other
- Location
scripts/setup.js:105- Finding
AI Provider Credentials and Traffic Routed Through an External Proxy
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for a spending-cap proxy, but it routes all AI provider traffic and credentials through a third-party service and persists a live proxy token in local config.
Install only if you trust ClawCap to process your prompts, responses, metadata, and provider API credentials. Review which providers will be patched, consider rotating provider keys after testing, protect ~/.openclaw/openclaw.json, and use the uninstall script or backup to restore direct provider URLs if you stop using the service.
scripts/setup.js:105AI Provider Credentials and Traffic Routed Through an External Proxy
scripts/setup.js:159Proxy Token Persisted and Exposed in URL Paths and Console Output
A second description-behavior mismatch indicates the skill may also perform local restoration or uninstall-style config changes without implementing the advertised budget enforcement, loop detection, or remote termination capabilities in the package. This is dangerous because deceptive or incomplete capability claims can cause operators to overtrust the skill and deploy it as a security or cost-control mechanism when it does not provide those guarantees locally.
A second description-behavior mismatch indicates the skill may also perform local restoration or uninstall-style config changes without implementing the advertised budget enforcement, loop detection, or remote termination capabilities in the package. This is dangerous because deceptive or incomplete capability claims can cause operators to overtrust the skill and deploy it as a security or cost-control mechanism when it does not provide those guarantees locally.
The skill declares no explicit tool scope or permissions despite requiring environment access, shell execution, and network use. This is dangerous because users cannot accurately assess that setup will execute a local Node script, read and modify OpenClaw configuration, and exfiltrate routing metadata to an external service.
The skill instructs users to redirect every provider baseUrl to https://clawcap.co/proxy/YOUR_TOKEN, which means prompts, responses, API credentials, and model metadata may transit a third-party service. Without a prominent warning about data handling, retention, trust boundaries, and privacy implications, users may unknowingly expose sensitive model traffic to an additional intermediary.
The script documentation explicitly says it does not run network requests, yet it invokes the system browser to open an external signup page. Even though the script itself is not performing an HTTP request directly, launching a remote URL is still a network-related action and weakens user trust by understating external interaction during setup.
The header claims the script does not read, store, or transmit API keys, but it does read a credential-like token from both an environment variable and interactive input. While the token appears to be intended for proxy configuration rather than exfiltration, the documentation is materially misleading about credential handling.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
process.exit(0);
}
// Write updated config (only to validated path within ~/.openclaw/)
const safePath = validatePath(configPath);
fs.writeFileSync(safePath, JSON.stringify(config, null, 2) + '\n', 'utf8');
The script rewrites all configured model provider base URLs to a ClawCap-controlled proxy, causing subsequent model prompts, responses, and potentially provider credentials to transit through a third-party endpoint. In a tool whose purpose is cross-provider spend enforcement, this behavior is expected, but it is still security-sensitive and dangerous if users are not explicitly warned about the traffic redirection and trust implications.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
function validatePath(filePath) {
const resolved = path.resolve(filePath);
if (!resolved.startsWith(ALLOWED_DIR)) {
console.error('Error: Refusing to write outside ~/.openclaw/ directory.');
process.exit(1);
}
return resolved;
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
function validatePath(filePath) {
const resolved = path.resolve(filePath);
if (!resolved.startsWith(ALLOWED_DIR)) {
console.error('Error: Refusing to write outside ~/.openclaw/ directory.');
process.exit(1);
}
return resolved;
Detected: suspicious.dangerous_exec