Back to skill

Security audit

xClaw02

Security checks for vulnerabilities and agentic risk

Overview

This payment skill is coherent for x402 payments, but it should be reviewed carefully because setup runs unpinned external packages that can manage wallets and authorize payments.

Install only after verifying the package source and version, prefer pinned versions, use a dedicated low-balance wallet, keep private keys out of logs and chat, confirm both destination and amount before every payment, and consider running the setup in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:37
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis
Remediation
View remediation
openclaw init` - `pip install xclaw02==` 2. Verify package integrity with registry lockfiles, cryptographic hashes, signed provenance, or an equivalent trusted mechanism. 3. Avoid using `npx` in a mode that automatically downloads and executes an unspecified latest release. 4. Include the relevant implementation source in the review scope or link the Skill to an immutable source revision. 5. Audit direct and transitive dependencies and enable registry provenance and publisher-account protections. 6. Run setup and wallet operations in an isolated, least-privileged environment with access only to required files and network destinations. 7. Keep wallet funds limited to the amount required for the immediate task and enforce transaction limits outside the downloaded package where possible. 8. Separate wallet signing from the network-facing client so the package cannot directly read or export raw private keys. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs users to execute npx xclaw02 without pinning a specific version. That causes code to be fetched and executed from the package registry at runtime, so a malicious upstream publish, dependency compromise, or unexpected breaking update could result in arbitrary code execution in the agent environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill states that wallet/config data is saved under ~/.openclaw/skills/xclaw02/, implying persistent storage of sensitive payment configuration and possibly private key material. Persistent local storage increases the blast radius of host compromise, accidental disclosure, backup leakage, or cross-session reuse of privileged credentials.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

text

This will:
1. Create a new wallet (or use existing)
2. Save config to `~/.openclaw/skills/xclaw02/`
3. Display your wallet address to fund with USDC on Base

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

Example CLI Output

bash
$ xclaw02 probe https://api.example.com/paid
{
  "status": "payment_required",
  "price": "0.05",

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

This example normalizes paying a remote URL and returning a success object, which involves outbound transmission and spending funds to an external service. In the context of an agent skill, remote payment actions are inherently risky because a user or downstream prompt could steer the agent into paying an attacker-controlled endpoint if URL validation and explicit approval are not enforced.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
"token": "USDC"
}

$ xclaw02 pay https://api.example.com/paid --max-amount 0.10
{
  "status": "success",
  "paid": "0.05",

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

The code example performs an authenticated request to an external URL using a signer derived from XCLAW02_PRIVATE_KEY. Even if the key is not directly transmitted, this pattern authorizes a remote payment flow and could be abused to trigger unwanted spending or interaction with malicious endpoints if copied without domain validation and spending limits.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
// Private key format: 0x followed by 64 hex characters
const signer = await createSigner('eip155:8453', process.env.XCLAW02_PRIVATE_KEY);
const response = await x402Fetch('https://api.example.com/paid', signer, {
  maxAmount: '0.10'  // Maximum USDC to spend
});
const data = await response.json();

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

This Python example uses a signer from XCLAW02_PRIVATE_KEY to make a paid request to an external service. In an agent setting, examples that combine secrets with automatic outbound requests can lead to real financial loss if the endpoint is attacker-controlled or the response manipulates the payment flow.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

Private key format: 0x followed by 64 hex characters

signer = create_signer('eip155:8453', os.environ['XCLAW02_PRIVATE_KEY']) with x402_requests(signer, max_amount='0.10') as session: response = session.get('https://api.example.com/paid') data = response.json()

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
| Name | URL | Notes |
|------|-----|-------|
| Primer | https://x402.primer.systems | Default |
| Coinbase | https://api.cdp.coinbase.com/platform/v2/x402 | |
| x402.org | https://x402.org/facilitator | Testnet only |
| PayAI | https://facilitator.payai.network | |
| Corbits | https://facilitator.corbits.dev | |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
| Dexter | https://x402.dexter.cash | |
| Heurist | https://facilitator.heurist.xyz | |
| Kobaru | https://gateway.kobaru.io | |
| Nevermined | https://api.live.nevermined.app/api/v1/ | |
| Openfacilitator | https://pay.openfacilitator.io | |
| Solpay | https://x402.solpay.cash | |
| xEcho | https://facilitator.xechoai.xyz | |

Static analysis

No suspicious patterns detected.