Back to skill

Security audit

ClawWorld

Security checks for vulnerabilities and agentic risk

Overview

This game skill is purpose-aligned, but it sends session authentication and gameplay commands to a remote server over unencrypted connections, so it needs review before use.

Install only if you trust the ClawWorld server and are comfortable with game-session authentication and actions traveling over unencrypted ws:// and http:// connections. Avoid using this on untrusted networks, and prefer a version that uses wss:// and https:// with clear first-use consent and transport-security documentation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
claw_world_skill.py:17
Finding

Plaintext Transport Exposes Authentication Tokens and Permits Session Manipulation

Content
View full analysis

Vulnerability Details

File Location: claw_world_skill.py:17-17, claw_world_skill.py:124-130, claw_world_skill.py:151-152, claw_world_skill.py:198-204, config.yaml:9-10, SKILL.md:18-19
Vulnerability Type: Plaintext authentication and application transport
Risk Level: High

The Skill uses unencrypted WebSocket and HTTP endpoints for authentication and game communication. The WebSocket connection can carry the public-key handshake, server-issued session token, game actions, heartbeat messages, and game events without transport confidentiality or integrity.

Vulnerable Code

claw_world_skill.py:17-17:

python
def __init__(self, server_url: str = "ws://claw.hifunyo.cc:8000/ws/"):

claw_world_skill.py:124-130:

python
return {
    "version": "1.0",
    "type": "a2a_handshake",
    "sender_id": self.agent_id,
    "payload": {
        "public_key": self.get_public_key_pem(),
        "nonce": self._generate_nonce(),
    },
}

claw_world_skill.py:151-152:

python
self.session_token = response.get("payload", {}).get("session_token")
self.player_id = response.get("payload", {}).get("player_id")

claw_world_skill.py:198-204:

python
self.ws = websocket.WebSocketApp(
    self.server_url,
    on_open=on_ws_open,
    on_message=on_ws_message,
    on_error=on_ws_error,
    on_close=on_ws_close,
)

config.yaml:9-10:

yaml
server_url: ws://claw.hifunyo.cc:8000/ws/
api_url: http://claw.hifunyo.cc:8000/api

SKILL.md:18-19:

markdown
- **WebSocket URL**: `ws://claw.hifunyo.cc:8000/ws/`
- **HTTP API URL**: `http://claw.hifunyo.cc:8000/api`

Technical Analysis

The ws:// and http:// schemes do not provide TLS encryption, server authentication, or transport-level integrity. An attacker with a network position between the Skill and the game server can read or alter both directions of communication.

...[truncated 2580 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace all plaintext endpoints with TLS-protected endpoints:
    • Use wss://claw.hifunyo.cc:8000/ws/ for WebSocket communication.
    • Use https://claw.hifunyo.cc:8000/api for HTTP API communication.
  2. Reject ws:// and http:// endpoint schemes during initialization rather than silently accepting insecure configuration.
  3. Ensure the WebSocket library performs certificate-chain validation and hostname verification. Do not disable TLS verification in production.
  4. Redesign authentication as a challenge-response exchange:
    • The server sends a fresh, unpredictable challenge.
    • The client signs the challenge, protocol context, sender ID, and server identity using its private key.
    • The server verifies the signature before issuing a session token.
    • The token is bound to the authenticated public key and has a short expiration time.
  5. Add replay protection using server-generated nonces, timestamps with bounded acceptance windows, and one-time challenge tracking.
  6. Rotate and invalidate session tokens after reconnects, authentication failures, and explicit disconnects.
  7. Avoid printing or otherwise logging session tokens and authentication payloads.
  8. Update SKILL.md, config.yaml, and the Python defaults together so that no documented example directs users to plaintext services.
  9. Add automated tests that reject insecure schemes and verify that certificate or hostname validation failures terminate the connection.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill clearly documents outbound connections to remote WebSocket and HTTP endpoints and describes transmission of authentication material, including a session token, but it does not warn users about this network behavior. This is dangerous because users or downstream agents may invoke the skill without understanding that credentials and gameplay actions are sent to an external server, increasing the risk of unintended data disclosure and unsafe trust in a third-party service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and user-facing descriptions are written exclusively in Chinese, and the file provides no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking region. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language instructions and operational descriptions are presented in Chinese throughout the skill documentation, with no indication that users can choose another language. The policy explicitly calls out forced language or locale without user opt-in as a violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.