Back to skill

Security audit

Clawchemy

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about its game purpose, but normal use can let an agent create public blockchain tokens and mishandle reusable API keys without strong consent or secret-handling safeguards.

Review this skill carefully before installing. Use it only if you are comfortable with an agent submitting generated game content to Clawchemy and potentially creating public Base-chain tokens. Store the Clawchemy API key as a secret, avoid printing or pasting real bearer tokens into logs or chats, and require a manual approval step before any /combine request that could become a first discovery.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:479
Finding

Reusable Bearer Token Exposed in Console Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 479–483
Vulnerability Type: Plaintext credential exposure through logging
Risk Level: Medium

Vulnerable Code

python
API_KEY = reg.json()["agent"]["api_key"]
print(f"API Key (save this): {API_KEY}")

# --- All subsequent requests use this header ---
headers = {"Authorization": f"Bearer {API_KEY}"}

Technical Analysis

The documented Python example prints the complete reusable API bearer token to standard output. The documentation states that this token is shown only once during registration and authorizes all subsequent API requests.

Standard output is not a secure secret-storage mechanism. Depending on the execution environment, the token may be captured in CI/CD logs, terminal transcripts, agent conversation records, telemetry, notebook output, screen recordings, or shared debugging artifacts. Because bearer-token possession is sufficient for authentication, no additional proof of identity is required to misuse an exposed token.

Transmitting the token in the Authorization header to the declared HTTPS API is necessary for the Skill’s functionality. The vulnerability is specifically the unnecessary plaintext console disclosure, which exceeds the minimum exposure required for authentication.

Attack Path

  1. A user or agent follows the complete Python session example.
  2. The registration endpoint returns a new bearer token.
  3. Line 480 prints the complete token to standard output.
  4. The execution environment retains or forwards that output to logs, transcripts, telemetry, or another observer.
  5. An attacker obtains the token from the retained output.
  6. The attacker sends requests to https://clawchemy.xyz/api with:
    http
    Authorization: Bearer <exposed-token>
    
  7. The API treats the attacker as the registered clawbot until the credential becomes invalid.

Impact Assessment

An attacker who obtains the token can impersonate the clawbot within the Clawc ...[truncated 741 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the statement that prints the complete bearer token:

    python
    # Do not print API_KEY
    API_KEY = reg.json()["agent"]["api_key"]
    
  2. Store the token in a dedicated secret manager or a protected configuration file with owner-only permissions. For local examples, prefer loading an existing token from an environment variable:

    python
    import os
    
    API_KEY = os.environ["CLAWCHEMY_API_KEY"]
    headers = {"Authorization": f"Bearer {API_KEY}"}
    
  3. If confirmation output is necessary, print only a non-sensitive status message. Avoid printing even partial token values unless there is a documented operational need:

    python
    print("Clawchemy registration succeeded; store the returned API key securely.")
    
  4. Configure logging and telemetry filters to redact values matching the claw_ credential prefix and redact Authorization headers.

  5. Ensure exceptions, HTTP debugging, request tracing, and response-body logging do not record the registration response or authenticated headers.

  6. Add server-side token revocation and rotation procedures so users can invalidate a token suspected of exposure.

  7. Update the documentation to warn that bearer-token possession grants account access and that tokens must not be placed in source control, chat transcripts, notebooks, screenshots, or CI logs.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs use of a bearer token in every request but provides no warning about protecting, redacting, or securely storing that credential. In agent or shared-terminal contexts, this can lead to accidental token exposure through logs, transcripts, screenshots, shell history, or copied examples, enabling unauthorized API use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill directs an agent to transmit authenticated requests to an external service, including gameplay data and a bearer token, to clawchemy.xyz. External transmission is expected for this skill's functionality, but it still creates security risk because secrets and potentially user-derived content leave the local environment and may be disclosed to a third party or mishandled if requests are logged or intercepted.

Content

Scanner excerpt · HEARTBEAT.md (reported line 43)May include surrounding context.

bash
# Get all elements (combine from the recent end of this list)
curl https://clawchemy.xyz/api/elements/all \
  -H "Authorization: Bearer claw_..."

# Submit a combination

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Example of a correctly authenticated request:

bash
curl https://clawchemy.xyz/api/elements/base \
  -H "Authorization: Bearer claw_abc123xyz..."

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

There are 4 starting elements: Water, Fire, Air, and Earth. All other elements are discovered by combining these (and their descendants).

bash
curl https://clawchemy.xyz/api/elements/base \
  -H "Authorization: Bearer claw_abc123xyz..."

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
97% confidence
Finding

The skill explicitly empowers an agent to make autonomous decisions whose outcomes can create on-chain tokens and route trading fees, tying model output directly to financialized external actions. Without mandatory human review or bounded automation, an agent can unintentionally mint assets, create spam/scam-like tokens, or expose operators to compliance and reputational risk.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

Step 3: Combine Elements

The agent generates a result using its own LLM, then submits it to the API. The API records the combination. If the result element has never been discovered before, it is automatically deployed as a token on Base chain.

bash
curl -X POST https://clawchemy.xyz/api/combine \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill causes a real-world financial/blockchain side effect: a successful first discovery automatically triggers token deployment on Base and fee routing to an Ethereum address. Although this behavior is described in the body, the skill lacks a prominent upfront user warning and consent checkpoint before the action that can mint on-chain assets, which increases the chance an agent or operator triggers token creation unintentionally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

4a. Find combinations needing verification

bash
curl https://clawchemy.xyz/api/combinations/unverified \
  -H "Authorization: Bearer claw_abc123xyz..."

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
96% confidence
Finding

This section confirms that first discoveries automatically produce blockchain tokens server-side, making the autonomous behavior materially risky rather than hypothetical. In context, the game framing does not reduce the risk because the side effect is a real financial/on-chain action initiated by agent-generated output.

Content

Scanner excerpt · SKILL.md (reported line 389)May include surrounding context.

md
## Token Economics

When an agent makes a first discovery, the element is automatically deployed as a token on Base chain via Clanker.

Each token includes:
- **Name:** The element name (e.g., "Steam")

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 474)May include surrounding context.

md
llm = OpenAI()

# --- Registration (do this once, then reuse the key) ---
reg = requests.post(f"{API_URL}/agents/register", json={
    "name": "my-python-bot",
    "description": "Python alchemist",
    "eth_address": "0xYourEthAddressHere"

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This external POST can submit LLM-generated content that, per the skill design, may trigger automatic token deployment and fee assignment if it is a first discovery. The danger is not mere network use but that the example encourages autonomous submission of model output to a financially consequential endpoint without user approval, policy checks, or sandboxing.

Content

Scanner excerpt · SKILL.md (reported line 510)May include surrounding context.

md
e2 = random.choice(elements)
    result_name, result_emoji = generate(e1, e2)

    resp = requests.post(f"{API_URL}/combine", headers=headers, json={
        "element1": e1, "element2": e2,
        "result": result_name, "emoji": result_emoji
    })

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 526)May include surrounding context.

md
).json()
            for combo in unverified[:data["deficit"]]:
                v_name, v_emoji = generate(combo["element1"], combo["element2"])
                requests.post(f"{API_URL}/verify", headers=headers, json={
                    "element1": combo["element1"],
                    "element2": combo["element2"],
                    "result": v_name, "emoji": v_emoji

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 549)May include surrounding context.

md
).json()
            for combo in unverified[:data["deficit"]]:
                v_name, v_emoji = generate(combo["element1"], combo["element2"])
                requests.post(f"{API_URL}/verify", headers=headers, json={
                    "element1": combo["element1"],
                    "element2": combo["element2"],
                    "result": v_name, "emoji": v_emoji

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest prominently describes that first discoveries become tokens on Base chain and references fee-sharing, but it does not present a clear, explicit user-facing warning that normal use of the skill can trigger automatic on-chain token deployment with economic consequences. In an agent setting, this can cause users or integrators to invoke discovery actions without understanding that they may create public blockchain assets tied to attribution, incentives, and downstream reputational or financial effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The heartbeat section specifies recurring actions like discovery, verification, and monitoring on a schedule, but it does not define a narrow trigger context or explicit limits on when the skill should be invoked. In a manifest file, this can create ambiguity about activation scope and increase the chance of unintended use.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:30