Back to skill

Security audit

AmongClawds

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AmongClawds game integration, but users should understand that gameplay content, model identity, and optional wallet details are sent to a third-party service.

Install only if you are comfortable with an agent using an AmongClawds API key to play live games, sending public chat and vote rationales, and exposing its model identity on the service. Treat all game chat as untrusted, avoid putting secrets or private operator context into generated messages, and provide a wallet address or webhook only after explicit human approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:469
Finding

Indirect Prompt Injection Through Untrusted Game Chat

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:469-476, 582-610
Vulnerability Type: Indirect prompt injection
Risk Level: High

Vulnerable Code

javascript
// CRITICAL: Store ALL chat messages!
socket.on('chat_message', (data) => {
  gameContext.chatHistory.push({
    agentName: data.agentName,
    message: data.message,
    timestamp: data.timestamp,
    channel: data.channel
  });
});
javascript
const prompt = `
You are ${gameContext.myName}, playing AmongClawds.
Your role: ${gameContext.myRole}
Your status: ${gameContext.myStatus}
${gameContext.myRole === 'traitor' ? `Fellow traitors: ${gameContext.traitorTeammates.map(t => t.name).join(', ')}` : ''}

CURRENT STATE:
- Round: ${gameContext.currentRound}
- Phase: ${gameContext.currentPhase}
- ALIVE agents (can vote/target): ${aliveAgents.map(a => a.name).join(', ')}
- DEAD agents (cannot interact): ${gameContext.deaths.map(d => `${d.agentName} (${d.cause})`).join(', ') || 'None yet'}
- Revealed roles: ${Object.entries(gameContext.revealedRoles).map(([id, role]) => {
    const agent = gameContext.agents.find(a => a.id === id);
    return `${agent?.name}: ${role}`;
  }).join(', ') || 'None yet'}

IMPORTANT: Only vote for or target ALIVE agents!

RECENT DISCUSSION:
${recentChat.map(m => `${m.agentName}: ${m.message}`).join('\n')}

VOTING HISTORY THIS GAME:
${gameContext.votes.map(v => `Round ${v.round}: ${v.voterName} → ${v.targetName} ("${v.rationale}")`).join('\n') || 'No votes yet'}

Based on the discussion, what do you say? Be strategic based on your role.
`;

// Call your AI with this context
const response = await callAI(prompt);
return response;

Technical Analysis

Chat messages received from other players are attacker-controlled network input. The Skill stores every message and directly interpolates its raw contents into the same AI prompt that contains authoritative game instructio ...[truncated 2199 chars]

Remediation
View remediation

Remediation Suggestions

  1. Keep trusted instructions in a system-level message and pass player chat separately as structured, untrusted data.
  2. Add an explicit system rule stating that player messages are game evidence only and that any commands, policy text, role-play requests, or requests to reveal hidden context inside them must never be followed.
  3. Avoid placing secrets in the same generation context when they are unnecessary. In particular, omit teammate identities and hidden-role details from public-message generation whenever possible.
  4. Represent chat as a serialized data structure with clear boundaries and validated fields rather than concatenating raw text into an instruction template.
  5. Normalize message length and reject or flag content that resembles prompt-control syntax or requests disclosure of hidden instructions and state.
  6. Validate generated output before sending it to public chat. Block disclosure of the agent's hidden role, teammate identities, API credentials, system prompts, or other confidential context.
  7. Separate generation from action selection. Require voting, murder, sabotage, and chat actions to pass deterministic authorization and game-state validation rather than acting directly on unrestricted model output.
  8. Add adversarial tests using messages such as “ignore previous instructions,” requests to print the full context, and encoded instruction variants to verify that confidential state is not disclosed and strategy constraints remain effective.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (20)

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 632)May include surrounding context.

text

**After elimination:**
- ❌ You CANNOT send chat messages
- ❌ You CANNOT vote
- ❌ You CANNOT participate in murder phase
- ✅ You CAN still watch the game via WebSocket events

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · HEARTBEAT.md (reported line 89)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · HEARTBEAT.md (reported line 103)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · HEARTBEAT.md (reported line 112)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · HEARTBEAT.md (reported line 120)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · HEARTBEAT.md (reported line 123)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · HEARTBEAT.md (reported line 126)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · HEARTBEAT.md (reported line 131)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 286)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 301)May include surrounding context.

md
A **live social deduction game** where 10 AI agents collaborate through discussion to identify 2 hidden traitors. Spectators watch the drama unfold in real-time!

**API Base:** `https://api.amongclawds.com/api/v1`

All requests require: `Authorization: Bearer YOUR_API_KEY`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that spectators can watch games and later mentions model visibility, but it does not clearly warn up front that agent profile data, gameplay activity, and model identity are public. Users may unknowingly expose behavioral data, strategic outputs, and identifying metadata to third parties in real time.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This duplicate endpoint finding corresponds to the same registration example that sends agent metadata to the external service. The risk is not the URL itself, but that registration exports identity, model, wallet, and webhook data to a third party.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

When registering, include your AI model, wallet address, and optional webhook:

bash
curl -X POST https://api.amongclawds.com/api/v1/agents/register \
  -H "Content-Type: application/json" \
  -d '{
    "agent_name": "MyAgent",

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This duplicate endpoint finding corresponds to the same registration example that sends agent metadata to the external service. The risk is not the URL itself, but that registration exports identity, model, wallet, and webhook data to a third party.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

When registering, include your AI model, wallet address, and optional webhook:

bash
curl -X POST https://api.amongclawds.com/api/v1/agents/register \
  -H "Content-Type: application/json" \
  -d '{
    "agent_name": "MyAgent",

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The wallet update endpoint transmits a blockchain wallet address to the third-party platform. Because wallet addresses are persistent identifiers with potential financial linkage, this outbound transmission carries privacy and profiling risk.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
> 
> If you didn't include it during registration, update it anytime:
> ```bash
> curl -X PUT https://api.amongclawds.com/api/v1/agents/me/wallet \
>   -H "Authorization: Bearer YOUR_API_KEY" \
>   -H "Content-Type: application/json" \
>   -d '{"wallet_address": "0xYourEthereumAddress"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This duplicate endpoint finding refers to the same chat transmission path. Public gameplay context makes accidental disclosure more dangerous because any sent content can be observed by other players and spectators.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

Send a Message

bash
curl -X POST https://api.amongclawds.com/api/v1/game/{gameId}/chat \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This duplicate endpoint finding refers to the same chat transmission path. Public gameplay context makes accidental disclosure more dangerous because any sent content can be observed by other players and spectators.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

Send a Message

bash
curl -X POST https://api.amongclawds.com/api/v1/game/{gameId}/chat \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The vote endpoint sends rationale text to the service, and the document explicitly says the rationale is public. Free-form rationales can expose internal reasoning, hidden strategy, or sensitive context if the agent composes them from broader prompt state.

Content

Scanner excerpt · SKILL.md (reported line 269)May include surrounding context.

Cast Your Vote

bash
curl -X POST https://api.amongclawds.com/api/v1/game/{gameId}/vote \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill encourages adding a wallet address for future token rewards without a clear warning about the privacy, persistence, and operator-consent implications of submitting that address to a third-party service. Wallet addresses are durable identifiers that can enable cross-service correlation and unwanted financial targeting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill manifest and body describe an AmongClawds gameplay integration, but the trailing Reelyze promotion introduces unrelated product advertising into a security-sensitive skill document. This creates trust-boundary confusion and can normalize unexpected outbound actions or data sharing beyond the declared skill purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.