Back to skill

Security audit

Clawver Onboarding

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Clawver store setup guide whose external account, payment, product, and webhook actions match its onboarding purpose.

Install only if you intend to let the agent help set up a live Clawver store. Review before running commands that publish products, connect Stripe, create webhooks, submit feedback, or generate seller link codes; avoid sending secrets, payment details, customer data, or raw logs in feedback metadata.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:416
Finding

Malformed Webhook Signatures Can Trigger Unhandled Exceptions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 416-425
Vulnerability Type: Improper input validation in webhook signature verification
Risk Level: Low

Vulnerable Code

javascript
function verifyWebhook(body, signature, secret) {
  const expected = 'sha256=' + crypto
    .createHmac('sha256', secret)
    .update(body)
    .digest('hex');
  return crypto.timingSafeEqual(
    Buffer.from(signature),
    Buffer.from(expected)
  );
}

Technical Analysis

The documented verification function passes the attacker-controlled signature value directly to Buffer.from() and then to crypto.timingSafeEqual() without validating its presence, type, format, or length.

Node.js requires both buffers passed to crypto.timingSafeEqual() to have the same byte length. A missing, truncated, oversized, or otherwise malformed X-Claw-Signature value can therefore cause an exception rather than returning a normal authentication failure. Depending on the surrounding webhook handler, this exception may produce repeated HTTP 500 responses or disrupt request processing.

The function should also explicitly require the documented sha256= prefix followed by exactly 64 hexadecimal characters and should calculate the HMAC over the exact raw request-body bytes.

Attack Path

  1. An attacker identifies the application's publicly accessible Clawver webhook endpoint.
  2. The attacker submits a request with an absent or malformed X-Claw-Signature, such as a signature with an incorrect length.
  3. The application invokes the documented verifyWebhook() function.
  4. Buffer.from(signature) and Buffer.from(expected) produce buffers of unequal lengths, or signature conversion itself fails for an invalid value.
  5. crypto.timingSafeEqual() throws an exception.
  6. If the integrating request handler does not catch the exception, webhook processing fails. Repeated malformed requests may degrade endpoint availability or generate excessive errors.

I

...[truncated 432 chars]

Remediation
View remediation

Remediation Suggestions

Validate the signature before performing the constant-time comparison:

  • Require signature to be a string.
  • Enforce the exact format sha256= followed by 64 hexadecimal characters.
  • Compare buffers only after confirming that their lengths are equal.
  • Return false for every malformed input instead of allowing an exception to escape.
  • Compute the HMAC over the exact raw request body, before JSON parsing or other transformations.
  • Catch verification errors at the webhook-handler boundary.
  • Apply request-size limits and rate limiting to the public webhook endpoint.

Example hardened implementation:

javascript
const crypto = require('crypto');

function verifyWebhook(rawBody, signature, secret) {
  if (
    typeof signature !== 'string' ||
    !/^sha256=[0-9a-f]{64}$/i.test(signature)
  ) {
    return false;
  }

  const expected = 'sha256=' + crypto
    .createHmac('sha256', secret)
    .update(rawBody)
    .digest('hex');

  const suppliedBuffer = Buffer.from(signature, 'utf8');
  const expectedBuffer = Buffer.from(expected, 'utf8');

  if (suppliedBuffer.length !== expectedBuffer.length) {
    return false;
  }

  try {
    return crypto.timingSafeEqual(suppliedBuffer, expectedBuffer);
  } catch {
    return false;
  }
}
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (42)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description uses broad activation cues like creating a new store, starting with Clawver, or completing initial setup, while the skill also contains actions that create products, configure payments, generate linking codes, and set webhooks. That increases the chance the skill is invoked in situations where the user did not intend external API calls or account-affecting changes.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Step 1: Register Your Agent

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{
    "name": "My AI Store",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Request Onboarding URL

bash
curl -X POST https://api.clawver.store/v1/stores/me/stripe/connect \
  -H "Authorization: Bearer $CLAW_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The feedback section explicitly encourages sending reproducible metadata, request IDs, contact email, and environment details to an external platform without a privacy warning or data-minimization guidance. This can lead agents or users to disclose sensitive operational, personal, or customer-linked information to a third party unnecessarily.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This feedback endpoint explicitly instructs sending diagnostic metadata and contact details to an external service. In context, this is more dangerous than the other API calls because it encourages discretionary data sharing, and the skill lacks restrictions on secrets, personal data, or customer/order information.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

Compatibility note: older keys with profile:write also work for this endpoint.

bash
curl -X POST https://api.clawver.store/v1/agents/me/feedback \
  -H "Authorization: Bearer $CLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 285)May include surrounding context.

md
# 4) Generate seeded AI mockups
# This endpoint first creates a real Printful mockup seed, then generates AI variants from that seed.
curl -X POST https://api.clawver.store/v1/products/{productId}/pod-designs/{designId}/ai-mockups \
  -H "Authorization: Bearer $CLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 397)May include surrounding context.

Receive notifications for orders and reviews:

bash
curl -X POST https://api.clawver.store/v1/webhooks \
  -H "Authorization: Bearer $CLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 245)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 256)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 285)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 299)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 303)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 309)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 320)May include surrounding context.

Good Example: Register Then Save API Key

bash
curl -X POST https://api.clawver.store/v1/agents \
  -H "Content-Type: application/json" \
  -d '{"name":"My AI Store","handle":"myaistore","bio":"AI art"}'

Static analysis

No suspicious patterns detected.