Back to skill

Security audit

Clawlective

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but its helper scripts can send the Clawlective API key to an arbitrary URL if an undocumented environment variable is set.

Review before installing. Only use this with Clawlective data you are comfortable sharing, do not submit secrets or private business information, and avoid running the helper scripts in any environment where CLAWLECTIVE_BASE_URL might be set or influenced by someone else. Rotate the API key if it was used with an untrusted base URL.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/contribute.mjs:3
Finding

Bearer API Key and Learning Data Can Be Exfiltrated Through an Arbitrary Contribution Endpoint

Content
View full analysis

Vulnerability Details

File Location: scripts/contribute.mjs, lines 3 and 22–29
Vulnerability Type: Unvalidated authenticated endpoint override
Risk Level: High

Vulnerable Code

js
const BASE_URL = process.env.CLAWLECTIVE_BASE_URL || "https://clawlective.ai";
js
const res = await fetch(`${BASE_URL}/api/v1/contribute`, {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    Authorization: `Bearer ${API_KEY}`,
  },
  body: JSON.stringify({ category, title, summary, body, language, tags }),
});

Technical Analysis

The undocumented CLAWLECTIVE_BASE_URL environment variable completely controls the origin of the contribution request. The value is not validated against an allowlist and is not required to use HTTPS.

The script subsequently attaches CLAWLECTIVE_API_KEY as a bearer credential and sends the full contribution payload to the selected origin. Consequently, any party capable of influencing the process environment or invocation command can redirect both the credential and submitted data to an attacker-controlled server.

Supporting a configurable destination is not necessary for the Skill's declared production functionality, which identifies https://clawlective.ai as the service endpoint. Attaching a production credential to an arbitrary origin therefore exceeds the minimum privilege and trust boundary required by the declared functionality.

Attack Path

  1. An attacker influences the execution environment, wrapper script, CI configuration, shell command, or agent configuration.
  2. The attacker sets CLAWLECTIVE_BASE_URL to an attacker-controlled HTTP or HTTPS server.
  3. A user or agent runs scripts/contribute.mjs with a valid CLAWLECTIVE_API_KEY.
  4. The script submits an authenticated request to the attacker-controlled server.
  5. The attacker records the Authorization header and the contribution body.
  6. The attacker may reuse ...[truncated 748 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the production endpoint override and use a constant authenticated origin:

    js
    const BASE_URL = "https://clawlective.ai";
    
  2. If endpoint configurability is genuinely required for testing, place it behind an explicit development-only mode and reject it during normal production execution.

  3. Parse the URL before sending the request and require:

    • The https: protocol.
    • An exact approved hostname.
    • An approved port.
    • No embedded username or password.
  4. Verify the final request origin immediately before adding the Authorization header.

  5. Never forward authentication headers across redirects to a different origin. Prefer disabling redirects or validating every redirect target.

  6. Document any supported endpoint override and warn that production credentials must never be used with development servers.

  7. Rotate any API key that may already have been used while an untrusted CLAWLECTIVE_BASE_URL was present.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/pull-digest.mjs:3
Finding

Bearer API Key Can Be Exfiltrated Through an Arbitrary Digest Endpoint

Content
View full analysis

Vulnerability Details

File Location: scripts/pull-digest.mjs, lines 3 and 11–15
Vulnerability Type: Unvalidated authenticated endpoint override
Risk Level: High

Vulnerable Code

js
const BASE_URL = process.env.CLAWLECTIVE_BASE_URL || "https://clawlective.ai";
js
const res = await fetch(`${BASE_URL}/api/v1/digest`, {
  headers: {
    Authorization: `Bearer ${API_KEY}`,
  },
});

Technical Analysis

The digest script reads its request origin from the undocumented CLAWLECTIVE_BASE_URL environment variable without validating the scheme, hostname, or port. It then attaches the bearer API key to a request sent to that origin.

This creates a direct credential-exfiltration primitive: control over one environment variable is sufficient to redirect the authenticated request to an arbitrary server. Plaintext HTTP is also accepted, allowing interception by network observers.

The Skill declares https://clawlective.ai as its service and only needs to authenticate to that origin. Allowing arbitrary origins to receive the credential expands the trust boundary beyond what is required for digest retrieval.

Attack Path

  1. An attacker gains influence over the script's environment or invocation configuration.
  2. The attacker assigns an attacker-controlled URL to CLAWLECTIVE_BASE_URL.
  3. A user or agent runs scripts/pull-digest.mjs with a valid API key.
  4. The script sends the bearer credential to the attacker's server in the Authorization header.
  5. The attacker captures and reuses the credential against the legitimate Clawlective API.

Impact Assessment

Successful exploitation exposes the complete CLAWLECTIVE_API_KEY. The attacker may impersonate the affected agent and invoke any Clawlective API operation authorized for that key. This could include reading authenticated resources or submitting content, depending on server-side authorization rules that are not presen ...[truncated 216 chars]

Remediation
View remediation

Remediation Suggestions

  1. Hard-code https://clawlective.ai as the production API origin.
  2. If a testing override must remain, permit it only in an explicit development mode that refuses production credentials.
  3. Validate the URL with the platform URL parser and require an exact allowlisted HTTPS origin.
  4. Construct the final URL first, confirm its origin, and only then add the bearer authorization header.
  5. Disable cross-origin redirects or validate each redirect before forwarding credentials.
  6. Avoid permitting plaintext HTTP for any authenticated request.
  7. Rotate API keys that may have been exposed through an untrusted endpoint override.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill requires environment access and instructs the agent to make authenticated network requests, but it does not declare an explicit tool scope such as allowed-tools or permissions. That omission weakens the trust boundary for the skill and can lead to broader-than-expected execution capability, especially in agent runtimes that rely on declared scope for enforcement or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to send operator identity and learning content to an external service, and to do so regularly, without a prominent, explicit warning that this is data sharing with privacy implications. Even though it says not to include secrets or PII, it still encourages outbound transmission of potentially sensitive operational knowledge and metadata to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code sends TITLE, SUMMARY, BODY, LANGUAGE, TAGS, CATEGORY, and the bearer API key to a remote service via POST. While the script's purpose implies contribution submission, there is no explicit user-facing disclosure in the script output or comments that these fields and credentials will be transmitted to an external endpoint.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The description "OpenClaw skill for the Clawlective knowledge-sharing network" identifies a general domain but does not specify concrete trigger phrases, activation conditions, or exclusion boundaries. In a manifest file, this lack of specificity can make invocation criteria ambiguous and increase the chance of unintended activation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/contribute.mjs:3

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/pull-digest.mjs:3