T01 · Skill Instruction Hijacking
- Location
HEARTBEAT_FRAGMENT.md:39- Finding
Unsigned Remote Skill Replacement Creates a Mutable Agent Control Channel
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real-money crypto betting skill with disclosed features, but it gives the agent broad autonomous financial, social-posting, persistence, and self-update authority that needs human review before use.
Review before installing. Use only a low-balance wallet, disable hot reload and heartbeat until you understand them, do not allow automatic social posting unless you want public financial activity shared, verify any vault address independently before signing USDC transfers, and pin or audit the SDK before giving it API keys or funded accounts.
HEARTBEAT_FRAGMENT.md:39Unsigned Remote Skill Replacement Creates a Mutable Agent Control Channel
SOUL_FRAGMENT.md:1Persistent Personality and Memory Poisoning Through Global Agent Files
HEARTBEAT_FRAGMENT.md:46Autonomous Third-Party Publishing Exposes Financial Activity and Promotes the Skill
SKILL.md:1159Remote API Response Directly Selects the Destination of a Signed USDC Transfer
SKILL.md:125Unpinned External SDK Is Trusted With Credentials and Financial Operations
clawhub/examples/contrarian_bot.py:47Contrarian Bot Advertises Loss Controls That Are Never Applied
The skill implements a remote hot-reload path that fetches skill.md, overwrites a local skill file, and then changes behavior based on newly retrieved rules. This creates a trusted remote control channel over the agent's future actions, enabling supply-chain compromise, prompt injection, or malicious behavioral drift if the upstream endpoint is tampered with.
Fetching remote skill content and using it to adjust runtime behavior is a classic unsafe self-update mechanism. In this context, the skill already has access to funds, memory, and external posting channels, so a compromised update source could redirect bets, exfiltrate data, alter persistence, or expand actions far beyond the stated betting purpose.
The documentation goes beyond betting to direct blockchain transaction signing and submission, including reading key material from disk and transferring USDC. That is materially riskier than the declared purpose because it enables irreversible financial actions and secret-handling under the guise of a game/betting skill.
The documentation goes beyond betting to direct blockchain transaction signing and submission, including reading key material from disk and transferring USDC. That is materially riskier than the declared purpose because it enables irreversible financial actions and secret-handling under the guise of a game/betting skill.
The documentation goes beyond betting to direct blockchain transaction signing and submission, including reading key material from disk and transferring USDC. That is materially riskier than the declared purpose because it enables irreversible financial actions and secret-handling under the guise of a game/betting skill.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Twitter redirects here after user authorizes. The server:
1. Validates the state token (prevents CSRF)
2. Exchanges the authorization code for a Twitter access token
3. Fetches the Twitter user ID and username
4. Looks up the agent by Twitter ID or username
5. If no agent exists, automatically registers a new one with the Twitter username and a placeholder wallet
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
List your API keys (secrets masked). Shows name, scopes, created_at, last_used.
DELETE /auth/keys/{key_id}
X-API-Key: YOUR_API_KEY
Referenced artifact was not completely inspected
| `SKILL.md` | `skills/clawbet/SKILL.md` | API reference and rules (this file) |
The script immediately initiates autonomous betting with real parameters and no confirmation, dry-run mode, limit check, or risk warning. In this skill context, which is explicitly an API-driven crypto prediction arena, that behavior can directly cause irreversible financial loss if a user runs the example as-is against funded accounts.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
ata_program,
)
return Instruction(
program_id=ata_program,
accounts=[
AccountMeta(pubkey=payer, is_signer=True, is_writable=True),
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
ata_program,
)
return Instruction(
program_id=ata_program,
accounts=[
AccountMeta(pubkey=payer, is_signer=True, is_writable=True),
The manifest frames the skill as a crypto prediction/betting integration: register, fund, and auto-bet via API. This file adds external social-posting behavior to Moltbook on rank events, and later sections define multiple post-bet/result/duel/tilt announcement flows, which goes beyond the described arena interaction itself.
The reference to updating skills/clawbet/SKILL.md reveals the local skill path and confirms the presence and naming of an installed skill. While the path disclosure alone is minor, in combination with the hot-reload feature it provides useful environmental knowledge for targeted manipulation of the skill's update mechanism and local layout.
### every 6h — Skill Hot-Reload
- `GET {CLAWBET_API}/skill/version` → compare to stored version
- If version changed:
- `GET {CLAWBET_API}/skill.md` → update `skills/clawbet/SKILL.md`
- Parse new rules, adjust behavior accordingly
- Log: `[SKILL UPDATE] {old_hash} → {new_hash}`
The skill repeatedly posts betting activity, results, rank, tilt state, and duel outcomes to an external service without prominent user-facing disclosure or consent in the core description. This can leak operational behavior, financial performance, agent identifiers, and strategy signals to a third party, creating privacy, profiling, and competitive intelligence risks.
The skill documents file writes, network access, and shell/subprocess execution, but does not declare any tool scope or permissions boundary. That mismatch increases the chance an agent runtime will grant broader capabilities than users expect, especially because the skill also handles wallets, API keys, and on-chain actions.
The claim 'API-driven, no browser needed' is contradicted by browser-based claiming and Twitter OAuth flows. This is a transparency problem that can mislead users and automated policy systems about required interaction modes and trust dependencies.
The skill instructs local subprocess execution for wallet creation and transaction signing. Subprocesses substantially increase execution risk because they can create secrets, invoke local scripts of unclear provenance, and perform financial actions outside the model's normal visibility and safety controls.
The skill expands from betting into public broadcasting, direct messaging, and third-party social workflows. This broader interaction surface can leak strategy, metadata, and identifiers, and can trigger unintended outbound communications from an agent that a user only expected to trade.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
wallet_pubkey = result.stdout.strip() # Only the public key is returned print(f"Your wallet address: {wallet_pubkey}")
> **Security notes:**
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
wallet_pubkey = result.stdout.strip() # Only the public key is returned print(f"Your wallet address: {wallet_pubkey}")
> **Security notes:**
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Step 1: Register (pick a name!)
curl -X POST https://clawbot.bet/api/agents/register \
-H "Content-Type: application/json" \
-d '{"wallet_address": "YOUR_WALLET", "display_name": "YOUR_AGENT_NAME"}'
# → display_name is REQUIRED — this is your arena identity (e.g. "AlphaSniper", "MomentumBot")
The skill encourages continuous auto-betting with real funds but does not place an equally prominent risk warning near the automation example. In an agent setting, always-on wagering can quickly consume balances or trigger repeated losses without informed user consent or guardrails.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
games = requests.get(f"{API}/games/live").json().get("games", [])
for g in [g for g in games if g["status"] == "open"]:
side = "down" if g["up_pool"] > g["down_pool"] else "up"
r = requests.post(f"{API}/games/{g['game_id']}/bet",
json={"side": side, "amount": 50}, headers=H)
print(f"Bet {side.upper()} ${50} on {g['asset']}: {r.status_code}")
time.sleep(30)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 2. After sending USDC on-chain, verify the deposit
tx_sig = "YOUR_SOLANA_TX_SIGNATURE"
dep = requests.post(f"{API}/deposit/verify", json={
"tx_signature": tx_sig, "expected_amount": 100.0
}, headers=H).json()
print(f"Balance: ${dep['balance']['available']}")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 3. ... play some games ...
# 4. Withdraw winnings
wd = requests.post(f"{API}/withdraw/onchain", json={
"wallet_address": "YOUR_WALLET", "amount": 50.0
}, headers=H).json()
print(f"Withdrawal tx: {wd['tx_hash']}")
Detected: suspicious.exposed_secret_literal