Back to skill

Security audit

The Agent Economy Architect

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable educational guide, but it asks the host to expose high-value signing and payment credentials more broadly than the guide itself justifies.

Review this before installing in an environment that auto-injects credentials. Do not provide AGENT_SIGNING_KEY or STRIPE_API_KEY to the skill context unless a specific, scoped workflow truly needs them, keep production and sandbox keys separate, and treat the production examples as capable of triggering real financial or identity changes if executed against live services.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:14
Finding

Excessive Declaration of Sensitive Credentials Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–23
Vulnerability Type: Excessive credential access and least-privilege violation
Risk Level: Medium

Vulnerable Code

yaml
credentials: [GREENHELIX_API_KEY, WALLET_ADDRESS, AGENT_SIGNING_KEY, STRIPE_API_KEY]
metadata:
  openclaw:
    requires:
      env:
        - GREENHELIX_API_KEY
        - WALLET_ADDRESS
        - AGENT_SIGNING_KEY
        - STRIPE_API_KEY
    primaryEnv: GREENHELIX_API_KEY

Technical Analysis

The Skill globally declares four credentials as environment requirements, including the sensitive AGENT_SIGNING_KEY and STRIPE_API_KEY. However, the reviewed examples only retrieve and use GREENHELIX_API_KEY:

python
API_KEY = os.environ["GREENHELIX_API_KEY"]

No reviewed example reads or otherwise requires AGENT_SIGNING_KEY or STRIPE_API_KEY. Declaring these secrets globally can cause a compatible host to expose high-value signing and payment credentials to the Skill context even when they are unnecessary for the documented functionality.

This exceeds the minimum privileges required by the guide and conflicts with the Skill's own recommendation at SKILL.md:457 that private keys should be stored in a secrets manager rather than environment variables.

The static pre-scan also flagged Base64 encoding at SKILL.md:258–272. That behavior was reviewed and is not a covert exfiltration channel: the example encodes only a newly generated Ed25519 public key for API registration. It does not encode, return, or transmit the private key.

Attack Path

  1. A user installs or loads the Skill in a host that resolves the metadata.openclaw.requires.env declarations.
  2. The host makes AGENT_SIGNING_KEY and STRIPE_API_KEY available to the Skill execution context despite their not being required by the reviewed examples.
  3. A separate compromised component, prompt-injected workflow, or subsequent ...[truncated 1465 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove unused sensitive credentials from the global Skill metadata:

    yaml
    credentials: [GREENHELIX_API_KEY, WALLET_ADDRESS]
    metadata:
      openclaw:
        requires:
          env:
            - GREENHELIX_API_KEY
            - WALLET_ADDRESS
        primaryEnv: GREENHELIX_API_KEY
    
  2. If later examples genuinely require Stripe access, request a restricted Stripe key only for that specific workflow rather than exposing it to the entire Skill context.

  3. Do not inject private signing keys into general-purpose environment variables. Use a secrets manager, hardware-backed signer, or isolated signing service that performs signing operations without releasing private key material.

  4. Apply narrowly scoped API permissions, transaction limits, expiration, and environment separation to all payment and platform credentials.

  5. Require explicit user approval before making production payment, settlement, webhook, or identity operations.

  6. Keep sandbox credentials separate from production credentials and default all educational examples to https://sandbox.greenhelix.net.

  7. Add automated checks that compare declared credentials against actual references in the Skill and reject unused high-value secrets.

  8. Rotate and revoke any signing or Stripe credentials that may already have been unnecessarily exposed to a shared Skill context.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest declares AGENT_SIGNING_KEY as an environment credential while the guide later states private keys should never be stored in environment variables. That contradiction can normalize unsafe secret handling for a signing key, increasing the chance that implementers expose long-lived cryptographic material to process dumps, logs, CI/CD systems, or inherited subprocess environments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide claims users can get started in a sandbox with no API key required, but the example code immediately requires GREENHELIX_API_KEY from the environment and uses a production-style API base URL. This mismatch can mislead users into supplying unnecessary real credentials or testing against live infrastructure when they believe they are in a safe sandbox context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 235)May include surrounding context.

md
import base64

API_KEY = os.environ["GREENHELIX_API_KEY"]
BASE_URL = "https://api.greenhelix.net/v1"

session = requests.Session()
session.headers.update({

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown guide moves from sandbox to staging to production and explicitly describes the production environment as handling 'real transactions, real money, real consequences,' then immediately provides launch instructions. While the document contains educational disclaimers earlier, it does not provide a clear user warning in the launch section to double-check credentials, funding sources, and irreversible financial impact before following the production steps.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.