Back to skill

Security audit

verified-agent-identity-0.0.15

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent identity tooling, but it handles long-lived private keys with insecure defaults and broad agent-triggered signing/linking behavior.

Review this carefully before installing. Only use it in an environment where you are comfortable storing DID private keys under $HOME/.openclaw/billions, set a high-entropy BILLIONS_NETWORK_MASTER_KMS_KEY before creating or importing identities, avoid passing existing private keys on the command line, and require explicit human confirmation before signing or linking identity proofs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/shared/storage/keys.js:46
Finding

Private keys are stored in plaintext by default without enforced owner-only filesystem permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generateChallenge.js:17
Finding

Authentication challenges have low entropy, no expiration, and are reusable after successful verification

Content
View full analysis
entry.did === did); if (index >= 0) { // Update existing entry entries[index] = { did, challenge, created_at }; } else { // Add new entry entries.push({ did, challenge, created_at }); } await this.writeFile(entries); } ``` Successful verification does not consume the challenge: ```js // Verify the challenge matches const payload = basicMessage.body; if (payload.message !== challenge) { console.error( `Error: Invalid signature: challenge mismatch ${payload.message} !== ${challenge}`, ); process.exit(1); } outputSuccess("Signature verified successfully"); ``` ### Technical Analysis `randomInt(0, 10000000000)` provides approximately 33 bits of challenge entropy. Cryptographic authentication nonces should generally contain at least 128 unpredictable bits. Although challenge storage records `created_at`, `verifySignature.js` only compares the signed payload against the stored challenge. It does not reject old challenges and does not delete or mark a challenge as consumed after successful verification. A valid DID/token pair can therefore be verified repeatedly until another challenge overwrites the stored value. The signature itself may remain cryptographically valid, but the pro ...[truncated 1402 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/shared/storage/crypto.js:26
Finding

Master encryption keys are derived with fast, unsalted SHA-256

Content
View full analysis
Remediation
View remediation

other

Note
Location
scripts/verifySignature.js:27
Finding

Signature verification discloses queried DIDs to an external resolver

Content
View full analysis
{ const resp = await fetch( `https://resolver.privado.id/1.0/identifiers/${did}`, ); const didResolutionRes = await resp.json(); return didResolutionRes; }, }; ``` ### Technical Analysis Verification delegates DID document resolution to `https://resolver.privado.id`. This sends the queried DID to an external service and also exposes normal network metadata such as the source IP address, request timing, and frequency. The signed token and locally stored challenge are unpacked locally and are not explicitly sent in this request. Therefore, this behavior is not evidence of private-key or token exfiltration. Remote DID resolution is relevant to signature verification, but the specific third-party recipient and resulting privacy disclosure are not clearly documented in the Skill instructions. The implementation also does not check `resp.ok` before parsing the response, and the DID is interpolated into the URL path without explicit path-component encoding. ### Attack Path 1. A user invokes `verifySignature.js` for a target DID. 2. The Skill requests the DID document from `resolver.privado.id`. 3. The resolver receives the target DID together with source-network and timing metadata. 4. The resolver or an entity with access to its logs correlates the DID with the operator performing verification. 5. Repeated requests may reveal verification relationships or usage patterns. ### Impact Assessment The external resolver can observe which DIDs are being verified, when verification occurs, and from which network source. This may enable identity correlation, behavioral profiling, or disclosure of trust relationships. No p ...[truncated 136 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (36)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 97)May include surrounding context.

md
| `identities.json`  | Identity metadata                                                                  |
| `defaultDid.json`  | Active DID and associated public key                                               |
| `challenges.json`  | Per-DID challenge history                                                          |
| `credentials.json` | Verifiable credentials                                                             |

There are several ways of storing private keys, to enable master key encryption as described in the **KMS Encryption** section below.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The public description frames the skill as identity verification/linking, but the content also reveals local private-key storage, key import, retrieval, and optional plaintext-at-rest behavior. That mismatch is security-relevant because operators or upstream agents may invoke the skill assuming verification-only semantics, while it actually performs sensitive wallet/KMS functions that can expose or misuse long-lived credentials.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

entity description: Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentication proofs. Based on iden3 self-sovereign identity protocol. metadata: { "category": "identity", "clawdbot": { "requires": { "bins": ["node"] } } } homepage: https://billions.network/

When to use this Skill

Lets AI agents create and manage their own identities on the Billions Network, and link those identities to a human owner.

  1. When you need to link your agent identity to an owner.
  2. When you need to sign a challenge.
  3. When you need to link a human to the agent's DID.
  4. When you need to verify a signature to confirm identity ownership.
  5. When you use shared JWT tokens for authentication.
  6. When you need to create and manage decentralized identities.

After installing the plugin run the following commands to create an identity and link it to your human DID:

bash
cd scripts && npm inst

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The skill explicitly documents access to highly sensitive local credential material, including private keys in kms.json and verifiable credentials in credentials.json, with a note that keys may be stored in plaintext if a master key is not configured. In an agent skill, this is dangerous because any over-permissioned execution path, prompt-triggered misuse, or adjacent compromise could expose long-lived identity secrets and enable impersonation.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
- `kms.json` - **CRITICAL**: Contains private keys (encrypted if BILLIONS_NETWORK_MASTER_KMS_KEY is set, otherwise in plaintext)
- `defaultDid.json` - DID identifiers and public keys
- `challenges.json` - Authentication challenges history
- `credentials.json` - Verifiable credentials
- `identities.json` - Identity metadata
- `profiles.json` - Profile data

Known Vulnerable Dependency: ws==8.18.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
96% confidence
Finding

ws 8.18.0 is flagged for uninitialized memory disclosure and memory-exhaustion denial of service. In an agent skill that may maintain network/WebSocket connections to wallets, chains, or identity services, a vulnerable WebSocket stack materially increases exposure to remote attacks and service instability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

brace-expansion 2.0.2 is associated with multiple denial-of-service conditions due to pathological expansion behavior. If any code path processes attacker-influenced patterns, this can lead to CPU or memory exhaustion, which is significant for agent runtime availability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

fast-uri 3.1.0 is reported vulnerable to host confusion and SSRF-related parsing issues. In a decentralized identity skill that may resolve DIDs, fetch registries, or call remote endpoints, URL parser confusion can be especially dangerous because attacker-controlled identifiers or endpoints may be interpreted as trusted destinations.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==7.5.10 — 1 advisory(ies): CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding

ws 7.5.10 is vulnerable to memory exhaustion from fragmented/chunked frames, enabling remote denial of service. If this older branch is reachable through JSON-RPC or other networked components, an attacker could degrade or crash the agent service.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: underscore==1.13.6 — 1 advisory(ies): CVE-2026-27601 (Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS)

High
Category
Supply Chain
Confidence
92% confidence
Finding

underscore 1.13.6 is reported vulnerable to unbounded recursion in flatten and isEqual, which can trigger denial of service on crafted nested data. In agent ecosystems that may consume untrusted JSON or RPC payloads, such recursion-based DoS can be realistic.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==5.29.0 — 12 advisory(ies): CVE-2026-1525 (Undici has an HTTP Request/Response Smuggling issue); CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-1527 (Undici has CRLF Injection in undici via `upgrade` option) +9 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

undici 5.29.0 is flagged for multiple HTTP smuggling, queue poisoning, and header injection issues. This is particularly important here because identity and attestation workflows often depend on remote HTTP services, so a vulnerable HTTP client can expose the skill to SSRF-adjacent behaviors, request confusion, or response mixups.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
96% confidence
Finding

ws 8.17.1 is affected by memory disclosure and memory exhaustion vulnerabilities. Because this package likely supports real-time communication in transitive blockchain or RPC libraries, leaving it unpatched creates meaningful remote attack surface in a network-facing skill.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
73% confidence
Finding

The code persists credential data to a local file named credentials.json, and the same module also persists key and identity material through file-backed storage. In an agent identity context, these artifacts can contain highly sensitive authentication and identity data; if stored unencrypted or with weak filesystem protections, local compromise, accidental exposure, backup leakage, or multi-user host access could disclose credentials and enable impersonation or privacy loss.

Content

Scanner excerpt · scripts/shared/bootstrap.js (reported line 54)May include surrounding context.

js
function newDataStorage(ethStateStorage) {
  return {
    credential: new CredentialStorage(
      new IdentitiesFileStorage("credentials.json"),
    ),
    identity: new IdentityStorage(
      new IdentitiesFileStorage("identities.json"),

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This is a real vulnerability: when no master key is present, _encodeEntry falls back to provider: "plain" and writes privateKeyHex directly to disk. Because this module stores cryptographic private keys for agent identity and authentication, plaintext persistence materially increases the risk of credential theft from local compromise, backups, logs, developer machines, containers, or misconfigured volumes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to execute npx clawhub@latest install verified-agent-identity, which pulls and runs the latest package version at install time. This creates a supply-chain risk because a compromised or malicious future release could execute arbitrary code on the user's machine or agent host with no version pinning or integrity verification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This installation command again relies on npx clawhub@latest, which executes the newest published package version dynamically. In security-sensitive identity tooling, that increases the chance of supply-chain compromise leading to arbitrary code execution or credential theft during installation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope even though its documented behavior requires environment access and network interaction, which weakens least-privilege controls and makes it easier for an agent runtime to grant broader capabilities than necessary. In an identity/key-management skill, missing scope declarations are more dangerous because the same workflow touches local secrets and external registries, increasing the blast radius of misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The invocation guidance is broad enough to match common identity and authentication requests, which can cause agents to trigger this skill in situations involving generic JWTs, signatures, or identity linking without sufficient context checks. Because the skill can create identities and sign proofs, overbroad routing increases the risk of unintended credential operations or social-engineered identity assertions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example trigger phrase 'Link your agent identity to me' is overly permissive and encourages automatic execution of a sensitive identity-linking workflow based on ambiguous natural language. In this context, that is risky because a malicious user could socially engineer the agent into generating attestations or proofs without adequate verification of who is requesting the link or what trust relationship is being established.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code accepts a private key from user input, uses it to derive an identity, and then persists the resulting DID/public key data to storage. Although comments describe the steps for developers, there is no user-facing prompt, warning, or disclosure indicating that sensitive key material is being processed and that identity data will be saved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code creates persistent key storage in "kms.json", and later also initializes additional file-backed stores for credentials, identities, profiles, DIDs, and challenges. While comments describe what the code does for developers, there is no user-facing confirmation, warning, or visible disclosure that sensitive identity and key material will be written to local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The runtime is configured to contact external services, including the Billions Network RPC endpoint and the revocation status URL, which may transmit wallet-related or credential-status query data. The file contains developer comments but no user-facing notice, confirmation, or explicit warning that external network calls will occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script creates a JsonRpcProvider from the configured mainnet URL and passes the wallet into identity creation, which causes network interaction with an external RPC service. There is no user-facing message or warning that the operation will contact a remote network endpoint as part of creating the identity.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: uuid==13.0.0 — 1 advisory(ies): CVE-2026-41907 (uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided)

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile pins uuid 13.0.0, which is reported vulnerable to missing buffer bounds checks when callers use v3/v5/v6 with a caller-provided buffer. This is a real supply-chain risk, though impact is limited unless the skill or its dependencies invoke the affected APIs with untrusted input and custom buffers.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: uuid==9.0.1 — 1 advisory(ies): CVE-2026-41907 (uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided)

Low
Category
Supply Chain
Confidence
92% confidence
Finding

uuid 9.0.1 carries the same bounds-check issue affecting certain namespace/versioned UUID generation paths with provided buffers. This is a genuine vulnerable dependency, but the practical impact is typically low and usage-dependent.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ajv==8.17.1 — 1 advisory(ies): CVE-2025-69873 (ajv has ReDoS when using `$data` option)

Low
Category
Supply Chain
Confidence
84% confidence
Finding

ajv 8.17.1 is reportedly vulnerable to ReDoS when the $data option is enabled. This is a real issue, but exploitability depends on the application validating attacker-controlled schemas or values with $data-enabled patterns; the lockfile alone cannot confirm active exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.