Back to skill

Security audit

Obverse Payments

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent payments skill, but it asks for payment API authority while exposing dashboard passwords in normal output and encouraging broad customer data collection without enough controls.

Review before installing. Use a narrowly scoped Obverse API key, avoid overriding OBVERSE_API_URL except to a trusted HTTPS or local development endpoint, do not share generated dashboard passwords in group chats or logs, and collect customer or contributor data only with explicit consent and a clear retention policy. Prefer verified OpenClaw and ClawHub installation methods instead of running remote scripts or unpinned global packages.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
DEPLOYMENT.md:83
Finding

Unverified Remote Installation Script Executed Directly by Bash

Content
View full analysis
Remediation
View remediation
openclaw-installer.sh" | sha256sum --check - less openclaw-installer.sh bash openclaw-installer.sh ``` The actual URL, version, and digest must come from an authenticated and trusted release source. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
obverse-cli.js:10
Finding

API Key Can Be Sent to an Arbitrary or Plaintext Configured Endpoint

Content
View full analysis
&2 exit 1 fi if [ -z "${OBVERSE_API_KEY:-}" ]; then echo "Error: OBVERSE_API_KEY is not set" >&2 exit 1 fi AUTH_HEADER="X-API-Key: $OBVERSE_API_KEY" ``` ```bash curl -sf -H "$AUTH_HEADER" -H "Accept: application/json" \ "$OBVERSE_API_URL/payment-links/$2" ``` ### Technical Analysis Both clients attach `OBVERSE_API_KEY` to every request sent to the configured `OBVERSE_API_URL`. Neither implementation parses and validates the URL scheme or restricts the credential to an expected host. A configuration value using plain HTTP exposes the API key to network interception outside a safely isolated local environment. A configuration value pointing to an attacker-controlled HTTPS host sends the credential directly to that host. The deployment documentation also demonstrates `http://localhost:4000`, but the clients do not enforce that plaintext HTTP is limited to loopback development use. The network access itself is necessary for the declared payment API functionality. The missing destination and transport checks are not necessary and violate least-priv ...[truncated 1157 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
obverse-cli.js:548
Finding

Temporary Dashboard Credentials Are Exposed Through Standard Output and Agent Messages

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
obverse-cli.js:106
Finding

Payment Amounts and Transaction Fields Lack Client-Side Validation

Content
View full analysis
{ const chainValidation = validateAndNormalizeChain(chain); if (chainValidation.success === false) { return chainValidation; } const result = await makeRequest('/payments', { method: 'POST', body: JSON.stringify({ linkCode, txSignature, chain: chainValidation.chain, amount: parseFloat(amount), token, fromAddress, toAddress, customerData: customerEmail ? { email: customerEmail } : undefined }) }); ``` ### Technical Analysis `parseFloat` accepts partial numeric strings and can produce negative, zero, non-finite, or unintended values. The client does not check `Number.isFinite`, positivity, maximum amount, decimal precision, or supported token values. It also does not validate the expected format of link codes, transaction signatures, or chain-specific wallet addresses. The deployment guide claims that negative amounts should be rejected, but the audited client does not implement that control. The backend must remain the authoritative validation boundary, but client-side checks are also important for preventing unsafe Agent-generated requ ...[truncated 1034 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
DEPLOYMENT.md:456
Finding

Unpinned Global Installation of a Third-Party Publishing CLI

Content
View full analysis
Remediation
View remediation
``` The placeholder must be replaced with a verified version and committed with the generated lockfile. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (28)

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

Piping a remote script directly into bash executes unverified code from the network with the user's privileges, creating a supply-chain compromise path if the host, TLS termination, DNS, or distribution channel is tampered with. In a deployment guide for a payment-related skill, this is especially risky because operators are likely to run setup commands on systems that also hold API keys, bot tokens, and payment infrastructure secrets.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 86)May include surrounding context.

md
brew install openclaw

# Linux (Ubuntu/Debian)
curl -fsSL https://openclaw.ai/install.sh | bash

# Or download from GitHub
# https://github.com/openclaw/openclaw/releases

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The command chaining pattern here directly feeds downloaded content into a shell interpreter, eliminating any opportunity for inspection and magnifying the impact of a compromised upstream source. Because this skill handles payments and directs users to configure sensitive credentials, successful exploitation could lead to theft of API keys, bot tokens, payment redirection, or broader host compromise.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 86)May include surrounding context.

md
brew install openclaw

# Linux (Ubuntu/Debian)
curl -fsSL https://openclaw.ai/install.sh | bash

# Or download from GitHub
# https://github.com/openclaw/openclaw/releases

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This second mismatch finding points to the same core issue: the skill markets itself as an end-to-end payments platform with invoices, receipts, dashboards, and messaging-platform support, but the provided content primarily documents a narrower API client pattern. Misrepresentation of functionality increases security risk because users cannot accurately assess data flows, trust boundaries, or whether sensitive operations are actually implemented safely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This second mismatch finding points to the same core issue: the skill markets itself as an end-to-end payments platform with invoices, receipts, dashboards, and messaging-platform support, but the provided content primarily documents a narrower API client pattern. Misrepresentation of functionality increases security risk because users cannot accurately assess data flows, trust boundaries, or whether sensitive operations are actually implemented safely.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to expose dashboard login credentials and sensitive customer/payment access details in a chat response. In shared or persisted chat environments, this can directly leak account access and PII to unauthorized parties, making the risk concrete rather than hypothetical.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 100)May include surrounding context.

3. API Keys Generated

Create API keys in your Obverse system:

typescript
// In your backend, add API key generation endpoint

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs operators to add analytics that capture agent identifiers, amounts, currencies, chains, and timestamps, but it does not warn users that payment metadata and identifiers will be transmitted to the backend and stored for analytics. In a payments skill, that omission matters because merchants and customers may assume only operational payment processing occurs, while the deployment guidance expands data collection without consent, minimization, or retention guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README promotes payment handling, invoices, wallet balances, and messaging-platform use, but it does not clearly warn users that the skill processes sensitive financial and potentially personal data. Without explicit notice, users may expose wallet information, transaction metadata, customer identifiers, or invoice details in contexts where retention, logging, or third-party access is not understood.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ✅ Generate payment links and QR codes
- ✅ Accept USDC/USDT on Solana and Monad
- ✅ Track payment status in real-time
- ✅ Create invoices automatically
- ✅ Check wallet balances
- ✅ Multi-platform: Telegram, WhatsApp, Discord, Signal
- ✅ Low transaction fees (0.5-1.5%)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The command examples are phrased as ordinary natural-language requests like "What's my balance?" and "List recent payments" without any explicit activation boundary, confirmation step, or scoped intent syntax. In a multi-agent or chat environment, this increases the chance of accidental invocation and unintended access to payment history or financial actions from routine conversation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 210)May include surrounding context.

bash
# Install curl (required dependency)
# Ubuntu/Debian:
sudo apt-get install curl jq

# macOS:
brew install curl jq

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope or allowed-tools despite clearly requiring environment access, network calls, and shell execution. In an agent environment, missing capability boundaries can lead to overbroad execution privileges and make it harder for operators to reason about what the skill may do with secrets and external endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill strongly encourages collecting customer email, name, phone, and arbitrary custom fields, but provides no privacy notice, consent guidance, retention limits, or data handling safeguards. In a payments context, combining financial activity with personal data materially raises privacy and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

bash
# Register from any platform (no Telegram required!)
curl -X POST https://obverse.onrender.com/api-keys/register \
  -H "Content-Type: application/json" \
  -d '{"username": "your-agent-name"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples show dashboard usernames and passwords being returned directly and normalized as routine output, without warning that these credentials grant access to customer and payment data. Encouraging agents to emit live credentials into chats creates a high likelihood of accidental disclosure through logs, screenshots, channel members, or prompt history.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow promotes extracting customer email lists from payment data for marketing, but does not mention consent, opt-in status, or purpose limitation. Using payment-collected personal data for marketing without controls can create privacy violations, regulatory exposure, and user harm.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 512)May include surrounding context.

md
# Check your API key
echo $OBVERSE_API_KEY
# Register for a new key:
curl -X POST https://obverse.onrender.com/api-keys/register \
  -H 'Content-Type: application/json' \
  -d '{"username": "your-agent-name"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · clawhub.json (reported line 43)May include surrounding context.

json
"envVars": {
            "OBVERSE_API_KEY": {
                "required": true,
                "description": "Your Obverse API key. Register programmatically: curl -X POST https://obverse.onrender.com/api-keys/register -H 'Content-Type: application/json' -d '{\"username\": \"your-agent-name\"}'"
            },
            "OBVERSE_API_URL": {
                "required": false,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The submit-payment path transmits customer email in customerData without any explicit warning, consent checkpoint, or disclosure in command output. In an agent-driven environment, silent forwarding of personal data to a third-party payment platform can violate privacy expectations and facilitate unnoticed data sharing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill adds product-sales and fundraiser commands that automatically collect customer or contributor identity fields such as email and name, which goes beyond a narrow payment-processing function and expands the data footprint. In an agent context, this can enable silent harvesting of personal data under the guise of creating payment links, especially because the behavior is framed as a convenience feature rather than a privacy-sensitive operation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The analytics and contributor-listing functionality exposes payer addresses, contribution history, totals, and activity timelines, creating profiling capability beyond basic payment handling. In a messaging-agent setting, this materially increases privacy risk because the tool can be used to enumerate and analyze contributors without any user-facing warning or access-control check in the CLI itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The contributor-listing feature returns payer wallet addresses, contribution totals, timestamps, and transaction references with no privacy warning or minimization. That enables deanonymization or profiling of donors/customers, which is especially sensitive in payment contexts where users may not expect broad disclosure of participation history.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generate-dashboard command returns temporary dashboard credentials directly in CLI output, along with login instructions, but does not warn that these are sensitive secrets that grant access to payment analytics. In agent or logged-shell environments, this can lead to credential leakage through logs, chat transcripts, terminal history, or downstream tool capture.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The help text explicitly advertises collecting 'ANY data you need' including phone, address, and company information, signaling broad arbitrary data capture unrelated to a payments-only description. This increases the risk that downstream agents or users will normalize overcollection of sensitive personal information without necessity, notice, or purpose limitation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a very broad 'complete stablecoin payment solution' for AI agents without defining activation boundaries, user consent requirements, or task-scoping constraints. In a payments skill, ambiguous scope increases the chance an agent will invoke financial actions in inappropriate contexts or without sufficiently explicit user intent, which raises misuse and accidental transaction risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
obverse-cli.js:10

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
obverse-cli.js:556