Back to skill

Security audit

Agent Gateway

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent gateway purpose, but it asks users to run mutable external code and understates where API keys and prompts may go.

Review this before installing. Use only with provider keys and prompts you are comfortable sending to the selected cloud model providers, and prefer a pinned, verified CLI version or lockfile-managed install rather than running the unpinned npx command directly. The artifact does not show destructive behavior or persistence, but the reviewed package does not contain the actual gateway implementation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:34
Finding

Execution of an Unpinned Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:34-37; scripts/start-gateway.mjs:1-5
Vulnerability Type: Unpinned external dependency execution through npx
Risk Level: Medium

The documented startup procedure and bundled wrapper direct users to execute the mutable registry version of @claws-shield/cli.

Relevant code from SKILL.md:34-37:

bash
npx @claws-shield/cli gateway --port 8787

Relevant code from scripts/start-gateway.mjs:1-5:

js
#!/usr/bin/env node
// Thin wrapper for starting the gateway from the OpenClaw skill
console.log("Starting Claws-Shield Agent Gateway...")
console.log("Gateway server not yet available in skill mode.")
console.log("Use the CLI instead: npx @claws-shield/cli gateway --port 8787")

Technical Analysis

The npx command resolves and executes an npm package without specifying an exact version. The project contains no lockfile, integrity metadata, vendored implementation, or other mechanism that binds the command to the version that was reviewed.

The local script does not implement or start the advertised gateway. Instead, it instructs the user to run the same external package. Consequently, the effective gateway implementation is mutable code outside this audit scope. A compromised package release, registry account, or unexpected future version could cause arbitrary package code to run under the invoking user's account.

This is a supply-chain weakness rather than evidence that the currently published package is malicious.

Attack Path

  1. An attacker compromises the npm package, its publisher account, or another part of its release pipeline.
  2. The attacker publishes a malicious version under @claws-shield/cli.
  3. A user follows the documented command or the instruction emitted by the bundled wrapper.
  4. npx resolves and downloads the mutable package version from the configured npm registry.
  5. The downloaded package exe ...[truncated 902 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an explicitly reviewed version, for example:
    bash
    npx --yes @claws-shield/cli@1.2.3 gateway --port 8787
    
  2. Prefer declaring the package as a project dependency and committing a lockfile containing registry integrity hashes.
  3. Install dependencies using a lockfile-enforcing workflow such as npm ci.
  4. Audit the pinned package, its transitive dependencies, executable entry point, and lifecycle scripts before distribution.
  5. Consider bundling the gateway implementation within the reviewed project so that actual runtime behavior is included in the audit scope.
  6. Document the expected registry and package publisher, and verify package provenance or signatures where supported.
  7. Run the gateway under a dedicated least-privileged account with access only to the provider credentials and files it requires.
  8. Update both SKILL.md and scripts/start-gateway.mjs so they reference the same pinned and verified artifact.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The privacy statement claims API keys are never transmitted to third parties, but the gateway's stated purpose is to call Anthropic, OpenAI, and Google endpoints using those credentials. This is misleading security/privacy documentation that can cause users to make unsafe trust decisions about where credentials and request data go.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes multi-provider routing to external model vendors but does not warn users that their prompts and related request data may be forwarded to third-party providers. In this context, the omission is materially risky because the gateway is explicitly designed to proxy potentially sensitive prompts across multiple external services, increasing disclosure and compliance risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to run npx @claws-shield/cli gateway without pinning an exact package version. This allows whatever version is currently published under that package name to be fetched and executed at runtime, creating a supply-chain execution risk if the package is updated maliciously, compromised, or unexpectedly changed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The wrapper instructs users to run npx @claws-shield/cli gateway --port 8787 without pinning an exact package version. That causes execution of whatever version is currently resolved from the registry, which can introduce supply-chain risk, unexpected behavior changes, or execution of a compromised release. In a gateway skill that brokers model access and may handle prompts, credentials, or routing logic, this increases exposure if a malicious or tampered package is fetched.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file comment says this is a wrapper for the "OpenClaw skill" and the log message announces "Claws-Shield Agent Gateway," while the manifest identifies the skill as "Agent Gateway." This is an active documentation/intent mismatch in the file itself, indicating the wrapper is labeled for a different skill identity than the one being audited.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.