Back to skill

Security audit

Clawver Reviews

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its review-management purpose, but it includes instructions that can publish public store responses and create webhooks with an API key without clearly requiring user confirmation.

Install only if you intend to let an agent access your Clawver review data and potentially post public review responses. Use a least-privilege API key if available, require the agent to show and confirm every response before publishing, approve webhook destination URLs yourself, and harden the webhook signature verification example before using it in production.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:157
Finding

Malformed Webhook Signatures Can Trigger Unhandled Exceptions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 157–165
Vulnerability Type: Improper input validation in webhook signature verification
Risk Level: Medium

javascript
function verifyWebhook(body, signature, secret) {
  const expected = 'sha256=' + crypto
    .createHmac('sha256', secret)
    .update(body)
    .digest('hex');
  return crypto.timingSafeEqual(
    Buffer.from(signature),
    Buffer.from(expected)
  );
}

Technical Analysis

Node.js crypto.timingSafeEqual requires its two buffer arguments to have identical lengths. If the attacker-controlled X-Claw-Signature header is missing, truncated, oversized, or otherwise malformed, Buffer.from(signature) or crypto.timingSafeEqual can throw an exception rather than returning false.

The example performs no presence, type, format, or length validation before comparing the supplied signature. If an application adopts this example without exception handling at the request boundary, malformed webhook requests can interrupt request processing and potentially affect process availability.

Attack Path

  1. An attacker locates the publicly reachable webhook endpoint.
  2. The attacker submits a request with a missing or malformed X-Claw-Signature, such as a signature whose length differs from the expected sha256=-prefixed hexadecimal digest.
  3. The webhook handler passes the attacker-controlled value to verifyWebhook.
  4. Buffer creation or crypto.timingSafeEqual throws an exception because the input is invalid or the buffer lengths differ.
  5. If the surrounding handler does not safely catch the exception, the request fails and may produce repeated errors or terminate the process in deployments configured to exit on uncaught exceptions.
  6. Repeated malformed requests can therefore degrade or deny webhook processing.

Impact Assessment

Exploitation does not grant access to the API key, webhook secret, customer ...[truncated 436 chars]

Remediation
View remediation

Remediation Suggestions

Validate the signature header before constructing buffers and compare only equal-length values. The verifier should fail closed by returning false for every malformed input rather than throwing.

Recommended hardening measures:

  1. Require body to be the exact raw request body used by the sender when computing the HMAC.
  2. Verify that the signature exists and is a string.
  3. Require the exact sha256= prefix and a 64-character hexadecimal digest.
  4. Decode the received and expected digests explicitly as hexadecimal buffers.
  5. Check buffer lengths before calling crypto.timingSafeEqual.
  6. Catch verification errors at the HTTP request boundary and return a generic 401 or 400 response.
  7. Apply request-size limits, rate limiting, and security-conscious logging to the webhook endpoint.

Example hardened implementation:

javascript
const crypto = require('crypto');

function verifyWebhook(body, signature, secret) {
  if (
    !Buffer.isBuffer(body) ||
    typeof signature !== 'string' ||
    typeof secret !== 'string'
  ) {
    return false;
  }

  const match = /^sha256=([a-fA-F0-9]{64})$/.exec(signature);
  if (!match) {
    return false;
  }

  const received = Buffer.from(match[1], 'hex');
  const expected = crypto
    .createHmac('sha256', secret)
    .update(body)
    .digest();

  if (received.length !== expected.length) {
    return false;
  }

  return crypto.timingSafeEqual(received, expected);
}

The webhook route should additionally wrap verification in safe error handling so that unexpected runtime failures result in rejection rather than process disruption.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation guidance says to use the skill when asked about customer feedback, reviews, ratings, or reputation management, which is a broad natural-language description rather than a constrained trigger list. Without narrower scope, exclusions, or negative examples, ordinary conversation about reviews or reputation could unintentionally activate the skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

Get All Reviews

bash
curl https://api.clawver.store/v1/stores/me/reviews \
  -H "Authorization: Bearer $CLAW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This example sends authenticated POST requests that create or replace public review responses on the store. In context, the endpoint is legitimate, but write-capable external transmission is more sensitive because accidental or unauthorized invocation can modify public-facing business content and affect merchant reputation.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

Respond to Reviews

bash
curl -X POST https://api.clawver.store/v1/reviews/{reviewId}/respond \
  -H "Authorization: Bearer $CLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
74% confidence
Finding

The webhook creation example transmits configuration to an external endpoint and includes a user-supplied callback URL and secret. While webhook setup is expected functionality, it can become dangerous if an agent configures callbacks to untrusted destinations or mishandles secrets, causing data leakage or integrity issues.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

Get notified when new reviews are posted:

bash
curl -X POST https://api.clawver.store/v1/webhooks \
  -H "Authorization: Bearer $CLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents automated posting of review responses that modify public store data without an explicit confirmation or warning step. In an agent setting, this can lead to unintended external actions, reputational harm, or unauthorized public responses if the automation is triggered from ambiguous user intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

Good Example: Fetch and Respond to Unanswered Reviews

bash
curl https://api.clawver.store/v1/stores/me/reviews \
  -H "Authorization: Bearer $CLAW_API_KEY"

curl -X POST https://api.clawver.store/v1/reviews/{reviewId}/respond \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

Good Example: Fetch and Respond to Unanswered Reviews

bash
curl https://api.clawver.store/v1/stores/me/reviews \
  -H "Authorization: Bearer $CLAW_API_KEY"

curl -X POST https://api.clawver.store/v1/reviews/{reviewId}/respond \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 217)May include surrounding context.

Good Example: Fetch and Respond to Unanswered Reviews

bash
curl https://api.clawver.store/v1/stores/me/reviews \
  -H "Authorization: Bearer $CLAW_API_KEY"

curl -X POST https://api.clawver.store/v1/reviews/{reviewId}/respond \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-examples.md (reported line 6)May include surrounding context.

Good Example: Fetch and Respond to Unanswered Reviews

bash
curl https://api.clawver.store/v1/stores/me/reviews \
  -H "Authorization: Bearer $CLAW_API_KEY"

curl -X POST https://api.clawver.store/v1/reviews/{reviewId}/respond \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-examples.md (reported line 9)May include surrounding context.

Good Example: Fetch and Respond to Unanswered Reviews

bash
curl https://api.clawver.store/v1/stores/me/reviews \
  -H "Authorization: Bearer $CLAW_API_KEY"

curl -X POST https://api.clawver.store/v1/reviews/{reviewId}/respond \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-examples.md (reported line 6)May include surrounding context.

Good Example: Fetch and Respond to Unanswered Reviews

bash
curl https://api.clawver.store/v1/stores/me/reviews \
  -H "Authorization: Bearer $CLAW_API_KEY"

curl -X POST https://api.clawver.store/v1/reviews/{reviewId}/respond \

Static analysis

No suspicious patterns detected.