Back to skill

Security audit

ClawCap

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for a spending-cap proxy, but it routes all AI provider traffic and credentials through a third-party service and persists a live proxy token in local config.

Install only if you trust ClawCap to process your prompts, responses, metadata, and provider API credentials. Review which providers will be patched, consider rotating provider keys after testing, protect ~/.openclaw/openclaw.json, and use the uninstall script or backup to restore direct provider URLs if you stop using the service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Error
Location
scripts/setup.js:105
Finding

AI Provider Credentials and Traffic Routed Through an External Proxy

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.js:159
Finding

Proxy Token Persisted and Exposed in URL Paths and Console Output

Content
View full analysis
Remediation
View remediation
`. 3. Keep the token in an environment variable, operating-system credential store, or another dedicated secret-management mechanism rather than embedding it in `baseUrl`. 4. Redact tokens in console output, displaying only a short non-sensitive suffix when identification is necessary. 5. Do not print copyable commands containing live credentials. 6. Ensure the OpenClaw configuration file has owner-only permissions, such as mode `0600`, before and after rewriting it. 7. Prevent authorization headers from being recorded by application, proxy, and observability logs. 8. Add token expiration, rotation, revocation, and narrowly scoped permissions. 9. Treat existing tokens as potentially exposed through configurations and logs, and advise affected users to rotate them. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A second description-behavior mismatch indicates the skill may also perform local restoration or uninstall-style config changes without implementing the advertised budget enforcement, loop detection, or remote termination capabilities in the package. This is dangerous because deceptive or incomplete capability claims can cause operators to overtrust the skill and deploy it as a security or cost-control mechanism when it does not provide those guarantees locally.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A second description-behavior mismatch indicates the skill may also perform local restoration or uninstall-style config changes without implementing the advertised budget enforcement, loop detection, or remote termination capabilities in the package. This is dangerous because deceptive or incomplete capability claims can cause operators to overtrust the skill and deploy it as a security or cost-control mechanism when it does not provide those guarantees locally.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope or permissions despite requiring environment access, shell execution, and network use. This is dangerous because users cannot accurately assess that setup will execute a local Node script, read and modify OpenClaw configuration, and exfiltrate routing metadata to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to redirect every provider baseUrl to https://clawcap.co/proxy/YOUR_TOKEN, which means prompts, responses, API credentials, and model metadata may transit a third-party service. Without a prominent warning about data handling, retention, trust boundaries, and privacy implications, users may unknowingly expose sensitive model traffic to an additional intermediary.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script documentation explicitly says it does not run network requests, yet it invokes the system browser to open an external signup page. Even though the script itself is not performing an HTTP request directly, launching a remote URL is still a network-related action and weakens user trust by understating external interaction during setup.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The header claims the script does not read, store, or transmit API keys, but it does read a credential-like token from both an environment variable and interactive input. While the token appears to be intended for proxy configuration rather than exfiltration, the documentation is materially misleading about credential handling.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.js (reported line 190)May include surrounding context.

js
process.exit(0);
  }

  // Write updated config (only to validated path within ~/.openclaw/)
  const safePath = validatePath(configPath);
  fs.writeFileSync(safePath, JSON.stringify(config, null, 2) + '\n', 'utf8');

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script rewrites all configured model provider base URLs to a ClawCap-controlled proxy, causing subsequent model prompts, responses, and potentially provider credentials to transit through a third-party endpoint. In a tool whose purpose is cross-provider spend enforcement, this behavior is expected, but it is still security-sensitive and dangerous if users are not explicitly warned about the traffic redirection and trust implications.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.js (reported line 39)May include surrounding context.

js
function validatePath(filePath) {
  const resolved = path.resolve(filePath);
  if (!resolved.startsWith(ALLOWED_DIR)) {
    console.error('Error: Refusing to write outside ~/.openclaw/ directory.');
    process.exit(1);
  }
  return resolved;

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/uninstall.js (reported line 26)May include surrounding context.

js
function validatePath(filePath) {
  const resolved = path.resolve(filePath);
  if (!resolved.startsWith(ALLOWED_DIR)) {
    console.error('Error: Refusing to write outside ~/.openclaw/ directory.');
    process.exit(1);
  }
  return resolved;

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/setup.js:85