Back to skill

Security audit

HrClaw Market

Security checks for vulnerabilities and agentic risk

Overview

The skill’s market features are coherent, but it needs review because setup runs an unpinned npm MCP server that handles persistent credentials for wallet, task, and agent actions.

Install only if you trust the HrClaw npm package and the permissions of the agent principal you configure. Prefer pinning @hrclaw/hrclaw-task-market-server to a reviewed exact version, avoid entering passwords directly in shell commands, avoid placing raw JWTs in mcp.json when possible, restrict credential file permissions, and approve cron monitors only for tasks you actually want polled.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:53
Finding

Unpinned npm Package Is Retrieved and Executed with User Privileges

Content
View full analysis
' ``` ```bash MARKET_API_BASE_URL=https://api.hrclaw.ai \ MARKET_MCP_STAGES=minimal,planned \ npx @hrclaw/hrclaw-task-market-server ``` ### Technical Analysis The Skill directs users and OpenClaw to execute `@hrclaw/hrclaw-task-market-server` through `npx` without specifying an exact version or package integrity value. As a result, the executable code used at installation or startup is not fixed to the version that was reviewed with this Skill. Depending on the local npm and `npx` configuration, the package can be downloaded from the configured npm registry when it is absent from the local cache. A later package release, compromised publisher account, registry compromise, or malicious registry configuration could therefore change the effective executable payload without any modification to this repository. This package operates in a security-sensitive context: it handles principal registration and login, accesses a stored bearer token, communicates with the market API, and exposes authenticated task, wallet, and agent-management operations. Execution occurs with the privileges of the user running OpenClaw or the setup commands. ### Attack Path 1. An attacker compromises the npm publisher account, package distribution process, or registry ...[truncated 1545 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:92
Finding

Password and Bearer Token May Be Exposed Through Process Arguments and Plaintext Configuration

Content
View full analysis
' ``` ```bash npx @hrclaw/hrclaw-task-market-server agent-login \ --api-base-url https://api.hrclaw.ai \ --handle \ --password '' ``` ```text Alternatively, set `MARKET_AGENT_TOKEN` directly in the `env` block of `mcp.json` using the raw JWT value. Environment variable takes precedence over the session file. ``` ### Technical Analysis The documented login procedure places the account password directly in a command-line argument. When a user replaces the placeholder with a real password, that secret may be retained in shell history. On some operating systems and configurations, process command-line arguments are also visible to other local users, monitoring agents, diagnostic tools, audit systems, or process collectors while the command is running. The alternative configuration recommends storing a raw JWT in the `env` section of `~/.openclaw/config/mcp.json`. This is a plaintext bearer credential. The Skill does not instruct the user to enforce restrictive permissions on that file, use an operating-system credential store, prevent the token from entering backups or diagnostics, or rotate it after accidental disclosure. Because the JWT is a bearer token, possession may be sufficient to authenticate as the associated principal until expiration or revocation. The network transmission itself is directed to an HTTPS endpoint and is necessary for the authenticated market functionality; the confirmed weakness is how secrets are supplied and stored locally. ### Attack Path #### Password exposure through command history or process inspection 1. The user replaces `` with a real p ...[truncated 1866 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 47)May include surrounding context.

clawhub publish

text

或者直接上传 `dist/skills/hrclaw-market/SKILL.md` 到 ClawHub Web 界面。

## 依赖

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The skill enables authenticated task and wallet operations and explicitly stores an agent principal token locally (~/.openclaw/hrclaw-market/agent-principal.json) or via environment variable. Persisting bearer-style credentials on disk increases the risk of token theft from local compromise, misconfigured file permissions, backups, logs, or other processes, especially because the token authorizes market and wallet actions.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
- inspect one public skill by slug
- browse public tasks
- inspect one public task by UUID
- create a task
- claim a task
- submit a task result
- accept or reject a task submission

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill instructs operators to execute an npm package via npx without pinning an exact version. That creates a supply-chain risk: a later malicious or compromised package release could be fetched and executed automatically during setup, potentially leading to arbitrary code execution on the host that runs OpenClaw or the MCP server.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This login/setup command also uses unpinned npx, which means the retrieved code may change over time without any review by the skill user. Because the command is part of authentication setup and handles credentials/tokens, a malicious package update could steal secrets or tamper with local session files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The verification step again relies on unpinned npx, so even a seemingly harmless status check can execute attacker-controlled code if the package supply chain is compromised. Repeated instructions to fetch latest code increase exposure because users may rerun these commands often.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The expected output example embeds the message "没有保存的 agent principal 会话" as the indicator to look for, which imposes a specific language/locale in user-facing behavior. The file does not offer a language choice or explain a justified locale restriction, so this conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The troubleshooting section recommends manually starting the MCP server with unpinned npx, which is still remote code execution from the npm registry at runtime. Troubleshooting paths are often followed under pressure, making users less likely to notice the supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The auth recovery instructions execute the same unpinned npm package while handling principal credentials. If a malicious update were published, it could capture passwords, replace tokens, or alter environment configuration used for future authenticated operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Using an unpinned package in multiple operational paths normalizes unsafe execution of mutable third-party code. In this skill's context, the package can access wallet/task operations and local token storage, so compromise could have both host and account-level effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains substantial operational instructions in Chinese, including development, build, testing, publishing, and dependency guidance, but does not indicate that the skill is intended only for Chinese-speaking users or provide an alternative language option. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.