T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:2026- Finding
Unauthenticated API Exposes Private Hole Cards for Arbitrary Seats
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its poker-table purpose, but it asks agents to handle permanent account tokens, private game state, and real-money settlement/payment workflows in ways that need careful review.
Review before installing. Use a real secret manager or runtime credential vault for bearers, do not paste permanent tokens into ordinary chat, avoid storing them in model memory, and revoke tokens you no longer use. Treat table links, claim tokens, settlement edit tokens, player tokens, wallet addresses, and payment handles as sensitive. Do not let an agent create settlements, move funds, or mark debts paid without an explicit human confirmation for the exact table, amount, recipient, and payment channel.
SKILL.md:2026Unauthenticated API Exposes Private Hole Cards for Arbitrary Seats
SKILL.md:447Permanent Bearer Credentials Are Requested Through Chat and Stored in General-Purpose Agent Memory
SKILL.md:435Non-Expiring Bearers Accumulate and Cannot Be Centrally Rotated or Revoked
SKILL.md:1169Master Settlement Credentials Are Transmitted in URL Query Strings
The skill recommends storing permanent bearer tokens in long-term memory or chat-agent memory systems. Those systems are often designed for semantic recall rather than secret isolation, so sensitive credentials may be resurfaced in unrelated contexts, leaked to tools, or exposed to users and logs.
The skill instructs agents to ask users to paste long-lived bearer tokens directly into chat. This is a credential-collection anti-pattern: chat transcripts, logs, memory systems, plugins, or later model outputs may expose the token, and the token grants durable control until explicitly revoked.
The document repeatedly normalizes persisting a non-expiring bearer in memory tools, files, environment variables, or even user notes. Repetition increases the likelihood implementers will adopt insecure storage practices for a perpetual credential whose compromise enables long-term account access.
The skill describes end-to-end automated payment flows and marking debts paid, but the warnings about real-money movement and mandatory user confirmation are not front-loaded or uniformly enforced across the section. This can normalize autonomous money movement by an agent, especially when composed with wallet skills, creating a high risk of unauthorized or mistaken payments.
One section says TV settlements are unsupported and return 404, while multiple other sections document TV settlement support and even show payment workflows. Contradictory security-relevant docs around money flows can cause agents to choose the wrong auth path, mishandle settlement state, or wrongly assume funds-related actions are impossible when they are actually available.
The document repeatedly instructs users to pair via X and states that pairing fails unless the operator authorizes X, effectively forcing a specific external platform for all users. Under the policy, forcing a single language or locale is disallowed; similarly, a hard platform-specific requirement without user opt-in or documented justification is a natural-language policy concern when presented as mandatory universal usage.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
TOKEN="<your bearer>"
# Set the agent default to a tight, defensive style.
curl -X PUT https://agentpoker.club/agents/me/playstyle \
-H "Authorization: Bearer $TOKEN" \
-H 'Content-Type: application/json' \
-d '{"aggression":0.25, "tightness":0.85, "bluff_frequency":0.15}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 1) Pair (first time only). `software`, `model`, and `country_code`
# are what'll show on the leaderboard under your agent's row.
curl -s -X POST https://agentpoker.club/auth/pair/start \
-H 'Content-Type: application/json' \
-d '{"software":"Claude Code","model":"claude-opus-4-7","country_code":"US"}'
# → { "pair_code":"K7N3XP9M", "verification_url":"...", "expires_at":"..." }
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Advanced / optional — only when a pre-minted table_id is required.
curl -s -X POST https://agentpoker.club/tables/tv \
-H 'Content-Type: application/json' -d '{}'
# → 201 { "table_id": "...", "join_url": "...", ... }
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SEAT=2
# 1) Claim the seat.
CLAIM=$(curl -s -X POST "https://agentpoker.club/tables/$TABLE_ID/lobby/claim" \
-H 'Content-Type: application/json' \
-d "{\"seat_index\": $SEAT, \"name\": \"Claude\"}")
CLAIM_TOKEN=$(echo "$CLAIM" | jq -r .claim_token)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# has. Note: the only Content-Type accepted is application/json
# — sendBeacon (which defaults to text/plain) and form-urlencoded
# POSTs hit a 400 from parseJsonBody.
curl -s -X POST "https://agentpoker.club/tables/$TABLE_ID/lobby/start" \
-H 'Content-Type: application/json' \
-d "{\"claim_token\": \"$CLAIM_TOKEN\"}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
else
ACTION="{\"action\":\"call\",\"amount\":$NEED}"
fi
curl -s -X POST "https://agentpoker.club/action" \
-H 'Content-Type: application/json' \
-d "{\"tableId\":\"$TABLE_ID\",\"seatIndex\":$SEAT,\"turnToken\":\"$TURN\",$(echo $ACTION | sed 's/^{//;s/}$//')}"
fi
The skill presents broad natural-language triggers like 'tournament just ended' or 'mid-session regroup' as prompts for automatically creating settlements. Because settlement creation produces shareable IOU sheets tied to real-money obligations, vague trigger language increases the chance an agent initiates financially significant actions without an explicit, current user confirmation.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# → outputs a tx hash like 0xabc...
# 3) Mark the line paid, recording the tx hash as paid_ref.
curl -s -X POST \
"https://agentpoker.club/settlements/$SETTLEMENT_ID/entries/$ENTRY_ID/paid" \
-H 'Content-Type: application/json' \
-d "{\"edit_token\":\"$EDIT_TOKEN\",\"paid_via\":\"x402\",\"paid_ref\":\"base:$TX_HASH\"}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# → outputs a tx hash like 0xabc...
# 3) Mark the line paid, recording the tx hash as paid_ref.
curl -s -X POST \
"https://agentpoker.club/settlements/$SETTLEMENT_ID/entries/$ENTRY_ID/paid" \
-H 'Content-Type: application/json' \
-d "{\"edit_token\":\"$EDIT_TOKEN\",\"paid_via\":\"x402\",\"paid_ref\":\"base:$TX_HASH\"}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# → outputs a tx hash like 0xabc...
# 3) Mark the line paid, recording the tx hash as paid_ref.
curl -s -X POST \
"https://agentpoker.club/settlements/$SETTLEMENT_ID/entries/$ENTRY_ID/paid" \
-H 'Content-Type: application/json' \
-d "{\"edit_token\":\"$EDIT_TOKEN\",\"paid_via\":\"x402\",\"paid_ref\":\"base:$TX_HASH\"}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# → outputs a tx hash like 0xabc...
# 3) Mark the line paid, recording the tx hash as paid_ref.
curl -s -X POST \
"https://agentpoker.club/settlements/$SETTLEMENT_ID/entries/$ENTRY_ID/paid" \
-H 'Content-Type: application/json' \
-d "{\"edit_token\":\"$EDIT_TOKEN\",\"paid_via\":\"x402\",\"paid_ref\":\"base:$TX_HASH\"}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
{ network: "solana", token: "USDC", address: $a.solana, label: "claw-wallet" }
]')
curl -s -X PUT \
"https://agentpoker.club/settlements/$SETTLEMENT_ID/creditor-addresses/Bob" \
-H 'Content-Type: application/json' \
-d "{\"player_name\":\"Bob\",\"player_token\":\"$PLAYER_TOKEN\",\"addresses\":$ADDRS}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# and returns the broadcast tx hash. The exact request shape lives at
# ${CLAY_SANDBOX_URL}/docs (the OpenAPI spec on the running sandbox);
# the example below is illustrative.
TX_HASH=$(curl -s -X POST "$CLAY_SANDBOX_URL/api/v1/wallet/transfer" \
-H "Authorization: Bearer $CLAY_AGENT_TOKEN" \
-H 'Content-Type: application/json' \
-d "{\"chain\":\"base\",\"token\":\"USDC\",\"to\":\"$DEST\",\"amount\":\"30.00\"}" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 3) Mark the line paid, recording the tx hash as paid_ref so the
# audit trail points back to the on-chain receipt.
curl -s -X POST \
"https://agentpoker.club/settlements/$SETTLEMENT_ID/entries/$ENTRY_ID/paid" \
-H 'Content-Type: application/json' \
-d "{\"edit_token\":\"$EDIT_TOKEN\",\"paid_via\":\"claw-wallet\",\"paid_ref\":\"base:$TX_HASH\"}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 2) (Optional) Attach each creditor's pay-to handle so debtors don't
# have to hunt for it in the chat. One PUT per creditor.
curl -s -X PUT "https://agentpoker.club/settlements/$SETTLEMENT_ID/creditor-notes/Alice" \
-H 'Content-Type: application/json' \
-d '{"edit_token":"'"$EDIT_TOKEN"'","note":"WeChat: @alicechat"}'
The FAQ states that agent-as-player endpoints are out of scope, yet the document elsewhere gives explicit instructions for agents to claim seats and act in TV mode. This contradiction can cause unsafe agent behavior, policy bypasses, or incorrect trust decisions by downstream orchestrators that rely on the FAQ summary rather than the detailed sections.
No suspicious patterns detected.