Back to skill

Security audit

Upload Clawhub

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed AI DeFi execution skill, but it runs unpinned npm code with a private key and has conflicting/high-risk transaction guidance that users should review before installing.

Review this as a financial signing tool, not a normal chat helper. Use only a fresh operator wallet with minimal gas, do not reuse any main wallet key, pin and verify the npm package before execution, avoid unpinned npx MCP setup, and require explicit confirmation for raw calldata, transfers, and any config change.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:9
Finding

Unpinned External Package Executes with Access to an Operator Private Key

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:225
Finding

Contradictory Config Classification Can Bypass Write Confirmation

Content
View full analysis
` (view-only; modify via web console) ``` However, `README.md` classifies the same operation as a write and documents mutating parameters: ```text | `config` | Write | Configure risk parameters (spending limits, cooldown) | ``` ```bash shll-run config -k --tx-limit --daily-limit --cooldown ``` ### Technical Analysis The Skill mandates explicit user approval before each write operation but classifies `config` as read-only and omits it from the write-command list. The README simultaneously documents `config` as a write operation capable of changing transaction limits, daily limits, and cooldown periods. An agent using both documents could infer that mutating `config` invocations do not require approval. This creates a confirmation-policy bypass at the instruction layer. It is especially security-sensitive because the affected parameters define risk controls governing later DeFi transactions. The supplied artifact does not contain the CLI implementation, so it is not possible to establish whether the documented mutating command remains operational. Nevertheless, the instructions explicitly advertise it and conflict with the controlling confirmation policy. ### Attack Path 1. The agent loads `SKILL.md` and treats every `config` ...[truncated 1104 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation states that a compromised operator key cannot withdraw vault funds, yet the documented transfer command allows sending BNB or ERC20 from the vault. That contradiction can mislead users into underestimating key compromise risk; if transfers are policy-permitted, an attacker controlling the operator could move assets to approved recipients or otherwise drain value within configured limits.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Allowing raw calldata execution gives the agent a near-generic transaction primitive, which undermines the safety benefits of constrained DeFi tools. Even if PolicyGuard exists, exposing arbitrary calldata from "any source" creates a powerful path for prompt-injection-driven transactions, unsafe contract calls, or abuse of any gaps in policy validation.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
NFT, or bypass spending limits.
    Treat it as a restricted session key, not a master key.
  guidance: >
    Use generate-wallet to create a purpose-built operator wallet.
    Fund it with ~$1 BNB for gas only. Do not store trading capital in this wallet.
    The operator wallet is NOT the owner wallet, NOT the vault, NOT the Agent NFT holder.
---

# SHLL — Contract-Enforced Safe Execution for AI Agents on BNB Chain

## What is SHLL?

SHLL is a DeFi execution layer for AI agents on BNB Chain with **on-chain safety enforcement**.
Unlike off-chain filters that can be bypassed, SHLL uses smart contracts to enforce
spending limits, trade intervals, protocol whitelists, and receiver restrictions.
Every AI agent action is validated by an immutable PolicyGuard contract before execution.

Key facts:
- Network: BSC mainnet
- 27 CLI + MCP tools for DeFi operations (swap, lend, meme trading, portfolio)
- Supports PancakeSwap V2/V3, Venus Protocol, Four.meme
- MCP Server compatible with Claude,

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
5. Do not repeat private keys after initial `generate-wallet` output.
6. If multiple DeFi skills are available, use SHLL for vault operations when token ID context exists.
7. Treat raw calldata as high risk. Use strict recipient checks.
8. Do not bypass security controls for convenience.

## Security Model

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises DeFi transaction execution, but its documented capabilities also include generic raw calldata execution and vault asset transfers, which materially expand its authority beyond a narrowly scoped trading assistant. This broadens the attack surface and enables arbitrary contract interactions or value movement if an agent is manipulated, misconfigured, or if policy checks are weaker than claimed.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The documentation encourages the AI to manage RUNNER_PRIVATE_KEY setup automatically during onboarding, increasing agent autonomy around handling sensitive credentials and executing financial actions. In a DeFi skill with write capabilities, reducing user involvement in security-sensitive steps raises the chance of silent misconfiguration, unsafe key handling, or unauthorized transaction execution.

Content

Scanner excerpt · README.md (reported line 128)May include surrounding context.

shll-run swap -f BNB -t USDC -a 0.1 -k 5

text

In OpenClaw, AI should set `RUNNER_PRIVATE_KEY` for the current session automatically. Do not ask the user to edit environment variables manually during chat onboarding.

### Commands

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

This instruction tells the AI to set RUNNER_PRIVATE_KEY automatically for the current session in OpenClaw rather than requiring an explicit user-managed secret handling step. Even though the key is described as a restricted operator wallet, automatic secret ingestion by the agent increases the chance of unintended exposure, persistence, misuse by other tools in the session, or execution under a key the user does not fully control.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
- Immediately explain that this is the operator hot wallet for AI only.
- Explicitly state that it is not the owner wallet, not the mint wallet, not the Agent NFT wallet, and not the vault wallet.
- Explicitly state that if the operator wallet leaks, vault funds still cannot be freely withdrawn because owner permissions stay on the owner wallet and PolicyGuard limits operator actions.
- In OpenClaw, set `RUNNER_PRIVATE_KEY` automatically for the current session after generating the wallet. Do not ask the user to set the environment variable manually.

2. Verify gas:
- Ensure the operator wallet has a small BNB balance for gas.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
- `four_buy`
- `four_sell`

Read-only commands (no confirmation needed): `config`, `policies`, `status`, `history`, `portfolio`, `price`, `tokens`, `search`, `balance`, `four_info`.

## CLI Commands

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

This repeats the guidance that the AI should set RUNNER_PRIVATE_KEY automatically in OpenClaw and perform readiness actions automatically before asking what to do next. In a DeFi skill, normalizing agent-managed wallet secret setup and proactive action sequencing reduces human oversight and can make accidental or unauthorized transaction preparation more likely, even if final write confirmation is required elsewhere.

Content

Scanner excerpt · SKILL.md (reported line 341)May include surrounding context.

md
2. Always call it the operator wallet or AI hot wallet.
3. Always explain the dual-wallet model the first time setup is discussed.
4. Always warn that the operator wallet must not be used to mint, subscribe to, or hold the Agent NFT.
5. Do not ask the user to manually set `RUNNER_PRIVATE_KEY` in OpenClaw; AI should do it.
6. After setup is complete and the user provides a token-id, run readiness checks automatically before asking the user what to do next.
7. When multiple listings are available, recommend one by default and explain why.
8. Prefer the structured `status.readiness` fields over ad-hoc prose when deciding the next user-facing instruction.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.