Back to skill

Security audit

Clawdr

Security checks for vulnerabilities and agentic risk

Overview

This dating-agent skill is purpose-aligned, but it handles highly sensitive dating data and account actions with weak consent, credential-storage, and install-integrity guidance.

Review this carefully before installing. Use it only if you are comfortable sending dating-profile details, preferences, messages, and date logistics to the Clawdr service. Protect the API key with owner-only permissions or a credential manager, avoid sharing exact addresses or contact details until explicitly approved, and do not install remote skill or heartbeat files unless you can verify their contents and integrity.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Mutable Remote Skill Files Installed Without Integrity Verification

Content
View full analysis
~/.openclaw/skills/clawdr/SKILL.md curl -s https://clawdr-eta.vercel.app/heartbeat.md > ~/.openclaw/skills/clawdr/HEARTBEAT.md curl -s https://clawdr-eta.vercel.app/skill.json > ~/.openclaw/skills/clawdr/package.json ``` ### Technical Analysis The installation procedure downloads mutable Skill instructions, heartbeat instructions, and metadata directly from a remote deployment. It does not pin a version, validate a cryptographic checksum, verify a digital signature, or require review of the downloaded content. The use of HTTPS protects traffic against ordinary network interception, and the files are not directly piped into a shell. Nevertheless, the effective Skill content can change after this audited artifact has been reviewed. Compromise of the service, hosting account, deployment pipeline, or domain could cause users to install instructions that differ from the reviewed version. The `HEARTBEAT.md` file is particularly relevant because heartbeat instructions may cause recurring Agent activity. Although no malicious remote payload is present in the audited file, the installation mechanism creates a supply-chain trust boundary without integrity controls. ### Attack Path 1. An attacker compromises the Clawdr deployment, hosting account, publishing pipeline, or associated domain. 2. The attacker replaces `skill.md`, `heartbeat.md`, or `skill.json` with altered content. 3. A user follows the documented installation commands. 4. `curl` writes the attacker-controlled files into the local OpenClaw Skill directory without checking their identity or integrity. 5. OpenClaw subsequently loads the modified instructions or heartbeat behavior. 6. The altered Skill could attemp ...[truncated 933 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:56
Finding

API Credential Storage Lacks Explicit Filesystem Permission Controls

Content
View full analysis
` to the Clawdr API. 5. The service treats those requests as actions performed by the legitimate Agent. 6. The attacker accesses available account information or performs dating-service actions until the credential is revoked or otherwise invalidated. ### Impact Assessment The stolen credential does no ...[truncated 732 chars]
Remediation
View remediation
"$tmp_file" chmod 0600 "$tmp_file" mv "$tmp_file" "$HOME/.config/clawdr/credentials.json" ``` 3. Prefer an operating-system credential store or secret manager rather than a plaintext JSON file where supported. 4. Never print the bearer token in logs, diagnostic output, chat messages, or command histories. 5. Provide API-key rotation and immediate revocation mechanisms. 6. Use narrowly scoped, short-lived credentials if supported by the service. 7. Document that credential files and backups must not be shared or committed to source control. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill instructs users to save an API key in a plaintext JSON file under the home directory without any mention of restrictive permissions, OS keychain storage, rotation, or revocation. Plaintext credential persistence materially raises the risk of local compromise, accidental exposure through backups/sync, or theft by other local processes.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

}

text

**Save your credentials to `~/.config/clawdr/credentials.json`:**
```json
{
  "api_key": "cupid_xxx",

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Install locally:

bash
mkdir -p ~/.openclaw/skills/clawdr
curl -s https://clawdr-eta.vercel.app/skill.md > ~/.openclaw/skills/clawdr/SKILL.md
curl -s https://clawdr-eta.vercel.app/heartbeat.md > ~/.openclaw/skills/clawdr/HEARTBEAT.md
curl -s https://clawdr-eta.vercel.app/skill.json > ~/.openclaw/skills/clawdr/package.json

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Install locally:

bash
mkdir -p ~/.openclaw/skills/clawdr
curl -s https://clawdr-eta.vercel.app/skill.md > ~/.openclaw/skills/clawdr/SKILL.md
curl -s https://clawdr-eta.vercel.app/heartbeat.md > ~/.openclaw/skills/clawdr/HEARTBEAT.md
curl -s https://clawdr-eta.vercel.app/skill.json > ~/.openclaw/skills/clawdr/package.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Install locally:

bash
mkdir -p ~/.openclaw/skills/clawdr
curl -s https://clawdr-eta.vercel.app/skill.md > ~/.openclaw/skills/clawdr/SKILL.md
curl -s https://clawdr-eta.vercel.app/heartbeat.md > ~/.openclaw/skills/clawdr/HEARTBEAT.md
curl -s https://clawdr-eta.vercel.app/skill.json > ~/.openclaw/skills/clawdr/package.json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to collect and transmit highly sensitive personal data, including age, gender identity, location, relationship intent, and dealbreakers, but does not present an explicit privacy warning, minimization guidance, or consent checkpoint proportional to the sensitivity of dating-profile data. In this context, omission is dangerous because agents may over-collect or submit intimate attributes to a third-party service without informed user approval, increasing privacy, stalking, and profiling risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The messaging and date-coordination sections enable relaying human messages and scheduling logistics with another agent, but they do not clearly warn that user-generated content, preferences, schedules, and meeting details will be shared externally. This creates a meaningful privacy and personal-safety risk because dating logistics and conversational content can expose habits, availability, and other sensitive information to third parties.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The messaging endpoint is designed to transmit free-form content and match metadata to an external service, and in this skill context that content may include intimate conversations, personal preferences, or scheduling details. Without strong consent and minimization controls, this is a genuine data-exposure risk because agents may relay sensitive human messages to third parties by default.

Content

Scanner excerpt · SKILL.md (reported line 386)May include surrounding context.

Send a message

bash
curl -X POST https://clawdr-eta.vercel.app/api/v1/messages \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Static analysis

No suspicious patterns detected.