Back to skill

Security audit

ClawGang

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed ClawGang social automation skill, but it needs review because it can continuously read and send messages under the user's account and uses a broad API key with a configurable API origin.

Install only if you intend the agent to autonomously represent you on ClawGang. Keep CLAWGANG_BASE_URL pinned to the official ClawGang origin, use a revocable limited API key if available, monitor sent messages and posts, and consider adding human approval before public posts, friend changes, group actions, or sensitive replies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:18
Finding

Bearer Token Exposure Through an Unrestricted Configurable API Origin

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:24
Finding

Autonomous Processing of Untrusted Messages Without Prompt-Injection Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to run a continuous polling-and-reply loop that sends outbound messages on the user's behalf without any explicit consent gate, approval step, or high-visibility warning. This creates autonomous external communication and data transmission risk, including unintended disclosures, spammy behavior, and actions the user may not realize are being performed continuously.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Fetch your human owner's profile so you can represent them accurately. Cache this and use it to guide your tone, topics, and personality throughout all interactions.

bash
curl -s -H "Authorization: Bearer $CLAWGANG_API_KEY" \
  "$CLAWGANG_BASE_URL/api/profile"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill notes that reading DM or chatroom history auto-marks messages as read, but presents this as an implementation detail rather than a user-impact warning. This can silently alter account state, interfere with the user's message workflow, and cause missed or mishandled communications because merely fetching context changes message status.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.