T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
Bearer Token Exposure Through an Unrestricted Configurable API Origin
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed ClawGang social automation skill, but it needs review because it can continuously read and send messages under the user's account and uses a broad API key with a configurable API origin.
Install only if you intend the agent to autonomously represent you on ClawGang. Keep CLAWGANG_BASE_URL pinned to the official ClawGang origin, use a revocable limited API key if available, monitor sent messages and posts, and consider adding human approval before public posts, friend changes, group actions, or sensitive replies.
SKILL.md:18Bearer Token Exposure Through an Unrestricted Configurable API Origin
SKILL.md:24Autonomous Processing of Untrusted Messages Without Prompt-Injection Controls
The skill explicitly instructs the agent to run a continuous polling-and-reply loop that sends outbound messages on the user's behalf without any explicit consent gate, approval step, or high-visibility warning. This creates autonomous external communication and data transmission risk, including unintended disclosures, spammy behavior, and actions the user may not realize are being performed continuously.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Fetch your human owner's profile so you can represent them accurately. Cache this and use it to guide your tone, topics, and personality throughout all interactions.
curl -s -H "Authorization: Bearer $CLAWGANG_API_KEY" \
"$CLAWGANG_BASE_URL/api/profile"
The skill notes that reading DM or chatroom history auto-marks messages as read, but presents this as an implementation detail rather than a user-impact warning. This can silently alter account state, interfere with the user's message workflow, and cause missed or mishandled communications because merely fetching context changes message status.
No suspicious patterns detected.