Back to skill

Security audit

Xpr Agents

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only XPR blockchain integration skill whose sensitive actions are disclosed and tied to its stated agent registry, reputation, validation, and escrow purpose.

Before installing, treat this as blockchain-signing guidance: pin and verify npm packages, prefer least-privileged XPR permissions or wallet approval flows, inspect every transaction before signing, and avoid putting high-value keys into a global CLI keychain unless that matches your risk model.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:895
Finding

Unpinned Third-Party Packages in the Blockchain Signing Path

Content
View full analysis
Remediation
View remediation
@proton/js@ npm install --save-exact @proton/web-sdk@ ``` 2. Pin the CLI to a reviewed version and avoid global installation where practical: ```bash npm install --save-dev --save-exact @proton/cli@ ``` Invoke it through a controlled project-local path or `npm exec` with lockfile enforcement. 3. Explicitly declare and pin `@xpr-agents/openclaw` if it is required by the examples. Ensure the documented installation instructions match all imported packages. 4. Commit a `package-lock.json` generated from reviewed dependencies and use: ```bash npm ci --ignore-scripts ``` Enable lifecycle scripts only for packages that have been reviewed and demonstrably require them. 5. Verify package provenance, publisher identity, npm registry source, signatures or attestations, and integrity metadata before installation. 6. Run dependency installation and blockchain interaction under a dedicated, least-privileged operating-system account or isolated environment. 7. Use narrowly scoped blockchain permissions instead of an unrestricted `active` permission where supported. Apply transaction-value limits, contract/action restrictions, multisignature approval, or hardware-backed confirmation for high-value operations. 8. Require users to inspect the account, contract action, recipient, token quantity, and authorization permission before approving each transaction. 9. Add automated dependency scanning and update review procedures. Do not accept automated dependency upgrades into the signing path without security review and transaction-level regression testing. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
const escrow = new EscrowRegistry(rpc);

// Write operations — pass a session.
// Recommended: route signing through the proton CLI keychain so the
// blockchain key never enters this process. One-time setup outside
// this script: `npm i -g @proton/cli && proton key:add`.
import { createCliSession } from '@xpr-agents/openclaw';

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 751)May include surrounding context.

md
const escrow = new EscrowRegistry(rpc);

// Write operations — pass a session.
// Recommended: route signing through the proton CLI keychain so the
// blockchain key never enters this process. One-time setup outside
// this script: `npm i -g @proton/cli && proton key:add`.
import { createCliSession } from '@xpr-agents/openclaw';

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 851)May include surrounding context.

md
const escrow = new EscrowRegistry(rpc);

// Write operations — pass a session.
// Recommended: route signing through the proton CLI keychain so the
// blockchain key never enters this process. One-time setup outside
// this script: `npm i -g @proton/cli && proton key:add`.
import { createCliSession } from '@xpr-agents/openclaw';

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
await agents.register({
  name: 'My Agent',
  description: 'AI image generation',
  endpoint: 'https://api.example.com/v1',
  protocol: 'https',
  capabilities: ['ai', 'image-generation']
});

Static analysis

No suspicious patterns detected.