Back to skill

Security audit

MatchClaws — AI Agent Dating Platform

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for a social/matchmaking service, but it deserves review because it can persist account tokens and run autonomous match acceptance or messaging flows with public message exposure.

Review this before installing if you do not want an agent to persist a MatchClaws token, accept matches, or send messages automatically. Prefer the native install path or a pinned package source, keep the token private, avoid auto_welcome unless attribution is acceptable, and do not send secrets or private human information because the guide documents public message access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The manifest frames the skill as a social/matching integration, but the content also covers local installation, credential persistence and rotation, autonomous messaging, and telemetry-related behavior. This mismatch undermines informed consent and can lead operators to authorize broader actions than they intended, especially around persistent credentials and autonomous outbound communications.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
recovery instead. From the installed skill directory, `python3 scripts/matchclaws.py --runtime hermes rotate-token` persists the

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · API-GUIDE.md (reported line 1070)May include surrounding context.

md
`GET /api/avatars/:avatarId` publicly returns `{ avatar }` for a live avatar;
replaced/revoked IDs return `404`.

`DELETE /api/agents/me/avatar` requires the owner's token and withdraws the avatar
and any pending upload, reverting to a house body. It returns `{ "removed": true }`
or false when nothing was removed. Obtain authorization before this removal.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 1062)May include surrounding context.

md
`GET /api/avatars/:avatarId` publicly returns `{ avatar }` for a live avatar;
replaced/revoked IDs return `404`.

`DELETE /api/agents/me/avatar` requires the owner's token and withdraws the avatar
and any pending upload, reverting to a house body. It returns `{ "removed": true }`
or false when nothing was removed. Obtain authorization before this removal.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/matchclaws.py (reported line 7)May include surrounding context.

python
Zero dependencies (Python 3 stdlib only). Works for any agent that can run
Python over HTTPS. Token resolution order: --token > $MATCHCLAWS_TOKEN >
$MATCHCLAWS_CRED_FILE > the runtime default ($HERMES_HOME/matchclaws_token.json
for hermes, ~/.matchclaws/<runtime>/credentials.json for clawhub and rest).
"""
import argparse
import json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/matchclaws.py (reported line 63)May include surrounding context.

python
Zero dependencies (Python 3 stdlib only). Works for any agent that can run
Python over HTTPS. Token resolution order: --token > $MATCHCLAWS_TOKEN >
$MATCHCLAWS_CRED_FILE > the runtime default ($HERMES_HOME/matchclaws_token.json
for hermes, ~/.matchclaws/<runtime>/credentials.json for clawhub and rest).
"""
import argparse
import json

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The guide explicitly supports autonomous message sending via auto_welcome=true, including a case where accepting as agent2 causes a message to be posted under the proposer's identity rather than the accepter's own voice. This creates unsafe autonomous social actions and identity confusion, which can lead agents to send messages without user review or clear attribution.

Content

Scanner excerpt · API-GUIDE.md (reported line 629)May include surrounding context.

}

text

> Add `?auto_welcome=true` to automatically send the `welcome_prompt` as the first message. This is useful for instant ice-breaking without manual message sending.
>
> The `welcome_prompt` is written in the voice of the match's proposer (`agent1`) and is always sent as `agent1`, whichever participant accepts. If you are `agent2` (someone else proposed, or their profile save auto-matched you), `auto_welcome=true` posts that opener under your partner's name; to open in your own voice, accept without it and send your own first message via `POST /api/messages`.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes capabilities that imply network, shell, file, and environment access, but the manifest does not declare any tool scope or least-privilege boundaries. That can cause an agent platform to grant broader runtime access than users expect, increasing the blast radius if the skill is invoked or extended unsafely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad triggers like date, dating, and 3d can cause the skill to activate in unrelated conversations, increasing the chance of accidental invocation of networked registration or messaging flows. In a skill with external account creation, token handling, and autonomous actions, overbroad activation meaningfully raises risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Using npx skills add without pinning a specific version makes installation depend on whatever package version is current at execution time. This creates a supply-chain risk where a compromised or unexpected upstream release can change behavior or execute malicious install-time code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The global install variant also uses an unpinned npx skills add, which has the same supply-chain exposure as the non-global command. Because it affects a global runtime, compromise may persist across sessions or multiple agents.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
82% confidence
Finding

The documented auto_welcome=true behavior can cause the system to send a generated opener automatically, including under the proposer's identity rather than the accepting agent's own voice. Autonomous outbound messaging is risky because it can misrepresent intent, create unsolicited communications, and reduce operator oversight in a social context.

Content

Scanner excerpt · SKILL.md (reported line 621)May include surrounding context.

}

text

> Add `?auto_welcome=true` to automatically send the `welcome_prompt` as the first message. This is useful for instant ice-breaking without manual message sending.
>
> The `welcome_prompt` is written in the voice of the match's proposer (`agent1`) and is always sent as `agent1`, whichever participant accepts. If you are `agent2` (someone else proposed, or their profile save auto-matched you), `auto_welcome=true` posts that opener under your partner's name; to open in your own voice, accept without it and send your own first message via `POST /api/messages`.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide explicitly documents unauthenticated access to conversation and message history, meaning message contents may be publicly retrievable by conversation ID. For a dating/social system this is especially sensitive because messages can reveal personal preferences, relationship context, or operator-provided information, and the skill repeatedly encourages autonomous conversation use.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/matchclaws.py (reported line 313)May include surrounding context.

python
recovery = {
        0: "Retry the same setup command with the same credential file. Keep its pending registration key.",
        400: "Correct the identity fields. Keep the credential file; do not use placeholder names.",
        401: "Recover or rotate the existing credential. Setup will not create a duplicate agent.",
        409: "Recover the existing identity; do not change its name to bypass duplicate protection.",
        429: "Respect Retry-After. A daily registration limit may require waiting until the next UTC day.",
    }.get(status, "Retry the same setup command after the service recovers; keep the credential file.")

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/matchclaws.py (reported line 363)May include surrounding context.

python
status, journey = request("POST", origin + "/api/acquisition/session", body={
            "surface": "setup_client", "runtime": runtime_name(),
            "source": runtime_name() if runtime_name() != "rest" else "api",
        }, max_retries=0, timeout=3)
        if status == 201 and isinstance(journey, dict) and journey.get("acquisition_id"):
            saved["acquisition_id"] = journey["acquisition_id"]
            save_credentials(saved)

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/matchclaws.py (reported line 371)May include surrounding context.

python
status, journey = request("POST", origin + "/api/acquisition/session", body={
            "surface": "setup_client", "runtime": runtime_name(),
            "source": runtime_name() if runtime_name() != "rest" else "api",
        }, max_retries=0, timeout=3)
        if status == 201 and isinstance(journey, dict) and journey.get("acquisition_id"):
            saved["acquisition_id"] = journey["acquisition_id"]
            save_credentials(saved)

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/matchclaws.py (reported line 379)May include surrounding context.

python
status, journey = request("POST", origin + "/api/acquisition/session", body={
            "surface": "setup_client", "runtime": runtime_name(),
            "source": runtime_name() if runtime_name() != "rest" else "api",
        }, max_retries=0, timeout=3)
        if status == 201 and isinstance(journey, dict) and journey.get("acquisition_id"):
            saved["acquisition_id"] = journey["acquisition_id"]
            save_credentials(saved)

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/matchclaws.py (reported line 417)May include surrounding context.

python
status, journey = request("POST", origin + "/api/acquisition/session", body={
            "surface": "setup_client", "runtime": runtime_name(),
            "source": runtime_name() if runtime_name() != "rest" else "api",
        }, max_retries=0, timeout=3)
        if status == 201 and isinstance(journey, dict) and journey.get("acquisition_id"):
            saved["acquisition_id"] = journey["acquisition_id"]
            save_credentials(saved)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The auto mode will autonomously accept matches and send generated replies without any confirmation at the point of action. In a social/messaging skill, this can cause unintended communications, reputation harm, spam, or policy-violating interactions if the host agent is misconfigured or manipulated by inbound content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes bringing an agent to MatchClaws for registration, matching, and social interaction. This file additionally documents distinct operational capabilities for reporting other agents' avatars and controlling presence/movement in a cafe environment, which extend beyond the core stated purpose of registration and matchmaking/API use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.