Back to skill

Security audit

RootData Crypto

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward RootData crypto lookup integration, with expected external API calls and disclosed local API-key storage, but users should note the mutable install command and avoid sending sensitive research queries.

Install only from a ClawHub source you trust, and prefer a pinned installer version if available. Treat searches, wallet or contract addresses, project targets, and people lookups as data sent to RootData; avoid using this skill for confidential diligence or sensitive investigations unless that disclosure is acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:15
Finding

Mutable Third-Party Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 15-19
Vulnerability Type: Insecure dependency and supply-chain exposure
Risk Level: Medium

Vulnerable Code Snippet

markdown
Install via ClawHub:

```text
npx clawhub@latest install rootdata-crypto
text

### Technical Analysis

The documented installation command directs `npx` to resolve and execute the mutable `latest` version of the third-party `clawhub` package. The package version is not pinned, and the command does not verify a cryptographic integrity hash or package provenance.

Consequently, the code executed by users may differ from the version that existed when this Skill was reviewed. This creates a supply-chain trust boundary in which compromise of the package registry, publisher account, package release process, or upstream dependency tree could introduce attacker-controlled code.

### Attack Path

1. An attacker compromises the `clawhub` publisher account, release infrastructure, or a dependency included by a future release.
2. The attacker publishes a malicious release and causes it to resolve under the `latest` distribution tag.
3. A user follows the installation command from `README.md`.
4. `npx` downloads the mutable package release and executes it locally.
5. The malicious package runs with the privileges and environment access of the user performing the installation.

### Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that user's privileges and environment, the malicious package could access readable files, environment variables, credentials, source repositories, and network resources, or modify files available to that account.

The reviewed project itself contains no executable scripts, privilege-escalation logic, or persistence mechanism. Therefore, elevated privileges or system-wide compromise are not established directly by the repository and would depend on the installation 
...[truncated 42 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable latest reference with an exact, reviewed package version, for example:
    bash
    npx clawhub@<reviewed-version> install rootdata-crypto
    
  2. Document the expected package publisher, registry, and provenance so users can validate the package source.
  3. Where supported, require signature or provenance verification and validate the package integrity digest before execution.
  4. Use a lockfile, trusted installer, or controlled internal package mirror to make dependency resolution reproducible.
  5. Review the pinned package and its transitive dependencies before recommending the command.
  6. Avoid running installation commands with administrative privileges and use an isolated, least-privileged environment where practical.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (11)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to run npx clawhub@latest install rootdata-crypto, which pulls and executes the latest published package version at install time rather than a pinned, reviewed version. If the upstream package, its dependencies, or the distribution channel is compromised, users could execute attacker-controlled code on their systems during installation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The initialization flow contacts an external RootData endpoint and stores the returned API key in a local environment variable. Although the key is described as low-privilege, this still establishes outbound connectivity and persistent secret storage without an explicit trust/consent boundary in the skill itself.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

If it does NOT exist, call:

text
POST https://api.rootdata.com/open/skill/init
Content-Type: application/json
Body: {}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill sends user-provided search terms and identifiers to a third-party API but does not warn the user that their queries will be transmitted off-platform. This creates a privacy and consent issue, especially if users include sensitive investigation targets, wallet addresses, names, or proprietary research terms in requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This endpoint transmits user-supplied search keywords to an external third-party service. If a user includes sensitive names, wallet addresses, internal codenames, or investigative queries, that information is disclosed to RootData without any warning in the skill text.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Request:

text
POST https://api.rootdata.com/open/skill/ser_inv
Body:
{
  "query": "<search keyword>",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

Request:

text
POST https://api.rootdata.com/open/skill/id_map
Body:
{
  "type": <1=Project | 2=Institution | 3=Person>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

Request:

text
POST https://api.rootdata.com/open/skill/id_map
Body:
{
  "type": <1=Project | 2=Institution | 3=Person>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

Request:

text
POST https://api.rootdata.com/open/skill/id_map
Body:
{
  "type": <1=Project | 2=Institution | 3=Person>

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

Project detail lookups send project IDs or contract addresses to RootData and may return enriched personnel and investor data. Contract addresses and target entities can be sensitive in some investigative or enterprise contexts, so transmitting them externally without user notice creates a meaningful privacy and intelligence-leak risk.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

Request:

text
POST https://api.rootdata.com/open/skill/get_item
Body:
{
  "project_id": <numeric project ID>,

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Funding-round queries may transmit project identifiers, time windows, and amount filters reflecting user interests or internal diligence activity to an external provider. In aggregate, this can reveal sensitive research focus or business intent even if individual parameters appear harmless.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

Request:

text
POST https://api.rootdata.com/open/skill/get_fac
Body:
{
  "page": 1,

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Person-detail lookups transmit specific person IDs to RootData and retrieve profile, influence, and education data. Queries about named individuals can be sensitive in investigative, HR, compliance, or adversarial contexts, so sending them externally without disclosure creates a privacy and monitoring risk.

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

Request:

text
POST https://api.rootdata.com/open/skill/get_people
Body:
{
  "people_id": <numeric person ID>

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README states that an anonymous API key is automatically generated on first use, but it does not clearly warn users about that side effect, what data is sent, where the key is stored, or any privacy/accountability implications. Silent credential generation can surprise users, hinder informed consent, and create unnecessary trust and tracking concerns even if the key is low-privilege.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.