Back to skill

Security audit

ClawPump V2 Token Launchpad

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly a Solana token launchpad, but it asks agents to handle raw wallet keys and sign server-built mainnet transactions with too little independent validation.

Review before installing. Use only a low-value wallet, validate every returned transaction before signing, and avoid any flow that displays a private key in chat or asks you to paste a private key back into a hosted agent. Prefer Phantom/Solflare or a protected signer with explicit transaction approval.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:295
Finding

Blind Signing and Broadcasting of Remotely Constructed Solana Transactions

Content
View full analysis
r.json()); const tx = Transaction.from(Buffer.from(r.txBase64, "base64")); tx.partialSign(agent); // wallet's slot const sig = await conn.sendRawTransaction( tx.serialize({ requireAllSignatures: true }) ); await conn.confirmTransaction(sig, "confirmed"); ``` The end-to-end swap workflow repeats the same pattern: ```ts const swap = await fetch("https://clawpump-v2.vercel.app/api/swap", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ pool: launch.poolPubkey, userWallet: agent.publicKey.toBase58(), amountIn: "1000000", swapBaseForQuote: false, slippageBps: 200, }), }).then((r) => r.json()); const buyTx = Transaction.from(Buffer.from(swap.txBase64, "base64")); buyTx.partialSign(agent); const buySig = await conn.sendRawTransaction( buyTx.serialize({ requireAllSignatures: true }) ); await conn.confirmTransaction(buySig, "confirmed"); ``` ### Technical Analysis The Skill instructs an agent to accept a serialized transaction from `clawpump-v2.vercel.app`, deserialize it, sign it with a wallet that may hold SOL and SPL tokens, and broadcast it directly to Solana mainnet. No validation is performed before signing. In particular, the examples do not verify: - The transaction's program IDs. - The identities and permissions of account metas. - The fee payer. - SOL or token transfer destinations and amounts. - The expected mint, pool, config, and quote-token addresses. - The number, order ...[truncated 2656 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:319
Finding

Plaintext Private-Key Exposure Through Agent Output and Conversation Workflows

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells users they may hand the private key back to the hosted agent for server-side signing, calling it 'less secure' but still presenting it as an acceptable option. In an LLM/hosted-agent environment this is extremely dangerous because secrets may be retained in conversation history, provider logs, debugging traces, or compromised plugins, enabling immediate wallet takeover and irreversible loss of funds.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 264)May include surrounding context.

md
const { connection } = useConnection();
const { publicKey, signTransaction } = useWallet();

const r = await fetch("https://clawpump-v2.vercel.app/api/launch", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 295)May include surrounding context.

md
const { connection } = useConnection();
const { publicKey, signTransaction } = useWallet();

const r = await fetch("https://clawpump-v2.vercel.app/api/launch", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 425)May include surrounding context.

md
const { connection } = useConnection();
const { publicKey, signTransaction } = useWallet();

const r = await fetch("https://clawpump-v2.vercel.app/api/launch", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs a hosted agent to generate a Solana keypair and return the private key to the user. Secret generation and disclosure materially expand the skill from launchpad orchestration into high-risk key management, and the same section normalizes private-key handling in an LLM-agent context where logging, prompt injection, telemetry, or UI leakage could expose funds irreversibly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This workflow has the agent generate a private key and reveal it to the user, but the warning is limited and embedded after the action rather than as a strong, upfront consent barrier. In an agent setting, users may not appreciate that displaying/exporting a raw private key is an extremely sensitive one-time event and that any compromise of chat history, logs, screenshots, or integrations can lead to theft of all associated assets.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 449)May include surrounding context.

md
console.log("pool live, progress:", state.progressPct + "%");

// 5. Optionally seed a first buy with 1 CLAW (1_000_000 atomic units).
const swap = await fetch("https://clawpump-v2.vercel.app/api/swap", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a Solana token launchpad for launching tokens, trading, and graduating pools. This section introduces separate account-linking, API-key verification, leaderboard, and profile-sync capabilities that are ancillary product/account features rather than obvious requirements for on-chain token launch and trading.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.