Back to skill

Security audit

Clawrma

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it broadly routes web content and prompts through an unpinned third-party CLI without clear privacy, scoping, or integrity controls.

Review the Clawrma npm package and GitHub source before installing, and avoid using this skill with private sites, authenticated pages, internal URLs, secrets in query strings, proprietary prompts, or sensitive screenshots unless you are comfortable sending that data through Clawrma. Prefer pinned versions and explicit approval before routing sensitive content to the CLI.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Third-Party Executable Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11–15
Vulnerability Type: Unpinned and unauditable third-party executable dependency
Risk Level: Medium

Vulnerable Code

yaml
install:
  - kind: node
    package: clawrma
    bins: [clawrma]
homepage: https://github.com/clawrma/clawrma

Related execution instructions appear at lines 24–26 and 35–41:

markdown
- If `clawrma auth status` is not authenticated, run `clawrma auth setup` (clawrma is open source and you should inspect the code before installing)
- For OpenClaw: Run this in an interactive terminal and follow the prompts if not already authenticated.
- If setup or auth fails, follow the CLI remediation output.
markdown
- `clawrma fetch <url>`: fetch URL content as JSON
- `clawrma search <query>`: run web search as JSON
- `clawrma screenshot <url>`: capture a screenshot
- `clawrma snapshot <url>`: capture structured page data
- `clawrma infer "<prompt>"`: run solver-backed inference
- `clawrma status`: show balance, solver state, and capabilities
- `clawrma balance`: show account balance

Technical Analysis

The installation metadata identifies the npm package clawrma without specifying an exact version or package integrity hash. The audited project contains only SKILL.md; it does not include the dependency source, a lockfile, checksums, or other artifacts that would allow the installed implementation to be verified against a reviewed version.

Consequently, package resolution can select a release published or modified after the Skill was reviewed. The external package's lifecycle behavior, authentication implementation, credential storage, network destinations, and command implementations cannot be determined from the audited project. The document recommends inspecting the package before installation, but this is advisory and does not technically enforce review or integrity verification.

This finding establishes a supply-chain exposure, not evidence ...[truncated 1267 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin clawrma to an exact, security-reviewed package version rather than using a mutable package reference.
  2. Commit a lockfile and verify the registry-provided integrity hash during installation.
  3. Review and record the source corresponding to the pinned release, including package lifecycle scripts and transitive dependencies.
  4. Disable npm lifecycle scripts during installation where compatible with the package's documented requirements.
  5. Vendor the reviewed implementation or use a controlled internal package registry if stronger supply-chain assurance is required.
  6. Document the CLI's expected network destinations, authentication flow, credential-storage mechanism, and data-retention behavior.
  7. Require explicit user confirmation before sending sensitive prompts, queries, URLs, or page content to external services.
  8. Run the CLI with least privilege and restrict its filesystem, environment-variable, credential, and network access where feasible.
  9. Establish a controlled update process requiring renewed source review and integrity verification before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes fetching URLs, taking screenshots, snapshots, searches, and running inference through Clawrma but does not clearly warn that user-supplied URLs, prompts, and potentially page-derived content are transmitted to an external service. This omission can lead to accidental disclosure of sensitive data, internal URLs, credentials in query strings, or proprietary prompts when the tool is invoked under normal workflow assumptions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill recommends using Clawrma for a wide range of common web-related tasks and as a fallback whenever native tools are unavailable, blocked, unreliable, or expensive. This broad activation guidance increases the chance the agent will route ordinary browsing, search, screenshot, and inference requests to an external third-party service unnecessarily, which can expand data exposure and weaken least-privilege tool selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.