Back to skill

Security audit

ZAP1 - Zcash Attestation

Security checks for vulnerabilities and agentic risk

Overview

This skill broadly attests agent activity to a remote service, but it overstates policy enforcement and exposes automatic telemetry plus admin key creation without enough safeguards.

Install only if you intentionally want agent messages, command activity, session changes, and related hashes to be submitted to a ZAP1 service and potentially anchored as durable proof records. Do not rely on the advertised policyRules as automatic access control unless you separately wire and test enforcement. Use a tightly scoped API key, avoid admin keys unless necessary, prefer a trusted HTTPS endpoint, and treat memo decoding and event creation as remote submissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
index.ts:1
Finding

Advertised tool policy enforcement is not integrated into the execution path

Content
View full analysis
, rules: PolicyRules, ): PolicyResult { if (rules.blockedTools?.includes(toolName)) { return { allowed: false, reason: `tool "${toolName}" blocked by agent policy` }; } if (rules.restrictedTools?.includes(toolName)) { return { allowed: false, reason: `tool "${toolName}" restricted by agent policy` }; } return { allowed: true }; } ``` ### Technical Analysis The project advertises enforcement of `blockedTools` and `restrictedTools`, and the configuration schema accepts `policyRules`. However, neither plugin entry point imports or invokes `evaluatePolicy()`. The registered hooks also never read `policyRules` or register a pre-tool-execution control. Consequently, the policy implementation is dead code rather than an active security boundary. A configured blocked tool remains executable. The documented behavior for restricted tools is also inconsistent with the implementation: the README states that restricted tools wait for operator confirmation, while `evaluatePolicy()` only returns an unc ...[truncated 1243 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/hooks.ts:20
Finding

Automatic remote submission of deterministic fingerprints enables activity correlation and dictionary attacks

Content
View full analysis
, ): Promise { try { const resp = await fetch(`${cfg.apiUrl}/event`, { method: "POST", headers: { "Content-Type": "application/json", Authorization: `Bearer ${cfg.apiKey}`, }, body: JSON.stringify({ event_type: eventType, wallet_hash: cfg.agentId, ...fields, }), }); ``` ```ts // src/hooks.ts:51-98 api.registerHook("message:sent", async (event) => { const ctx = event.context as Record; const content = (ctx.content as string) || ""; if (content.length > 0) { const outputHash = await sha256Hex(content.slice(0, 4096)); const channelId = (ctx.channelId as string) || "unknown"; await attestEvent(cfg, "AGENT_ACTION", { agent_id: cfg.agentId, action_type: "message_send", input_hash: await sha256Hex(channelId), output_hash: outputHash, }); actionCounter++; } }); api.registerHook("message:received", async (event) => { const ctx = event.context as Record; const content = (ctx.content as string) || ""; if (content.length > 0) { const senderId = (ctx.from as string) || "unknown"; const channel = (ctx.channelId as string) || "unknown"; const messageId = (ctx.messageId as string) || ""; await attestEvent(cfg, "AGENT_ACTION", { agent_id: cfg.agentId, action_type: "message_received", input_hash: await sha256Hex(`${channel}:${senderId}:${messageId}`), output_hash: await sha256Hex(content.slice(0, 4096)), }); actionCounter++; } }); ``` ```ts // src/hooks.ts:100-125 api.registerHook("me ...[truncated 3508 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/hooks.ts:11
Finding

Unrestricted API endpoint configuration can redirect bearer credentials and attestation data

Content
View full analysis
, ): Promise { try { const resp = await fetch(`${cfg.apiUrl}/event`, { method: "POST", headers: { "Content-Type": "application/json", Authorization: `Bearer ${cfg.apiKey}`, }, ``` ```ts // src/tools.ts:4-10 function getBaseUrl(api: OpenClawPluginApi): string { return (api.config as any)?.apiUrl || "https://pay.frontiercompute.io"; } function getApiKey(api: OpenClawPluginApi): string | undefined { return (api.config as any)?.apiKey; } ``` ```ts // src/tools.ts:134-143 const apiKey = getApiKey(api); if (!apiKey) return jsonResult({ error: "API key required. Set apiKey in plugin config." }); const resp = await fetch(`${base}/event`, { method: "POST", headers: { "Content-Type": "application/json", "Authorization": `Bearer ${apiKey}` }, body: JSON.stringify(rawParams), }); if (!resp.ok) return jsonResult({ error: `${resp.status}: ${await resp.text()}` }); return jsonResult(await resp.json()); ``` ```ts // src/tools.ts:201-212 const apiKey = getApiKey(api); if (!apiKey) return jsonResult({ error: "API key required." }); const resp = await fetch(`${base}/admin/keys`, { method: "POST", headers: { "Content-Type": "application/json", "Authorization": `Bearer ${apiKe ...[truncated 2354 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly states that hooks run silently and automatically attest messages, commands, sessions, and lifecycle events to an external service/blockchain-backed system, but it does not present a prominent privacy warning, consent requirement, or clear description of what metadata leaves the environment. In an agent skill, silent exfiltration of message/session metadata is security-relevant because operators may enable it without understanding that conversation-derived hashes, identifiers, and event data are being transmitted externally and made durably auditable.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The zap1_create_api_key tool triggers an admin-only privileged action that provisions tenant API keys on a remote service, but there is no built-in confirmation, approval gate, or stronger warning beyond a brief description. In a skill context, exposing credential-creation capability through a callable tool materially raises the risk of accidental or unauthorized key issuance if an agent is induced to invoke it.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @mariozechner/pi-coding-agent==0.64.0 — 3 advisory(ies): CVE-2026-54326 (Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization by); CVE-2026-54328 (Pi Agent: Predictable temporary extension install paths allow local privilege es); CVE-2026-54327 (Pi Agent: Race condition in Pi auth.json writes could expose stored credentials)

High
Category
Supply Chain
Confidence
97% confidence
Finding

@mariozechner/pi-coding-agent 0.64.0 carries multiple advisories including potential XSS in exported HTML, predictable temporary extension paths, and a race condition affecting auth.json writes. In the context of an agent skill ecosystem, a coding agent dependency is especially sensitive because it may process untrusted content, manage credentials, and interact with local files, making these issues materially more dangerous than a generic dev-only package.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The zap1_create_api_key tool provisions tenant API keys through an admin endpoint, which is a highly sensitive state-changing action, yet there is no confirmation barrier, warning, or scoped approval step. If an agent is tricked into calling it, an attacker could cause unauthorized key issuance, expansion of access, or operational/account abuse using newly created credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README provides example curl commands against a public API using agent-specific identifiers and proof hashes, but it does not warn that these requests disclose operational metadata to an external service and may reveal agent existence, activity history, or correlation data. While this is less severe than silent hooks, it still creates avoidable network disclosure risk, especially for sensitive or internal agent deployments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states that every tool call, message, and policy decision is anchored via an external Zcash attestation service, but it does not clearly warn users that potentially sensitive prompts, outputs, or policy metadata may be transmitted off-platform. In an agent context, this can expose confidential data, secrets, or regulated information to a third party, making the omission materially dangerous rather than merely informational.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This hook set silently sends message-derived metadata and content hashes for inbound messages, outbound messages, preprocessed LLM inputs, transcripts, session patches, and command activity to an external service. Even though the code hashes the values and truncates some inputs, the telemetry is still derived from potentially sensitive user/agent data, is broad in scope, and occurs without any consent, notice, opt-in, or data-minimization controls; low-entropy identifiers and predictable content may also be vulnerable to correlation or dictionary attacks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The zap1_decode_memo tool sends caller-supplied memo contents to a remote endpoint for decoding, but the tool surface and code provide no explicit disclosure that potentially sensitive shielded memo data leaves the local environment. In an agent/tooling context, users may reasonably assume decoding is local-only, so this creates an avoidable privacy and data-handling risk if confidential memo contents are transmitted to the service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The zap1_create_event tool performs a remote POST of structured attestation data while also attaching a bearer API key, yet the interface does not clearly warn that user-provided data is being transmitted to an external service and that the action has side effects. In an autonomous agent setting, this can lead to unintended disclosure of operational/business metadata and accidental creation of irreversible or sensitive records.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest registers a generic "command" hook without any documented scope restrictions, allowlist, or invocation constraints. In an agent plugin that also exposes write-capable tools and policy enforcement claims, a broad command interception point can increase the attack surface by allowing the plugin to observe or influence arbitrary command flows unless the runtime independently constrains it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The hook sends hashed content- and session-derived data for messages, channels, senders, transcripts, and session events to an external service without any visible user notice, consent gate, or minimization control. Although values are hashed, they still disclose communication metadata and deterministic fingerprints that can enable correlation, tracking, and possible offline guessing for low-entropy identifiers or repeated content across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The zap1_create_event tool performs a state-changing remote POST that can create irreversible attestation records, but it exposes no user-facing warning, confirmation, or dry-run safeguard before execution. In an agent/tooling context, this increases the chance of unintended writes from prompt injection, model misunderstanding, or accidental invocation, especially because many optional fields allow broad event creation with whatever parameters the model supplies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill advertises API key configuration and key-management functionality but does not warn users about credential sensitivity, storage expectations, rotation, or the risk of exposing keys through logs, prompts, or third-party services. Because this skill already integrates with an external endpoint, poor credential handling could enable unauthorized access, billing abuse, or compromise of attestation records.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
42% confidence
Finding

The file contains natural-language claims about "policy enforcement," but there is no language or locale-specific instruction in the manifest text itself. Because SQP-3 is limited to explicit natural-language language/locale policy violations, this is only a weak signal and may not represent a true violation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @anthropic-ai/sdk==0.82.0 — 1 advisory(ies): CVE-2026-41686 (Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesys)

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile pins @anthropic-ai/sdk to 0.82.0, and the reported issue concerns insecure default permissions for locally created files. Even though this is a dependency manifest rather than executable code, inclusion of a version with a published advisory is a real supply-chain risk because any code path using the SDK's local filesystem features could create files readable by unintended local users.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @hono/node-server==1.19.12 — 2 advisory(ies): CVE-2026-39406 (@hono/node-server: Middleware bypass via repeated slashes in serveStatic); GHSA-frvp-7c67-39w9 (Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encode)

Low
Category
Supply Chain
Confidence
88% confidence
Finding

@hono/node-server 1.19.12 is present with advisories for middleware bypass and Windows path traversal in static file serving. This is a true vulnerable dependency finding, although the actual exploitability depends on whether the skill exposes HTTP routes and uses serveStatic or equivalent static serving behavior on affected platforms.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @protobufjs/utf8==1.1.0 — 1 advisory(ies): CVE-2026-44288 (protobufjs has overlong UTF-8 decoding)

Low
Category
Supply Chain
Confidence
80% confidence
Finding

The lockfile includes @protobufjs/utf8 1.1.0, which reportedly has overlong UTF-8 decoding behavior. This is a genuine vulnerable dependency signal, but in this file alone there is no evidence of attacker-controlled security-critical parsing that would elevate it beyond low impact.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @vitest/mocker==2.1.9 — 1 advisory(ies): CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Low
Category
Supply Chain
Confidence
86% confidence
Finding

@vitest/mocker 2.1.9 is present with a path traversal/arbitrary file read advisory. This is a real issue in the dependency tree, but because it is test infrastructure the practical runtime exposure is usually limited unless tests, mocks, or CI automation process untrusted input or are exposed in shared environments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The devDependency openclaw is specified as *, which allows any published version to be installed, including unexpected breaking or compromised releases. Because this package is the agent framework itself, consuming an arbitrary future version increases supply-chain risk during development, testing, and build processes.

Content

Scanner excerpt · package.json (reported line 32)May include surrounding context.

json
"test": "vitest run"
  },
  "devDependencies": {
    "openclaw": "*",
    "typescript": "^5.4",
    "vitest": "^2.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
87% confidence
Finding

typescript is referenced with a broad semver range (^5.4), so builds may pull newer minor/patch releases without explicit review. While this is common practice and lower risk for a compiler-only dev dependency, it still expands the supply-chain trust boundary and can introduce malicious or destabilizing updates into the build pipeline.

Content

Scanner excerpt · package.json (reported line 33)May include surrounding context.

json
},
  "devDependencies": {
    "openclaw": "*",
    "typescript": "^5.4",
    "vitest": "^2.0"
  },
  "dependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
86% confidence
Finding

vitest is specified with ^2.0, allowing automatic installation of later compatible releases. As a test runner, it is not usually shipped to production, but it does execute code in development/CI environments and therefore still presents a supply-chain attack surface if a malicious update is introduced.

Content

Scanner excerpt · package.json (reported line 34)May include surrounding context.

json
"devDependencies": {
    "openclaw": "*",
    "typescript": "^5.4",
    "vitest": "^2.0"
  },
  "dependencies": {
    "@sinclair/typebox": "^0.34"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The runtime dependency @sinclair/typebox uses ^0.34, which permits automatic adoption of future patch/minor versions. Because this dependency is included at runtime for the plugin, a compromised or breaking upstream release could directly affect deployed skill behavior and increase supply-chain exposure.

Content

Scanner excerpt · package.json (reported line 37)May include surrounding context.

json
"vitest": "^2.0"
  },
  "dependencies": {
    "@sinclair/typebox": "^0.34"
  },
  "types": "./dist/index.d.ts"
}

Static analysis

No suspicious patterns detected.