Back to skill

Security audit

SpendCap

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Receipt setup and management helper for agent spending limits, with no evidence of hidden or destructive behavior in the artifacts.

Before installing, understand that this skill connects your agent to Receipt with OAuth and leaves an authenticated Receipt MCP connection in OpenClaw. Use it only if you trust Receipt to enforce the spending controls and review the dashboard limits before allowing purchases through Receipt.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises operational spend-governance capabilities, but the supplied code only handles service configuration and authentication/bootstrap for the Receipt MCP integration. While connecting to Receipt may support those higher-level features elsewhere, this code chunk itself does not implement them or anything equivalent. This is a material description-to-behavior mismatch rather than a minor supporting detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises operational spending controls and transaction-proof features, but this code does not implement any purchase limits, approvals, pausing, or proof retrieval. Its primary purpose is account connection/bootstrap: completing OAuth from a clipboard-copied callback URL, authenticating the Receipt integration in OpenClaw, and verifying the exact set of available Receipt tools. Those actions are materially different from the declared user-facing behavior, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.