, and identity metadata. In an agent environment, merely exposing or normalizing access to this path materially raises the risk of credential theft, misuse of verifiable credentials, and account or DID impersonation if the skill or surrounding tooling is compromised.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
- `kms.json` - **CRITICAL**: Contains unencrypted private keys
- `defaultDid.json` - DID identifiers and public keys
- `challenges.json` - Authentication challenges history
- `credentials.json` - Verifiable credentials
- `identities.json` - Identity metadata
- `profiles.json` - Profile data

Known Vulnerable Dependency: ws==8.18.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

ws 8.18.0 is present and is reported with memory disclosure and memory exhaustion DoS advisories. Because this skill handles authentication/identity workflows and includes multiple network-facing libraries, a vulnerable WebSocket stack raises meaningful risk of denial of service or unintended data exposure if WebSocket features are exercised.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

brace-expansion 2.0.2 has multiple reported denial-of-service issues involving pathological expansion patterns. Even if this dependency is only used transitively, any path that accepts attacker-influenced glob or pattern input could be abused to cause CPU or memory exhaustion.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

fast-uri 3.1.0 is reported with multiple host-confusion and SSRF-related issues. In an auth/identity ecosystem that may resolve external identifiers, schemas, or DID-related resources, URI parsing flaws can materially increase the risk of SSRF or security boundary bypass.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==7.5.10 — 1 advisory(ies): CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
96% confidence
Finding

ws 7.5.10 is flagged for memory exhaustion DoS and is an older WebSocket branch still present transitively. If any component exposes or consumes WebSocket traffic from untrusted peers, attackers may be able to consume excessive resources and disrupt availability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: jsonpath==1.2.1 — 1 advisory(ies): CVE-2026-1615 (jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Express)

High
Category
Supply Chain
Confidence
98% confidence
Finding

jsonpath 1.2.1 is reported for arbitrary code injection via unsafe evaluation. Although it appears as a transitive/peer dependency, this is especially concerning because code-evaluation bugs can become RCE if attacker-controlled JSONPath expressions are ever processed.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: minimatch==5.1.6 — 3 advisory(ies): CVE-2026-27904 (minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regu); CVE-2026-26996 (minimatch has a ReDoS via repeated wildcards with non-matching literal in patter); CVE-2026-27903 (minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adja)

High
Category
Supply Chain
Confidence
94% confidence
Finding

minimatch 5.1.6 has several ReDoS issues caused by crafted wildcard/extglob patterns. This is a real denial-of-service risk anywhere attacker-controlled patterns reach matching logic, even if only through build or helper tooling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: underscore==1.13.6 — 1 advisory(ies): CVE-2026-27601 (Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS)

High
Category
Supply Chain
Confidence
92% confidence
Finding

underscore 1.13.6 is flagged for unlimited recursion in _.flatten and _.isEqual, enabling potential DoS. If deeply nested attacker-controlled objects are processed by dependent tooling, the process may crash or hang from stack exhaustion or excessive computation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==5.29.0 — 12 advisory(ies): CVE-2026-1525 (Undici has an HTTP Request/Response Smuggling issue); CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-1527 (Undici has CRLF Injection in undici via `upgrade` option) +9 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

undici 5.29.0 is reported with multiple HTTP smuggling, queue poisoning, and CRLF-related issues. In an identity/authentication skill that likely performs outbound HTTP requests to issuers, verifiers, schemas, or DID resources, flaws in the HTTP client stack can directly affect request integrity and SSRF-style controls.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

ws 8.17.1 is present separately and has reported memory disclosure and memory exhaustion DoS issues. Since this project includes blockchain, RPC, and identity libraries that commonly rely on WebSockets, the presence of multiple vulnerable ws versions increases the chance that an exposed runtime path is affected.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 97)May include surrounding context.

md
function newDataStorage(ethStateStorage) {
  return {
    credential: new CredentialStorage(
      new IdentitiesFileStorage("credentials.json"),
    ),
    identity: new IdentityStorage(
      new IdentitiesFileStorage("identities.json"),

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/shared/bootstrap.js (reported line 54)May include surrounding context.

js
function newDataStorage(ethStateStorage) {
  return {
    credential: new CredentialStorage(
      new IdentitiesFileStorage("credentials.json"),
    ),
    identity: new IdentityStorage(
      new IdentitiesFileStorage("identities.json"),

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to install and execute npx clawhub@latest, which pulls and runs the latest published package version at execution time rather than a pinned, reviewed version. This creates a supply-chain risk: if the package is compromised or a malicious update is published, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documentation again directs users to run npx clawhub@latest, which executes whatever version is currently published. Because this is an installation path for the skill itself, a compromised upstream package could lead to arbitrary code execution on the operator's machine before any other safeguards in the skill matter.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope or permissions despite requiring capabilities that can access the environment and send networked/direct messages via external CLIs. In an agent setting, missing scope boundaries increases the chance the skill is invoked with broader authority than intended, enabling unintended data access or message exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation guidance is broad and overlaps with many common identity-related requests, without clear boundaries on when the skill should or should not be used. In an agent ecosystem, this can cause over-triggering on loosely related prompts and lead to unnecessary identity creation, signing, or disclosure actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script imports raw Ethereum private key material directly into persistent KMS-backed storage without any explicit warning, consent, or indication of how that secret will be retained. In an identity-management skill, silently persisting a user-supplied or newly generated private key increases the blast radius of compromise: if the local store, host, backups, or downstream tooling are exposed, the attacker can recover the key and fully control the created identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code sends a generated pairing URL to the recipient via sendDirectMessage, which is a network/message transmission action. While the file documents URL creation, it does not provide a user-facing notice, confirmation, or comment disclosing that the script will transmit the verification link to another party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code persists private cryptographic keys directly to a JSON file on disk in plaintext and also exposes them via the list() method. In an identity/authentication skill, compromise of these keys can allow account impersonation, unauthorized signing, and long-term credential theft if the host filesystem, backups, logs, or developer workstation are accessed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The utility exposes an outbound messaging capability by invoking the external openclaw CLI and allows callers to send messages to arbitrary recipients. Even though execFileSync avoids classic shell injection and there is some input validation, this still grants the skill a side-effecting communication channel that exceeds the advertised identity/authentication scope and could be abused for exfiltration, spam, or unauthorized contact.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:134