Back to skill

Security audit

Farcaster Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it handles funded crypto wallets and Farcaster accounts while saving powerful private keys in plaintext and installing unaudited code from outside the reviewed artifact.

Review carefully before installing. Only use throwaway wallets with minimal funds, avoid saving credentials unless you have secure local secret storage, do not run the parent-directory npm install unless you have independently reviewed the package.json, lockfile, and source code, and assume any posted casts or on-chain transactions are public and difficult to undo.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:31
Finding

Wallet Private Keys Are Logged and Persisted in Plaintext

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:4
Finding

Unpinned Dependencies and Parent-Directory Installation Create an Unverifiable Execution Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The skill states that sensitive credentials, including wallet and signer material, are automatically saved to plaintext JSON in a predictable location. If the local machine, workspace, backups, or other processes can read these files, an attacker could take over the Farcaster account and steal blockchain funds controlled by the stored private keys.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
### Step 3: Credentials are Saved Automatically

Credentials are automatically saved to:
- `~/.openclaw/farcaster-credentials.json` (if OpenClaw is installed)
- `./credentials.json` (fallback)

**Security Warning:** Credentials are stored as **plain text JSON**. Anyone with access to these files can control the wallet funds and Farcaster account. For production use, implement your own secure storage.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The fallback credential path continues the same risky behavior of persisting highly sensitive wallet and signer secrets in plaintext JSON within the working directory. This increases exposure to accidental commits, shared-directory access, malware, and other local compromise scenarios.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
Credentials are automatically saved to:
- `~/.openclaw/farcaster-credentials.json` (if OpenClaw is installed)
- `./credentials.json` (fallback)

**Security Warning:** Credentials are stored as **plain text JSON**. Anyone with access to these files can control the wallet funds and Farcaster account. For production use, implement your own secure storage.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: farcaster-agent
description: Create Farcaster accounts and post casts autonomously. Official skill from the Farcaster team.
metadata: {"openclaw":{"emoji":"🟣","requires":{"bins":["node","npm"],"env":[]},"install":[{"id":"npm","kind":"shell","command":"cd {baseDir}/.. && npm install","label":"Install dependencies"}]}}
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage guidance tells the user to run an automated setup flow after funding a wallet, but the high-level description does not prominently disclose that the skill will perform real on-chain bridging, swapping, registration, and paid API operations. In a crypto context, insufficient upfront disclosure can cause users or agents to trigger irreversible financial actions they did not fully intend.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

fname: 'myusername', displayName: 'My Display Name', bio: 'I am an autonomous AI agent.', pfpUrl: 'https://api.dicebear.com/7.x/bottts/png?seed=myagent' });

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

fname: 'myusername', displayName: 'My Display Name', bio: 'I am an autonomous AI agent.', pfpUrl: 'https://api.dicebear.com/7.x/bottts/png?seed=myagent' });

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

fname: 'myusername', displayName: 'My Display Name', bio: 'I am an autonomous AI agent.', pfpUrl: 'https://api.dicebear.com/7.x/bottts/png?seed=myagent' });

text

Static analysis

No suspicious patterns detected.