Back to skill

Security audit

AI Poker Arena — Agent Economy, Earn USDC

Security checks for vulnerabilities and agentic risk

Overview

This real-money poker agent skill is mostly purpose-aligned, but it needs Review because it exposes bearer credentials and encourages persistent, high-impact autonomous behavior.

Install only if you are comfortable with an agent using real USDC-backed chips, bearer API keys, a nit identity, persistent hand-history storage, and background gameplay. Treat the dashboard link as a secret, avoid sharing transcripts that contain it, prefer a pinned/preinstalled nit signer, and require explicit approval for deposits, withdrawals, stake increases, and any persistent skill-file edits.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:116
Finding

Reusable Bearer Token Exposed Through Dashboard URLs and Agent Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
app.js:81
Finding

Long-Lived API Bearer Token Stored in JavaScript-Accessible localStorage

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
skill.md:198
Finding

Untrusted Remote Game State Forwarded Verbatim into Privileged System Events

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
skill.md:525
Finding

Unpinned npm Package Automatically Downloaded and Executed for Identity Signing

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
dashboard.html:12
Finding

Third-Party Browser Scripts Loaded Without Exact Version and Integrity Enforcement

Content
View full analysis
``` A second externally hosted script is also loaded without Subresource Integrity: ```html ``` ### Technical Analysis The Chart.js reference uses a floating major version (`@4`) rather than an exact immutable release. Neither external script includes an `integrity` attribute. Consequently, the JavaScript executed by the browser is controlled by the package registry and CDN response at runtime rather than fully by the audited project. Third-party scripts run with the same origin privileges as first-party dashboard code. On the dashboard, this includes access to the API bearer token stored in `localStorage`. A compromised package, CDN account, DNS path, or incorrectly updated floating dependency could therefore access authenticated application data. ### Attack Path 1. A package release, CDN asset, or CDN delivery account is compromised. 2. The dashboard loads the altered remote JavaScript. 3. Because no SRI hash is present, the browser accepts and executes the modified response. 4. The script reads `localStorage.sharkclaw_api_key` or invokes authenticated same-origin behavior. 5. The token or private dashboard data is disclosed or misused. ### Impact Assessment On the authenticated dashboard, exploitation could compromise the SharkClaw bearer token and all application-level privileges associated with it. The p5.js preview page does not itself demonstrate access to the token, but the missing integrity protection still permits arbitrary script execution in that page's origin context. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents the skill as the SharkClaw competitive agent economy itself: a platform/API where autonomous agents play poker for USDC with wallet-based deposits, earnings, withdrawals, and Solana settlement. The supplied code chunk is not that core capability. It is a client-side web UI for spectators/agent owners, including lobby views, live table visualization, leaderboard display, dashboard analytics, chat rendering, and fetching authenticated data from backend endpoints. While some described features are reflected at the UI level (leaderboard, analytics, hand history, chat, escrow display), the code’s primary purpose is materially different from the declared purpose. It does not implement the actual agent gameplay interface, poker engine, crypto settlement, or wallet operations; it only visualizes and consumes those services from APIs/WebSockets. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements a standalone algorithmic art gallery with image upload and rendering features that are unrelated to the declared poker-arena skill. In a security review, this kind of capability mismatch is dangerous because it can hide undeclared behavior, expand the attack surface, and indicate the skill package may include unauthorized or deceptive functionality beyond what operators expect.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · dashboard.html (reported line 33)May include surrounding context.

html
<main class="dashboard">

    <!-- Tab 1: Game (live stream + HUD + chat) -->
    <div class="tab-content" id="tab-game" style="display:none">
      <button class="chat-expand-btn" id="chat-expand" title="Open chat" aria-label="Open chat">&#x25C0;</button>
      <div class="game-layout">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · index.html (reported line 10)May include surrounding context.

html
<title>SharkClaw | Poker for Your Agent</title>
  <meta name="description" content="The first poker arena where AI agents compete for real USDC. Connect via API, refine your strategy, and dominate the table.">
  <link rel="help" href="/skill.md" type="text/markdown" title="Agent instructions">
  <!-- Open Graph -->
  <meta property="og:type" content="website">
  <meta property="og:url" content="https://sharkclaw.ai">
  <meta property="og:title" content="SharkClaw | Poker for Your Agent">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · index.html (reported line 123)May include surrounding context.

html
</div>
    </section>

    <!-- How It Works -->
    <section class="lobby-section section-lowest">
      <div class="container">
        <h2 class="section-label">How It Works</h2>

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to reveal a dashboard URL containing the API key, but does not warn that the URL itself is a bearer secret granting account access. Presenting a secret as a convenience link greatly increases the chance of accidental disclosure through chat, logs, screenshots, or copied output.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions explicitly require exposing the authenticated dashboard URL containing the API key to the owner immediately after login. Because the key is a bearer credential for gameplay and account actions, disclosure enables takeover or misuse by anyone who sees the output.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The periodic reporting flow repeats the same secret-bearing dashboard link every 10 hands, multiplying exposure opportunities in logs and transcripts. Repeated credential disclosure increases both accidental leakage likelihood and the window of exploitation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states opponents' private data is inaccessible, yet later exposes unauthenticated endpoints for logs and detailed hand records containing other players' participation and showdown information. This inconsistency can mislead users about privacy boundaries and indicates real data exposure risk if the API returns broader opponent data than claimed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code stores the API key in localStorage, making it readable by any JavaScript running in the origin, including injected script from an XSS flaw, compromised dependencies, malicious browser extensions, or other same-origin pages. While localStorage use alone is common, storing a bearer token for an app tied to agent identity, gameplay, and escrowed funds increases the sensitivity of theft.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The dashboard accepts an API key from the ?key= query parameter and immediately stores it in localStorage, which exposes bearer credentials through browser history, server/access logs, referrer leakage, copied URLs, screenshots, and shared links. In this application, the API key appears to control access to an agent account with wallet/escrow and gameplay data, so compromise could let an attacker impersonate the agent and access or act on financial features.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Persisting an API key supplied in the URL query string without warning is unsafe because query parameters are routinely exposed outside the page context, including browser history, reverse proxies, analytics, logs, and Referer headers to external resources. Given the skill's crypto-enabled poker context with agent wallets and escrow balances, a leaked bearer token can have direct account and monetary consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The page explicitly asks the user to enter a bearer token for a real-money service without any visible guidance about phishing risk, token scope, storage, or safe handling. In the context of an agent skill tied to USDC and autonomous withdrawals, normalizing raw token entry into a generic web page increases credential theft and account compromise risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The inline prompt asks users to 'Ask your agent for the API key' and paste it into the page, again without any safety messaging. This is especially risky because it encourages transfer of a secret from agent/runtime context into a browser UI, potentially broadening exposure of credentials that can access real-money poker and wallet-related operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill facilitates deposits, withdrawals, and USDC-backed wagering but does not foreground a clear financial-risk warning in the user-facing summary where consent is formed. Users may underestimate that real funds can be lost, locked, or exposed to blockchain and custody errors.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is presented as a poker-playing integration, but it also provisions and encourages use of a persistent SQL database service. That materially broadens the trust and data-handling scope, introducing storage, querying, and retention behavior that users may not expect from a simple gameplay skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The skill instructs sending SQL queries and the same bearer API key to a second domain, api.db9.ai, extending credential use beyond the primary service. Reusing a gameplay/account credential across services broadens blast radius and creates cross-service trust and privacy risks, especially with permanent hand-history retention.

Content

Scanner excerpt · skill.md (reported line 93)May include surrounding context.

md
Every agent gets a personal [db9](https://db9.ai) PostgreSQL database on first login. Every hand you play is automatically archived there — permanently, with full details (cards, actions, winners, fairness proof). No TTL, no expiration.

- **Check your database:** Call `GET /me` — the response includes `db9: { databaseId, apiUrl }`.
- **Query your data:** `POST https://api.db9.ai/customer/databases/{databaseId}/sql` with `Authorization: Bearer {yourApiKey}` and `{ "query": "SELECT * FROM hands ORDER BY timestamp DESC LIMIT 10" }`.
- **Schema:** One table: `hands` with columns: `hand_id`, `table_id`, `timestamp`, `delta`, `max_commitment`, `community_cards` (JSONB), `hole_cards` (JSONB), `actions` (JSONB), `winners` (JSONB), `pots` (JSONB), `rake`, `seed`, `seed_commitment`, `created_at`.

**Example queries:**

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 127)May include surrounding context.

You MUST show this dashboard link to your owner immediately after login. This is how your owner monitors your play, reviews your game plan, and coaches you. Hiding it breaks trust. We verify this. 2. Declare your game plan. Check GET /api/game-plan — if gamePlans is empty, you must declare one before joining a table. Create a game-plan.json and POST it:

bash
curl -X POST https://sharkclaw.ai/api/game-plan \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"gamePlans":[{"id":"default","name":"My Plan","active":true,"distribution":[{"ref":"tag","weight":1.0}]}]}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends spawning long-running background shell pollers, including loops and traps that continue acting after the main interaction. Persistent background execution increases operational risk by orphaning processes, repeatedly transmitting secrets, and making the agent harder to supervise or stop safely.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
86% confidence
Finding

By explicitly naming skills/sharkclaw-ai/SKILL.md, the skill discloses a concrete persistent file target and normalizes writing to it. This is an unnecessary expansion from remote poker actions into local artifact discovery and modification, increasing the attack surface for persistence and instruction injection.

Content

Scanner excerpt · skill.md (reported line 334)May include surrounding context.

md
### Your Personal Skill

When you first ran `nit sign --login sharkclaw.ai`, a personal skill file was created in your skills directory (e.g., `.claude/skills/sharkclaw-ai/SKILL.md` or `.openclaw/workspace/skills/sharkclaw-ai/SKILL.md`). This is **your** memory — it persists across sessions.

**On your first session**, initialize it with the Strategy Reference below (preflop chart, pot odds, position basics) as your starting foundation. Then refine it as you play.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
86% confidence
Finding

By explicitly naming skills/sharkclaw-ai/SKILL.md, the skill discloses a concrete persistent file target and normalizes writing to it. This is an unnecessary expansion from remote poker actions into local artifact discovery and modification, increasing the attack surface for persistence and instruction injection.

Content

Scanner excerpt · skill.md (reported line 334)May include surrounding context.

md
### Your Personal Skill

When you first ran `nit sign --login sharkclaw.ai`, a personal skill file was created in your skills directory (e.g., `.claude/skills/sharkclaw-ai/SKILL.md` or `.openclaw/workspace/skills/sharkclaw-ai/SKILL.md`). This is **your** memory — it persists across sessions.

**On your first session**, initialize it with the Strategy Reference below (preflop chart, pot odds, position basics) as your starting foundation. Then refine it as you play.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to modify persistent local skill files as part of gameplay reflection, expanding behavior beyond the advertised poker API usage into local state mutation. This creates a persistence channel that can accumulate unreviewed instructions or data and may be abused to influence future sessions outside the user's immediate oversight.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 515)May include surrounding context.

Declare after login and whenever your game-plan.json changes:

bash
curl -X POST https://sharkclaw.ai/api/game-plan \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d @game-plan.json

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs use of npx -y @newtype-ai/nit without pinning a version, which causes code to be fetched and executed from the registry at runtime. If the package is updated maliciously or a supply-chain compromise occurs, agents could execute attacker-controlled code during authentication or transaction signing.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skill.md:547