Back to skill

Security audit

Leanjutsu

Security checks for vulnerabilities and agentic risk

Overview

This identity skill is mostly purpose-aligned, but it handles powerful private keys and authentication proofs with unsafe defaults that users should review before installing.

Review this before installing. Use it only if you are comfortable with an agent managing DID private keys on this machine. Set BILLIONS_NETWORK_MASTER_KMS_KEY before creating or importing identities, lock down $HOME/.openclaw/billions to the current user, avoid passing private keys with --key because shell history and logs may capture them, and treat signed challenge tokens as sensitive. Prefer waiting for a version that enforces encrypted key storage, restrictive permissions, single-use expiring challenges, and pinned install instructions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/shared/storage/keys.js:48
Finding

Private Keys Are Stored in Plaintext by Default Without Enforced File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/verifySignature.js:18
Finding

Signed Authentication Challenges Can Be Replayed Indefinitely

Content
View full analysis
entry.did === did); if (index >= 0) { // Update existing entry entries[index] = { did, challenge, created_at }; } else { // Add new entry entries.push({ did, challenge, created_at }); } await this.writeFile(entries); } ``` From `scripts/shared/storage/challenge.js:30-33`: ```js async getChallenge(did) { const entry = await this.find(did); return entry?.challenge; } ``` From `scripts/verifySignature.js:18-23`: ```js // Get the stored challenge const challenge = await challengeStorage.getChallenge(args.did); if (!challenge) { console.error(`Error: No challenge found for DID: ${args.did}`); console.error("Generate a challenge first with generateChallenge.js"); process.exit(1); } ``` From `scripts/verifySignature.js:49-59`: ```js // Verify the challenge matches const payload = basicMessage.body; if (payload.message !== challenge) { console.error( `Error: Invalid signature: challenge mismatch ${payload.message} !== ${challenge}`, ); process.exit(1); } outputSuccess("Signature verified successfully"); ``` ### Technical Analysis Challenge records include a creation timestamp, but verification retrieves only the challenge value. It does not enforce a maximum age or validate the saved timestamp. After successful signature verification, the challenge is not deleted, invalidated, or marked as used. As a result, the same signed J ...[truncated 1663 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/createNewEthereumIdentity.js:22
Finding

Private Keys Can Be Exposed Through Command-Line Arguments

Content
View full analysis
] # Create identity from existing private key (with 0x prefix) node scripts/createNewEthereumIdentity.js --key 0x1234567890abcdef... # Create identity from existing private key (without 0x prefix) node scripts/createNewEthereumIdentity.js --key 1234567890abcdef... ``` ### Technical Analysis The Skill accepts an existing Ethereum private key through `--key`. Command-line arguments are not an appropriate secret transport because they may be visible through: - Shell history. - Process listings or operating-system process inspection. - Agent command-execution logs and transcripts. - Monitoring, auditing, crash-reporting, or telemetry systems. - Wrapper scripts that record invoked commands. The application does not print the key itself, but disclosure can occur before the process parses it. Therefore, preventing application logging alone does not mitigate the exposure. ### Attack Path 1. A user follows the documented example and invokes the script with `--key `. 2. The shell records the complete command in history, or a process/Agent monitoring component records the invocation. 3. A local attacker, administrator, compromised process, log reader, ...[truncated 727 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (40)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 97)May include surrounding context.

md
| `identities.json`  | Identity metadata                                                                  |
| `defaultDid.json`  | Active DID and associated public key                                               |
| `challenges.json`  | Per-DID challenge history                                                          |
| `credentials.json` | Verifiable credentials                                                             |

There are several ways of storing private keys, to enable master key encryption as described in the **KMS Encryption** section below.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as identity verification/linking functionality, but its documented behavior includes key management and local private key storage, including plaintext storage when no master key is configured. This mismatch can mislead users and orchestrators into invoking a skill that handles far more sensitive material than expected, increasing the chance of unsafe execution and secret exposure.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

entity description: Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentication proofs. Based on iden3 self-sovereign identity protocol. metadata: { "category": "identity", "clawdbot": { "requires": { "bins": ["node"] } } } homepage: https://billions.network/

When to use this Skill

Lets AI agents create and manage their own identities on the Billions Network, and link those identities to a human owner.

  1. When you need to link your agent identity to an owner.
  2. When you need to sign a challenge.
  3. When you need to link a human to the agent's DID.
  4. When you need to verify a signature to confirm identity ownership.
  5. When you use shared JWT tokens for authentication.
  6. When you need to create and manage decentralized identities.

After installing the plugin run the following commands to create an identity and link it to your human DID:

bash
cd scripts && npm inst

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill documents storage of highly sensitive artifacts including private keys and verifiable credentials under a predictable local directory, and notes that keys may be stored in plaintext. In an agent setting, any capability that can read local files or influence execution could expose credential material, enabling impersonation or unauthorized identity operations.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
- `kms.json` - **CRITICAL**: Contains private keys (encrypted if BILLIONS_NETWORK_MASTER_KMS_KEY is set, otherwise in plaintext)
- `defaultDid.json` - DID identifiers and public keys
- `challenges.json` - Authentication challenges history
- `credentials.json` - Verifiable credentials
- `identities.json` - Identity metadata
- `profiles.json` - Profile data

Known Vulnerable Dependency: ws==8.18.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding

ws 8.18.0 is flagged for memory disclosure and memory-exhaustion DoS issues. In an agent identity skill likely to accept network connections, proofs, or websocket-based messaging, a vulnerable websocket stack materially increases remote attack surface and can enable denial of service or leakage from process memory.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
87% confidence
Finding

brace-expansion 2.0.2 is associated with several expansion-based DoS conditions. Even if primarily build-tooling adjacent, lockfile presence means the package may be invoked in runtime or auxiliary agent workflows, and crafted patterns can drive extreme CPU or memory consumption.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

fast-uri 3.1.0 is flagged for multiple host-confusion and SSRF-related parsing issues. This is especially relevant in an identity/proof ecosystem that may resolve DIDs, fetch schemas, or contact registry endpoints, because malformed attacker-controlled URLs could bypass allowlists or redirect server-side requests.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==7.5.10 — 1 advisory(ies): CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
94% confidence
Finding

ws 7.5.10 is vulnerable to memory exhaustion from tiny fragments/data chunks. If any part of the skill or its dependencies exposes websocket endpoints or consumes untrusted websocket streams, an attacker may remotely degrade or crash the service with relatively low-cost traffic.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: underscore==1.13.6 — 1 advisory(ies): CVE-2026-27601 (Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS)

High
Category
Supply Chain
Confidence
90% confidence
Finding

underscore 1.13.6 is flagged for unlimited recursion in functions such as _.flatten and _.isEqual, allowing denial of service with crafted deeply nested inputs. In a skill handling identity documents, attestations, and JSON-like structures, attacker-supplied nested objects could trigger stack exhaustion or prolonged processing.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==5.29.0 — 12 advisory(ies): CVE-2026-1525 (Undici has an HTTP Request/Response Smuggling issue); CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-1527 (Undici has CRLF Injection in undici via `upgrade` option) +9 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

undici 5.29.0 is reported with multiple HTTP smuggling, queue poisoning, and header injection issues. This is particularly dangerous in an agent identity context because the skill likely performs outbound HTTP to registries, resolvers, or proof services; malformed responses or attacker-controlled endpoints could desynchronize requests, poison reused connections, or bypass assumptions about remote peers.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding

ws 8.17.1 is flagged for uninitialized memory disclosure and memory-exhaustion DoS. Given the networked, agent-to-agent identity use case, any websocket-enabled component increases exposure to remote attackers who can abuse framing behavior to leak process data or exhaust memory.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Persisting credentials to "credentials.json" creates a local cache of sensitive credential data that may include attestations or material useful for identity verification flows. In this skill’s context, compromise of that file can directly enable privacy loss, credential harvesting, or unauthorized reuse of identity artifacts, making the issue more serious than generic local app state storage.

Content

Scanner excerpt · scripts/shared/bootstrap.js (reported line 54)May include surrounding context.

js
function newDataStorage(ethStateStorage) {
  return {
    credential: new CredentialStorage(
      new IdentitiesFileStorage("credentials.json"),
    ),
    identity: new IdentityStorage(
      new IdentitiesFileStorage("identities.json"),

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub@latest install verified-agent-identity, which fetches and executes the latest CLI code at install time rather than a pinned, reviewed version. If the package or one of its distribution paths is compromised, users could execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This installation command again relies on npx clawhub@latest, causing remote code execution risk from an unpinned package version. Because installation is the first step users take, this expands supply-chain exposure before any trust decision about the skill itself can be made.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill requires Node and clearly performs operations involving local sensitive files and external identity/attestation workflows, yet it declares no explicit tool scope or permission boundaries. In an agent environment, this can cause overbroad execution authority and makes it easier for routine identity requests to trigger networked actions or access sensitive environment-backed secrets without clear user approval.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation guidance is broad enough to overlap with common identity and help requests, which increases the chance that an agent auto-selects this skill in normal conversations. Because the skill can create identities, sign challenges, and interact with sensitive local stores, broad triggering raises the risk of unintended key creation, identity linking, or disclosure-related actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup instructions encourage creating an identity and linking it immediately, but they do not prominently warn that this generates and stores highly sensitive private key material locally. Since the storage may be plaintext absent a master key, users may unknowingly create long-lived credentials in an insecure state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The script creates a JsonRpcProvider and passes an Ethereum signer into createEthereumBasedIdentity, which indicates network interaction with the configured chain service. This file does not provide a user-facing warning or disclosure that identity creation may contact a remote RPC endpoint and transmit identity-related data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code persists a new DID, public key, and default-status flag via didsStorage.save(...). While there are internal comments, there is no confirmation prompt, user-facing log, or other disclosure here that this operation will write identity data to storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code initializes key management using a file-backed keystore ("kms.json"), which means private key material is persisted to local disk. For an identity/authentication skill, storing long-lived signing keys in plaintext or weakly protected local files materially increases the risk of credential theft, agent impersonation, and unauthorized proof generation if the host or working directory is exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The runtime persists credentials, identities, profiles, DIDs, and challenge data to local JSON files without any visible access controls, minimization, or disclosure in this file. In a decentralized identity skill, these artifacts can contain sensitive metadata and authentication state that may aid account linkage, replay, deanonymization, or unauthorized access if read by other local users/processes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The list() method returns every stored private key in plaintext, expanding access far beyond simple key lookup or proof generation. In an identity/authentication skill, exposure of raw private keys enables full impersonation, unauthorized signing, and long-term compromise of agent identities if any caller or log path can access this method.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This script performs a private-key-backed signing operation over attacker-controlled input from --challenge without any confirmation, policy check, or restriction on what may be signed. In an agent identity skill, that is security-relevant because any caller able to invoke the script could obtain a valid authentication token or proof tied to the agent's DID, enabling misuse of the identity and replay of unintended attestations depending on downstream verifier behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends a user-supplied DID to a third-party resolver service during signature verification, which can disclose identifiers and verification activity to an external party. In an identity-verification skill, this creates a real privacy and metadata-leak risk because DIDs may be linkable to users or agents, and the resolver learns which identities are being checked and when.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: uuid==13.0.0 — 1 advisory(ies): CVE-2026-41907 (uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided)

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The lockfile includes uuid 13.0.0, which is flagged for a buffer-bounds issue when v3/v5/v6 are called with a caller-provided buffer. This is a real supply-chain risk, although impact depends on whether the vulnerable API shape is actually exercised; in an identity/proof stack that processes attacker-influenced identifiers, malformed inputs could still trigger crashes or memory-safety issues in dependent code paths.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.