Back to skill

Security audit

Openclaw

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent payment-wallet skill, but it gives an agent financial authority while under-scoping how sensitive API keys and configurable API endpoints are handled.

Install only if you are comfortable giving the agent controlled access to a USDC wallet. Use a low-balance wallet, strict per-transaction and daily limits, and only the official CardZero API endpoint. Treat the API key and claim key as secrets; revoke and rotate them if they were pasted with or sent to an untrusted API URL.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:62
Finding

Unrestricted API Base URL Can Cause Wallet Credential Disclosure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:62-74 and authenticated request examples at SKILL.md:349-410
Vulnerability Type: Unvalidated security-sensitive endpoint configuration
Risk Level: High

Vulnerable Code

text
After claiming, your Owner will give you a block like this:

== CardZero Agent Configuration ==
API Key:   czapi_a1b2c3d4_e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4
Wallet ID: wallet_7370ee785775
API URL:   https://api.cardzero.ai/v1

When you receive this, extract and save:
- CARDZERO_API_KEY — the API Key (starts with `czapi_`)
- CARDZERO_WALLET_ID — the wallet ID
- CARDZERO_API_URL — the API base URL

The configured endpoint is subsequently used together with the bearer credential:

bash
curl -X POST "$CARDZERO_API_URL/v1/jobs" \
  -H "Authorization: Bearer $CARDZERO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "providerAddress": "0xabc...",
    "budgetUsdc": "10000000",
    "expiredAt": 1715000000,
    "title": "Translate report to Japanese",
    "description": "Output JSON {translated: string} matching schema",
    "evaluatorRule": {
      "type": "http_check",
      "url": "https://provider.example.com/output",
      "expectedStatus": 200
    }
  }'

Technical Analysis

The Skill directs the agent to extract both CARDZERO_API_KEY and CARDZERO_API_URL from a configuration block supplied through conversation. It does not require the URL to use HTTPS, verify that its hostname is the official CardZero domain, prohibit embedded credentials, or define redirect restrictions.

Authenticated operations then construct request destinations from CARDZERO_API_URL and attach CARDZERO_API_KEY as a bearer token. Consequently, the party controlling the configuration text can potentially control where the credential is transmitted. This violates the security principle that secret-bearing requests must only be sent to authe ...[truncated 1915 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin all credential-bearing requests to the canonical CardZero origin, such as https://api.cardzero.ai.
  2. Do not accept or update the authenticated API endpoint from ordinary conversational text or pasted configuration blocks.
  3. If endpoint configurability is required, validate the parsed URL before storing or using it:
    • Require HTTPS.
    • Compare the normalized hostname against an explicit allowlist.
    • Reject IP literals, nonstandard ports, embedded username/password fields, fragments, and malformed URLs.
    • Reject lookalike domains and subdomains unless separately allowlisted.
    • Normalize the path to prevent duplicate /v1 segments.
  4. Disable redirects for credential-bearing requests or validate every redirect destination against the same allowlist before forwarding the Authorization header.
  5. Separate endpoint configuration from secret provisioning. Endpoint changes should require an authenticated owner-controlled configuration mechanism and explicit confirmation.
  6. Never display, log, or transmit the complete API key except in the authorization header sent to the validated CardZero origin.
  7. Provide credential revocation and rotation guidance. If an untrusted endpoint was previously configured, immediately revoke the affected key, issue a replacement, and review wallet and payment history.
  8. Apply server-side least-privilege protections, including wallet-bound credentials, transaction and daily limits, anomaly detection, and additional approval for high-risk financial operations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises many broad trigger phrases such as 'make a payment', 'buy with crypto', and 'check my balance', which can cause overly eager invocation in ambiguous conversations. In a payment-capable skill, accidental activation is more dangerous because it increases the chance of exposing wallet context or steering the agent toward transactional actions the user did not clearly intend.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
- CARDZERO_API_KEY
        - CARDZERO_WALLET_ID
      bins:
        - curl
    primaryEnv: CARDZERO_API_KEY
    emoji: "\U0001F4B3"
    homepage: https://cardzero.ai

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to extract and save API credentials but does not clearly warn that these are secrets that must never be echoed, logged, or shared back to users. Because this is a payment wallet API key, mishandling could enable unauthorized balance checks, payment attempts, history access, or other wallet operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

== CardZero Agent Configuration == API Key: czapi_a1b2c3d4_e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4 Wallet ID: wallet_7370ee785775 API URL: https://api.cardzero.ai/v1

text

When you receive this, extract and save:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The one-time claim key is effectively a wallet-claim secret, yet the instructions focus on relaying it without prominently warning that anyone who obtains it can potentially claim the wallet. In a financial skill, omission of sensitivity guidance materially increases the chance of accidental disclosure through chat history, logging, screenshots, or forwarding.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

md
Authorization: Bearer {CARDZERO_API_KEY}

{
  "url": "https://api.example.com/premium-data",
  "maxAmount": "1.00",
  "recipient": "0x1234567890123456789012345678901234567890",
  "network": "eip155:8453",

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest frames the skill as an authenticated payment wallet for an agent's own wallet operations, but the documented API includes an unauthenticated endpoint to retrieve payment details by payment ID alone. Even if payment IDs are intended to be unguessable, this broadens behavior from operating your wallet to allowing lookup of payment records without wallet-bound authorization.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The manifest does mention A2A jobs with escrow, but the detailed behavior here goes further by introducing evaluator rules that can perform HTTP checks against arbitrary URLs and provider-submitted content URIs. That is a materially broader operational model than just wallet creation and payments, because the skill participates in externally evaluated job workflows tied to remote resources.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:45