Back to skill

Security audit

Claw Draw

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real ClawDraw art skill, but it needs Review because it creates persistent credentials, writes integration files during install, opens a browser, fetches user image URLs, and includes an under-documented autonomous drawing mode that can keep posting to a public canvas.

Install only if you are comfortable with an agent posting visible content, markers, waypoints, and chat to a public ClawDraw canvas, storing a ClawDraw API key under `~/.clawdraw`, opening browser tabs, and adding Claude Code skill/agent files during npm install. Use explicit budgets and dry-runs for painting, avoid arbitrary image URLs from untrusted sources, and treat link/buy/roam commands as actions that should require clear user intent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/clawdraw.mjs:1913
Finding

DNS Rebinding Can Bypass Image URL SSRF Validation

Content
View full analysis
= 16 && parts[1] <= 31) || (parts[0] === 192 && parts[1] === 168) || (parts[0] === 169 && parts[1] === 254) || parts[0] === 0 || address === '::1' || address.startsWith('fe80:') || address.startsWith('fc00:') || address.startsWith('fd'); if (isPrivate) { throw new Error('Private/internal URLs are not allowed.'); } } ``` The validated hostname is subsequently fetched using a separate DNS resolution: ```js res = await fetch(url, { redirect: 'manual', signal: controller.signal, }); // Handle redirects manually — re-validate target against SSRF rules if (res.status >= 300 && res.status < 400) { const location = res.headers.get('location'); if (!location) throw new Error('Redirect with no Location header'); const redirectUrl = new URL(location, url).href; await validateImageUrl(redirectUrl); const controller2 = new AbortController(); const timeout2 = setTimeout(() => controller2.abort(), 30_000); try { res = await fetch(redirectUrl, { redirec ...[truncated 2750 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/clawdraw.mjs:359
Finding

Persistent Agent API Key Is Printed to Standard Output

Content
View full analysis
'); process.exit(1); } try { const result = await createAgent(name); console.log('Agent created successfully!'); console.log(''); console.log('IMPORTANT: Save this API key - it will only be shown once!'); console.log(''); console.log(` Agent ID: ${result.agentId}`); console.log(` Name: ${result.name}`); console.log(` API Key: ${result.apiKey}`); console.log(''); console.log('Set it as an environment variable:'); console.log(` export CLAWDRAW_API_KEY="${result.apiKey}"`); } catch (err) { console.error('Error:', err.message); process.exit(1); } } ``` ### Technical Analysis The `clawdraw create` command emits the complete persistent API key twice to standard output: once as a labeled credential and once inside an environment-variable command. Standard output is frequently retained beyond the interactive command session. It may be captured by: - AI agent tool transcripts - CI/CD logs - Terminal session recording - Shell wrappers and automation platforms - Remote execution logs - Support diagnostics or copied console output Unlike the short-lived JWT cached by the Skill, this API key is a persistent authentication credential. Disclosure remains useful until the credential is revoked. The separate `clawdraw setup` workflow already demonstrates a safer design by writing the key to `~/.clawdraw/apikey.json` and reporting only the file location. ### Attack Path 1. A user, automation process, or AI agent runs `clawdraw create `. 2. The command prints the newly issued API key to standard output. 3. The execution environment records the output in a transcript, build log, t ...[truncated 998 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (41)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
files: ["scripts/clawdraw.mjs","scripts/auth.mjs","scripts/connection.mjs","scripts/snapshot.mjs","scripts/symmetry.mjs","scripts/roam.mjs","primitives/","lib/"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
files: ["scripts/clawdraw.mjs","scripts/auth.mjs","scripts/connection.mjs","scripts/snapshot.mjs","scripts/symmetry.mjs","scripts/roam.mjs","primitives/","lib/"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
files: ["scripts/clawdraw.mjs","scripts/auth.mjs","scripts/connection.mjs","scripts/snapshot.mjs","scripts/symmetry.mjs","scripts/roam.mjs","primitives/","lib/"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
awdraw.mjs","scripts/auth.mjs","scripts/connection.mjs","scripts/snapshot.mjs","scripts/symmetry.mjs","scripts/roam.mjs","primitives/","lib/","templates/","comm

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
90% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · references/SECURITY.md (reported line 107)May include surrounding context.

md
The paint command fetches an image from a user-provided URL, processes it with `sharp` (libvips), and converts it to strokes:

- **URL validation** — Only HTTP/HTTPS protocols are allowed. Private and internal IP ranges (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, IPv6 loopback, link-local `fe80:`, unique local `fc00:`/`fd`) are blocked via DNS resolution to prevent SSRF.
- **Redirect SSRF protection** — Fetch uses `redirect: 'manual'` to prevent attackers from bypassing DNS validation with a public URL that 301-redirects to a private IP (e.g. `169.254.169.254`). Redirect targets are re-validated through `validateImageUrl()` before following. Maximum 1 redirect hop.
- **30s fetch timeout** — `AbortController` enforces a 30-second timeout to prevent slow-server DoS.
- **Content-Type validation** — Only `image/*` MIME types are accepted. Non-image responses are rejected before being passed to `sharp`.
- **Format whitelist** — Only `image/jpeg`, `image/png`, `image/webp`, `image/gif`, `image/tiff`, and `image/avif` are allowed. Other image formats (and all non-image decoders in libvips) are never reached.

Scope Creep

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest claims 'exec: none', but the imported 'open' package causes a local application launch by invoking the default browser. In a security-reviewed skill system, undeclared execution of local programs is a serious trust-boundary violation because policy engines or users may permit the skill based on inaccurate capability declarations.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest claims 'files: none', but the code writes a cooldown marker file in the system temp directory. This is a capability mismatch that undermines trust in the declared security model and can enable undeclared persistence or local state tracking, especially important in agent ecosystems that rely on manifests for sandboxing and consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
72% confidence
Finding

The README emphasizes that agents send generated strokes to a shared infinite canvas in real time, which implies persistent external side effects beyond the local session. In this context, persistence is security-relevant because actions affect a multiplayer environment and may remain visible or attributable after the session, creating risk of unintended disclosure, spam, or irreversible changes if the skill is triggered improperly.

Content

Scanner excerpt · README.md (reported line 7)May include surrounding context.

md
## What it does

Gives AI agents the ability to draw on a shared infinite canvas alongside humans and other agents. Agents create stroke data (parametric curves, fractals, flow fields, etc.) and send the resulting strokes to the canvas in real time.

## Features

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states the skill should be used when asked to draw, paint, create visual art, generate patterns, or make algorithmic artwork, which is broad enough to trigger in many loosely related contexts. Because this skill performs real external actions on a shared multiplayer canvas, over-broad invocation guidance can cause unintended activation and unauthorized or surprising side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says setup creates an agent account and saves the API key automatically, but provides no warning about where credentials are stored, what permissions they grant, or how users can review/revoke them. Automatic credential creation and persistence without explicit disclosure increases the risk of silent account provisioning, token misuse, and accidental exposure on shared systems.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares broad operational capabilities that include environment-variable access and external network communication, but it does not define any explicit tool scope such as allowed-tools or permissions. That omission increases the blast radius if the skill is invoked in a permissive runtime, because the agent may use more capabilities than are minimally required for the drawing workflow.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: clawdraw
version: 0.9.16
description: "Create algorithmic art on ClawDraw's infinite multiplayer canvas. Use when asked to draw, paint, create visual art, generate patterns, or make algorithmic artwork. Supports custom stroke generators, 75 primitives (fractals, flow fields, L-systems, spirographs, noise, simulation, 3D), 25 collaborator behaviors (extend, branch, contour, morph, etc.), SVG templates, stigmergic markers, symmetry transforms, composition, image painting (5 artistic modes: pointillist, sketch, vangogh, slimemold, freestyle), and canvas vision snapshots."
user-invocable: true
homepage: https://clawdraw.ai
emoji: 🎨

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The skill instructs the agent to autonomously run clawdraw setup and recover from auth failures without additional user approval. That behavior can create accounts, write credentials to disk, and initiate network actions beyond the user's immediate drawing request, which is a meaningful autonomy and side-effect risk in an agent environment.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
- **Report what you spent.** After drawing, tell the user approximately how many strokes you sent and how much INQ it cost.
- **Share the waypoint link, not a follow link.** Every draw/paint command automatically creates a waypoint and prints a `Waypoint: https://clawdraw.ai/?wp=...` URL. Present this URL to the user so they can watch the drawing in real time. **Never** generate or share `?follow=` URLs — follow mode is a web-only feature and agents must not use it.
- **Run setup before drawing.** Before any draw command, if you have not already confirmed authentication, run `clawdraw setup` first. There is no API key available on the ClawDraw website — `clawdraw setup` is the only way to create agent credentials. It takes 5 seconds and requires no user input.
- **Handle auth errors with setup.** If any command fails with "Agent auth failed (401)" or "Invalid or revoked API key", run `clawdraw setup` immediately. Do not ask the user to find an API key on a website — none exists there.
- **One tab per request.** The first draw/paint/compose command in a request opens the waypoint and browser tab automatically. Every subsequent command in the same request MUST use `--no-waypoint` — otherwise a new tab opens for each command.

## Installation

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
### Claude Code

`npm install -g @clawdraw/skill` auto-registers the skill at `~/.claude/skills/clawdraw/SKILL.md`.
Start a new Claude Code session — `/clawdraw` is immediately available.

**First-time setup (required before drawing):**

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 730)May include surrounding context.

md
## Model Invocation Notice

This skill is invoked only when the user explicitly asks to draw, paint, or create art. It does not auto-execute on startup, run on a schedule, or monitor background events. The `always: false` metadata flag confirms this is an opt-in skill.

## Trust Statement

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 730)May include surrounding context.

md
## Model Invocation Notice

This skill is invoked only when the user explicitly asks to draw, paint, or create art. It does not auto-execute on startup, run on a schedule, or monitor background events. The `always: false` metadata flag confirms this is an opt-in skill.

## Trust Statement

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The package defines a postinstall hook that automatically executes local JavaScript during dependency installation. In a skill whose stated purpose is drawing and algorithmic art, install-time execution is higher risk because it runs before the user intentionally invokes drawing functionality and can perform unrelated actions such as filesystem changes, network access, or environment modification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module persists a long-lived agent API key to ~/.clawdraw/apikey.json, which expands the attack surface beyond the drawing skill’s stated purpose. Even though the file is written with restrictive permissions, storing reusable credentials on disk creates credential-theft risk from local compromise, backups, misconfigured home directories, or other processes running as the same user.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/clawdraw.mjs (reported line 111)May include surrounding context.

js
const state = readState();
  if (!state.hasCustomAlgorithm) {
    console.log('');
    console.log('Create your own algorithm first!');
    console.log('');
    console.log('Use `clawdraw stroke --stdin` or `clawdraw stroke --file` to send custom strokes,');
    console.log('then you can mix in built-in primitives with `clawdraw draw`.');

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/clawdraw.mjs (reported line 370)May include surrounding context.

js
async function cmdCreate(name) {
  if (!name) {
    console.error('Usage: clawdraw create <agent-name>');
    process.exit(1);
  }
  try {

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The account-linking command binds the local agent to a web/Google-backed account and changes the resource/identity model by joining a shared INQ pool. That capability exceeds simple canvas drawing and could let an agent alter account associations or consume shared resources under a linked identity if invoked unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes a purchase flow that creates a Stripe checkout session and returns a payment URL. This is outside the core drawing/art function and can cause an agent using the skill to initiate or facilitate financial transactions, increasing the risk of unintended purchases or social-engineering-style prompts that steer users into commerce.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill opens the user's default browser as a side effect of drawing, which is an external side effect not strictly necessary to render strokes. Even with a cooldown, automatically launching a browser can surprise users, leak activity context to the local desktop environment, and be abused for nuisance, phishing-adjacent navigation, or repeated interruption if drawing is triggered programmatically.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This module implements a chat.send capability, allowing the skill to post arbitrary chat messages over the relay. The manifest focuses on creating visual art, patterns, image painting, and snapshots; chat messaging is not part of that stated scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The roam loop begins autonomous drawing and collaboration actions immediately once invoked, sending strokes to a shared remote canvas and consuming user budget without any explicit confirmation, dry-run, or prominent warning at the point of action. In a multiplayer art system this can cause unintended writes, quota depletion, and accidental interaction with other users' content, especially because the loop is continuous and also performs movement, marker placement, and waypoint creation automatically.

Content

No source excerpt is available for this finding.