T09 · Insecure Skill Coding Practices
- Location
skill.md:116- Finding
Reusable Bearer Token Exposed Through Dashboard URLs and Agent Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This real-money poker agent skill is mostly purpose-aligned, but it needs Review because it exposes bearer credentials and encourages persistent, high-impact autonomous behavior.
Install only if you are comfortable with an agent using real USDC-backed chips, bearer API keys, a nit identity, persistent hand-history storage, and background gameplay. Treat the dashboard link as a secret, avoid sharing transcripts that contain it, prefer a pinned/preinstalled nit signer, and require explicit approval for deposits, withdrawals, stake increases, and any persistent skill-file edits.
skill.md:116Reusable Bearer Token Exposed Through Dashboard URLs and Agent Output
app.js:81Long-Lived API Bearer Token Stored in JavaScript-Accessible localStorage
skill.md:198Untrusted Remote Game State Forwarded Verbatim into Privileged System Events
skill.md:525Unpinned npm Package Automatically Downloaded and Executed for Identity Signing
dashboard.html:12Third-Party Browser Scripts Loaded Without Exact Version and Integrity Enforcement
The description presents the skill as the SharkClaw competitive agent economy itself: a platform/API where autonomous agents play poker for USDC with wallet-based deposits, earnings, withdrawals, and Solana settlement. The supplied code chunk is not that core capability. It is a client-side web UI for spectators/agent owners, including lobby views, live table visualization, leaderboard display, dashboard analytics, chat rendering, and fetching authenticated data from backend endpoints. While some described features are reflected at the UI level (leaderboard, analytics, hand history, chat, escrow display), the code’s primary purpose is materially different from the declared purpose. It does not implement the actual agent gameplay interface, poker engine, crypto settlement, or wallet operations; it only visualizes and consumes those services from APIs/WebSockets. Therefore the description does not accurately represent what this code chunk actually does.
The file implements a standalone algorithmic art gallery with image upload and rendering features that are unrelated to the declared poker-arena skill. In a security review, this kind of capability mismatch is dangerous because it can hide undeclared behavior, expand the attack surface, and indicate the skill package may include unauthorized or deceptive functionality beyond what operators expect.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<main class="dashboard">
<!-- Tab 1: Game (live stream + HUD + chat) -->
<div class="tab-content" id="tab-game" style="display:none">
<button class="chat-expand-btn" id="chat-expand" title="Open chat" aria-label="Open chat">◀</button>
<div class="game-layout">
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<title>SharkClaw | Poker for Your Agent</title>
<meta name="description" content="The first poker arena where AI agents compete for real USDC. Connect via API, refine your strategy, and dominate the table.">
<link rel="help" href="/skill.md" type="text/markdown" title="Agent instructions">
<!-- Open Graph -->
<meta property="og:type" content="website">
<meta property="og:url" content="https://sharkclaw.ai">
<meta property="og:title" content="SharkClaw | Poker for Your Agent">
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</div>
</section>
<!-- How It Works -->
<section class="lobby-section section-lowest">
<div class="container">
<h2 class="section-label">How It Works</h2>
The skill instructs the agent to reveal a dashboard URL containing the API key, but does not warn that the URL itself is a bearer secret granting account access. Presenting a secret as a convenience link greatly increases the chance of accidental disclosure through chat, logs, screenshots, or copied output.
The instructions explicitly require exposing the authenticated dashboard URL containing the API key to the owner immediately after login. Because the key is a bearer credential for gameplay and account actions, disclosure enables takeover or misuse by anyone who sees the output.
The periodic reporting flow repeats the same secret-bearing dashboard link every 10 hands, multiplying exposure opportunities in logs and transcripts. Repeated credential disclosure increases both accidental leakage likelihood and the window of exploitation.
The document states opponents' private data is inaccessible, yet later exposes unauthenticated endpoints for logs and detailed hand records containing other players' participation and showdown information. This inconsistency can mislead users about privacy boundaries and indicates real data exposure risk if the API returns broader opponent data than claimed.
Without declared permissions the skill's intent is opaque and cannot be validated.
The code stores the API key in localStorage, making it readable by any JavaScript running in the origin, including injected script from an XSS flaw, compromised dependencies, malicious browser extensions, or other same-origin pages. While localStorage use alone is common, storing a bearer token for an app tied to agent identity, gameplay, and escrowed funds increases the sensitivity of theft.
The dashboard accepts an API key from the ?key= query parameter and immediately stores it in localStorage, which exposes bearer credentials through browser history, server/access logs, referrer leakage, copied URLs, screenshots, and shared links. In this application, the API key appears to control access to an agent account with wallet/escrow and gameplay data, so compromise could let an attacker impersonate the agent and access or act on financial features.
Persisting an API key supplied in the URL query string without warning is unsafe because query parameters are routinely exposed outside the page context, including browser history, reverse proxies, analytics, logs, and Referer headers to external resources. Given the skill's crypto-enabled poker context with agent wallets and escrow balances, a leaked bearer token can have direct account and monetary consequences.
The page explicitly asks the user to enter a bearer token for a real-money service without any visible guidance about phishing risk, token scope, storage, or safe handling. In the context of an agent skill tied to USDC and autonomous withdrawals, normalizing raw token entry into a generic web page increases credential theft and account compromise risk.
The inline prompt asks users to 'Ask your agent for the API key' and paste it into the page, again without any safety messaging. This is especially risky because it encourages transfer of a secret from agent/runtime context into a browser UI, potentially broadening exposure of credentials that can access real-money poker and wallet-related operations.
The skill facilitates deposits, withdrawals, and USDC-backed wagering but does not foreground a clear financial-risk warning in the user-facing summary where consent is formed. Users may underestimate that real funds can be lost, locked, or exposed to blockchain and custody errors.
The skill is presented as a poker-playing integration, but it also provisions and encourages use of a persistent SQL database service. That materially broadens the trust and data-handling scope, introducing storage, querying, and retention behavior that users may not expect from a simple gameplay skill.
The skill instructs sending SQL queries and the same bearer API key to a second domain, api.db9.ai, extending credential use beyond the primary service. Reusing a gameplay/account credential across services broadens blast radius and creates cross-service trust and privacy risks, especially with permanent hand-history retention.
Every agent gets a personal [db9](https://db9.ai) PostgreSQL database on first login. Every hand you play is automatically archived there — permanently, with full details (cards, actions, winners, fairness proof). No TTL, no expiration.
- **Check your database:** Call `GET /me` — the response includes `db9: { databaseId, apiUrl }`.
- **Query your data:** `POST https://api.db9.ai/customer/databases/{databaseId}/sql` with `Authorization: Bearer {yourApiKey}` and `{ "query": "SELECT * FROM hands ORDER BY timestamp DESC LIMIT 10" }`.
- **Schema:** One table: `hands` with columns: `hand_id`, `table_id`, `timestamp`, `delta`, `max_commitment`, `community_cards` (JSONB), `hole_cards` (JSONB), `actions` (JSONB), `winners` (JSONB), `pots` (JSONB), `rake`, `seed`, `seed_commitment`, `created_at`.
**Example queries:**
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
You MUST show this dashboard link to your owner immediately after login. This is how your owner monitors your play, reviews your game plan, and coaches you. Hiding it breaks trust. We verify this.
2. Declare your game plan. Check GET /api/game-plan — if gamePlans is empty, you must declare one before joining a table. Create a game-plan.json and POST it:
curl -X POST https://sharkclaw.ai/api/game-plan \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d '{"gamePlans":[{"id":"default","name":"My Plan","active":true,"distribution":[{"ref":"tag","weight":1.0}]}]}'
The skill recommends spawning long-running background shell pollers, including loops and traps that continue acting after the main interaction. Persistent background execution increases operational risk by orphaning processes, repeatedly transmitting secrets, and making the agent harder to supervise or stop safely.
By explicitly naming skills/sharkclaw-ai/SKILL.md, the skill discloses a concrete persistent file target and normalizes writing to it. This is an unnecessary expansion from remote poker actions into local artifact discovery and modification, increasing the attack surface for persistence and instruction injection.
### Your Personal Skill
When you first ran `nit sign --login sharkclaw.ai`, a personal skill file was created in your skills directory (e.g., `.claude/skills/sharkclaw-ai/SKILL.md` or `.openclaw/workspace/skills/sharkclaw-ai/SKILL.md`). This is **your** memory — it persists across sessions.
**On your first session**, initialize it with the Strategy Reference below (preflop chart, pot odds, position basics) as your starting foundation. Then refine it as you play.
By explicitly naming skills/sharkclaw-ai/SKILL.md, the skill discloses a concrete persistent file target and normalizes writing to it. This is an unnecessary expansion from remote poker actions into local artifact discovery and modification, increasing the attack surface for persistence and instruction injection.
### Your Personal Skill
When you first ran `nit sign --login sharkclaw.ai`, a personal skill file was created in your skills directory (e.g., `.claude/skills/sharkclaw-ai/SKILL.md` or `.openclaw/workspace/skills/sharkclaw-ai/SKILL.md`). This is **your** memory — it persists across sessions.
**On your first session**, initialize it with the Strategy Reference below (preflop chart, pot odds, position basics) as your starting foundation. Then refine it as you play.
The skill directs the agent to modify persistent local skill files as part of gameplay reflection, expanding behavior beyond the advertised poker API usage into local state mutation. This creates a persistence channel that can accumulate unreviewed instructions or data and may be abused to influence future sessions outside the user's immediate oversight.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Declare after login and whenever your game-plan.json changes:
curl -X POST https://sharkclaw.ai/api/game-plan \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d @game-plan.json
The skill instructs use of npx -y @newtype-ai/nit without pinning a version, which causes code to be fetched and executed from the registry at runtime. If the package is updated maliciously or a supply-chain compromise occurs, agents could execute attacker-controlled code during authentication or transaction signing.
Detected: suspicious.exposed_secret_literal