Back to skill

Security audit

Qfc Openclaw Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent QFC blockchain toolkit, but it handles wallet secrets and irreversible transactions with under-enforced safety controls, so it needs review before use.

Use this only on a trusted machine and prefer testnet until you have reviewed every transaction flow. Do not use real mainnet keys unless you can verify prompts, recipients, amounts, contract addresses, allowances, and explorer submissions yourself; require explicit human confirmation before any transfer, approval, swap, marketplace purchase, deployment, or agent/session-key action. Treat generated or imported private keys as sensitive secrets, use strong unique keystore passwords, and prefer a pinned, reviewed dependency install path.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
src/wallet.ts:65
Finding

Transaction Safety Controls Are Not Enforced by Value-Transferring APIs

Content
View full analysis
{ if (!ethers.isAddress(to)) { throw new Error('Invalid address format. Expected 0x + 40 hex characters.'); } const wallet = this.requireWallet(); const tx = await wallet.sendTransaction({ to, value: ethers.parseEther(amount), gasLimit: opts?.gasLimit, }); ``` The ERC-20 transfer path similarly submits the transaction without invoking the security policy: ```ts async transfer( tokenAddress: string, to: string, amount: string, signer: ethers.Wallet, ): Promise { const connected = signer.connect(this.provider); const contract = new ethers.Contract(tokenAddress, ERC20_ABI, connected); const decimals = await contract.decimals(); const parsedAmount = ethers.parseUnits(amount, decimals); const tx = await contract.transfer(to, parsedAmount); ``` The project contains a policy implementation, but it is not integrated into these transaction paths: ```ts preTransactionCheck(tx: TransactionCheck): CheckResult { // Rule 1: Validate address format first — reject before any other processing if (tx.to.includes(' ') || tx.to.length !== 42 || !tx.to.startsWith('0x')) { return { approved: false, requiresConfirmation: false, warnings: ['Invalid address format — possible injection attempt'], }; } const warnings: string[] = []; let requiresConfirmation = this.config.requireConfirmAlways; // Rule 2: Large transaction (>100 QFC) if (tx.amount > 100) { warnings.push(`Large transaction: ${tx.amount} QFC exceeds 100 QFC threshold`); ...[truncated 2900 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/swap.ts:313
Finding

Automatic Unlimited ERC-20 Allowances to Caller-Supplied Contracts

Content
View full analysis
{ const token = new ethers.Contract(tokenAddress, ERC20_ABI, signer); const current = await token.allowance(signer.address, spender); if (current < amount) { const tx = await token.approve(spender, ethers.MaxUint256); const receipt = await this.waitForReceipt(tx.hash); if (receipt.status !== '0x1') { throw new Error(`Approval failed for ${tokenAddress} (tx: ${tx.hash})`); } } } ``` The airdrop implementation uses the same unlimited-approval pattern: ```ts // Check and set allowance const currentAllowance = await token.allowance(connected.address, airdropContract); if (currentAllowance < totalNeeded) { const approveTx = await token.approve(airdropContract, ethers.MaxUint256); const approveReceipt = await this.waitForReceipt(approveTx.hash); if (approveReceipt.status !== '0x1') { throw new Error(`Approval transaction reverted (tx: ${approveTx.hash})`); } } ``` ### Technical Analysis The affected methods approve `ethers.MaxUint256` whenever the existing allowance is lower than the amount needed for the current operation. This creates a persistent, effectively unlimited authorization even though the operation only needs a bounded allowance. The spender is derived from caller-supplied pool or airdrop contract addresses. The code does not establish that these addresses contain an expected contract implementation, are trusted deployments, or have bytecode matching the embedded pool or airdrop source. An ERC-20 allowance permits the approved spender to invoke `transf ...[truncated 1473 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:1
Finding

Non-Reproducible Dependency Installation Without a Lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (81)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This code chunk does not implement the declared QFC blockchain functionality. It only performs project setup by running npm install and npm run build. That is a materially different immediate behavior from the declared purpose. While setup scripts can be supporting infrastructure, the prompt asks whether the supplied code chunk accurately represents the description; this chunk itself is a build/setup script and does not exhibit the described wallet, chain, staking, or inference capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description is materially broader and partly inaccurate relative to the code. The code is focused on a specific AgentRegistry contract and supports agent lifecycle and session-key management plus preflight checks. It does perform some chain reads and write transactions, so it is related to blockchain interaction, but the named capabilities in the description—wallet, faucet, staking, epoch/finality, and AI inference—are not actually present in this chunk. Because the declared purpose suggests a substantially different and wider feature set than the implemented behavior, this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code chunk is narrowly focused on blockchain query operations and does not implement most of the declared capabilities. It creates a provider and exposes read-only methods for block, transaction, and receipt lookup. There is no wallet management, signing, sending transactions, faucet access, staking, epoch/finality-specific queries, or any AI inference logic in this chunk. Since the declared description presents a much broader purpose than the code actually performs, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description claims a broad blockchain toolkit covering wallet, faucet, chain queries, staking, epoch/finality, and AI inference. This code chunk instead focuses specifically on contract operations: calling contract methods, sending signed transactions to contracts, deploying contracts, checking deployed code, and submitting source code for verification. Some of this fits a generic 'blockchain interaction' label, but key implemented capabilities like contract deployment and verification are not declared, while many declared capabilities are not represented here. That makes the description materially inaccurate for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code’s core behavior is a Discord-oriented command handler that parses prefixed chat commands and formats bot responses, which is a meaningful undeclared capability relative to the description. While it does perform some declared blockchain interactions (faucet, wallet/balance, chain queries), it does not implement several prominently declared areas: staking, epoch/finality, or AI inference. Therefore the description does not accurately represent this code chunk’s actual functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description covers only a subset of the exported functionality: wallet, faucet, chain queries, staking, epoch/finality, and inference. The code chunk is an index file that re-exports many additional modules with materially broader capabilities unrelated to or beyond that description, including token/NFT tooling, swaps, marketplace operations, event systems, agents, Discord bot support, and miner monitoring. Since these are externally exposed capabilities rather than internal implementation details, the declared description does not accurately represent the full behavior of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is much broader and materially different from the supplied code. The code is specifically focused on NFT marketplace functionality on QFC: deploying a marketplace contract, listing ERC-721 tokens for sale, auto-approving NFTs, buying with native QFC, canceling listings, querying marketplace/listing state, and setting platform fees. It also includes embedded Solidity source and bytecode plus best-effort explorer verification. It does not implement faucet access, general wallet tooling, staking, epoch/finality queries, or AI inference. Because the actual primary purpose is an NFT marketplace rather than the declared blockchain interaction suite, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code chunk is narrowly focused on multicall infrastructure and batched read/query behavior, plus deployment of a Multicall3 contract and optional explorer verification. It does not implement the broad set of features claimed in the description such as wallet management, faucet use, staking, epoch/finality handling, or AI inference. Additionally, it includes a contract deployment capability that is not explicitly represented in the declared description. While chain queries are partially consistent, the overall declared purpose materially overstates and mischaracterizes what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code chunk is specifically an NFT module (src/nft.ts) for ERC-721 operations on QFC. Its concrete behavior is deploying a precompiled NFT contract, minting tokens, querying token data, and transferring tokens. That is a blockchain interaction skill, but it is materially narrower and different from the declared description, which emphasizes wallet, faucet, chain queries, staking, epoch/finality, and AI inference. The NFT capability is undeclared, while several declared capabilities are not represented here. This is a description-behavior mismatch rather than merely an incomplete implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broad blockchain interaction skill with wallet, faucet, chain queries, staking, epoch/finality, and AI inference capabilities. The supplied code does not implement any of those substantive behaviors except indirectly supporting wallet transaction handling. Instead, it focuses specifically on pre-transaction safety checks and spend tracking: validating recipient address format, marking known addresses, flagging large transfers, unknown recipients, contract calls, and daily limit excess, and determining whether confirmation is required or auto-approval is allowed. This is a materially different and narrower purpose than the declared feature set, and it adds an undeclared security policy capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code is specifically focused on decentralized exchange behavior on QFC: wrapped native token deployment and use, AMM pool deployment, liquidity management, swap quoting/execution, and limited on-chain reads related to pools/tokens. While this fits part of 'QFC blockchain interaction,' the declared description is much broader and prominently lists wallet, faucet, staking, epoch/finality, and AI inference capabilities that are not present in this code chunk. The code also performs contract deployment and explorer verification POST requests, which are still aligned with swap infrastructure, not the broader declared feature set. Therefore the description does not accurately represent this chunk's actual functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The declared description is broad QFC blockchain interaction with wallet, faucet, chain queries, staking, epoch/finality, and AI inference. The supplied code chunk is specifically a token module focused on ERC-20 token lifecycle and distribution operations on QFC. It includes contract bytecode/source for token and airdrop contracts, token deployment, mint/burn, approvals/transfers, portfolio/history lookups, and token launch with liquidity. Those are substantial capabilities not reflected in the declared description, while several declared areas (faucet, staking, epoch/finality, AI inference, general wallet features) are not present in this code chunk. This is a material description/behavior mismatch rather than merely an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code is clearly related to QFC blockchain interaction, so the domain is aligned. However, the declared description promises a much broader capability set than the supplied code actually implements. This chunk is focused on wallet and native token transfer operations plus keystore persistence. It does not implement faucet requests, staking, epoch/finality queries, or any AI inference behavior. While over-declaration alone is sometimes acceptable, here those absent capabilities are central parts of the declared purpose, making the description materially broader than the actual behavior of this code chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

swapTokenForQFC unwraps the caller's entire WQFC balance after the swap, not just the amount received from that transaction. This can unexpectedly convert previously held WQFC and interfere with other strategies or balances, causing unintended asset movement and exposing users to greater loss if the action was prompt-induced or the wallet held additional WQFC.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

createWallet() returns the mnemonic phrase and private key directly to the caller, which exposes the wallet's full secret material in process memory and to any upstream caller, logger, UI, or telemetry pipeline. In an agent skill context, this is especially dangerous because other components may automatically display, serialize, or persist tool outputs, turning key disclosure into immediate wallet compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

sendQFC() performs an irreversible on-chain value transfer immediately after basic address validation, with no application-level confirmation, policy check, recipient allowlist, or amount sanity validation. In an agent-integrated skill, this increases the risk of prompt-induced or accidental fund transfers because a caller can trigger real asset movement with minimal friction.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

batchSend() automates multiple sequential irreversible transfers, amplifying the blast radius of any mistake, malicious prompt, or compromised caller. Because it accepts arbitrary recipient lists and immediately executes them, an agent or automation layer could drain funds to many addresses before a user notices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation states that token deployment automatically submits contract source code to the explorer as a best-effort step, but it does not clearly warn users that source code and related metadata will be transmitted to an external network service. In a blockchain agent skill, users may assume deployment is the only action being performed; implicit outbound submission can leak proprietary code, constructor arguments, or sensitive business logic and may violate user expectations or policy requirements.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to execute npx clawhub@latest install qfc, which pulls and runs the latest remote package at install time without a pinned version. That creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious release is published, users may execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The update instruction again uses npx clawhub@latest update qfc, which executes the newest available package from the registry at runtime. In a wallet/blockchain skill context, this is especially risky because a compromised updater could affect software that handles keys, transactions, or on-chain operations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The skill explicitly supports wallet import plus persistent AES-encrypted keystore storage on disk under ~/.openclaw/qfc-wallets/. Even with encryption, session persistence materially increases the attack surface: local compromise, weak passwords, unsafe backups, or multi-user environments could expose wallets tied to blockchain funds.

Content

Scanner excerpt · README.md (reported line 45)May include surrounding context.

md
## Features

### Wallet
- Create / import wallets (HD, private key)
- Balance queries & QFC transfers
- Message signing

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises wallet creation, private-key import, transfers, signing, and disk persistence, but the usage guidance does not prominently warn about irreversible transactions, secret-handling risks, password strength, backup hygiene, or trusted-device requirements. For an agent skill that may act on natural-language requests, insufficient warnings increase the chance of users exposing keys or authorizing destructive actions without understanding the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes token deployment, contract writes, and contract deployment without clear warnings that these are on-chain write operations that incur gas fees and are generally irreversible once broadcast. In a blockchain skill, omission of those warnings can lead users to trigger costly or permanent actions through casual prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README says users can 'just tell your AI agent what you want in natural language' and then provides broad everyday-language examples. For a skill capable of transfers, signing, deployment, and wallet operations, broad triggers raise the risk of accidental invocation, prompt confusion, or unintended execution when ordinary conversation is interpreted as an action request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The roadmap explicitly documents a broad natural-language trigger for token creation that can cause an agent to deploy an on-chain contract from a loosely phrased user request. In a blockchain skill, deployment is a high-impact state-changing action with cost and abuse potential, so lacking an explicit warning and confirmation boundary increases the chance of unintended contract deployment and fund expenditure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.