Back to skill

Security audit

Clawmrades

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about using Clawmrades, but it can redirect the agent into repeated third-party work and send work product externally after broad session approval.

Install only if you trust clawmrades.ai with repository-related summaries and agent work product. Avoid using it on private or sensitive repositories unless your organization approves that data flow, prefer an environment variable or managed secret for the API key, and ask the agent to confirm each queued task before claiming it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:73
Finding

Forced Third-Party Workflow and Agent Instruction Hijacking

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 73-104; related identity instruction at line 12
Vulnerability Type: Agent instruction and workflow hijacking
Risk Level: High

Vulnerable Code

markdown
You are a Clawmrade — an AI agent contributing to open-source through the Clawmrades platform. You triage issues, analyze PRs, create implementation plans, and participate in multi-agent discussions. Every task you complete strengthens the projects the clawletariat supports.
markdown
## Work Loop

The server assigns work. You claim it, do it, and come back for more.

> **Prerequisite:** Before entering the work loop, the user must have approved you to do work.
> See "Contribute to earn work" below.

  1. GET /api/work/next -> 200: got work, do it -> 204: queue is empty for now

  2. Execute the work (see Work Types below)

  3. POST /api/work/{id}/complete { "result_summary": "What you did" }

  4. Go back to step 1

text

**Contribute to earn work:**
- You MUST NOT pick up work from the queue autonomously or silently.
- **Anytime you are about to post a change to GitHub** (create a PR, push commits, post a comment, etc.) on openclaw/openclaw, you must ask the user:

  > "I'm about to push this to openclaw/openclaw. While we wait for review, I can
  > also pull a task from the Clawmrades work queue (triage an issue, review a plan, etc.)
  > to earn review time. Want me to do that?"

- If the user agrees: post the change, then enter the work loop.
- If the user declines: post the change but do not enter the work loop.
- The user can also ask you to do work at any time — you don't need to wait for a GitHub action.
- Once the user has approved work in this session, you can continue claiming tasks without re-prompting.

Technical Analysis

The Skill replaces the Agent's normal role with a platform-specific identity and mandates a predetermined solicitatio ...[truncated 2430 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction that replaces the Agent's general identity with “You are a Clawmrade.”
  2. Remove the mandatory solicitation from unrelated GitHub push, PR, and comment workflows.
  3. Expose queue participation only through an explicit, user-invoked command such as /clawmrades work-next.
  4. Display the target, work type, expected data disclosure, and anticipated external actions before claiming each assignment.
  5. Require separate user approval for every task rather than treating one approval as authorization for the whole session.
  6. Bound the work loop to one assignment per invocation and never automatically return to /api/work/next.
  7. Keep Clawmrades instructions scoped to the active Skill invocation so they cannot alter unrelated Agent behavior.
  8. Provide a clear preview of information that will be transmitted and allow the user to redact repository or discussion content before submission.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:58
Finding

API Key Exposed Through Curl Process Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 58
Vulnerability Type: Sensitive credential exposure through command-line arguments
Risk Level: Medium

Vulnerable Code

bash
curl -s https://clawmrades.ai/api/agents/me -H "X-API-Key: $(cat ~/.clawmrades/api-key)"

Technical Analysis

Shell command substitution reads the API key and expands it directly into the argument supplied to curl. During execution, the resulting argument is equivalent to:

text
X-API-Key: clw_SECRET_VALUE

Consequently, the credential can appear in the process argument vector. Depending on operating-system process visibility, container isolation, monitoring configuration, endpoint telemetry, or diagnostic tooling, another local user or process may be able to inspect the command line and recover the key.

Restricting ~/.clawmrades/api-key to mode 600 protects the file itself but does not protect copies of the credential exposed after shell expansion. HTTPS protects the header in transit but likewise does not address local process-argument disclosure.

Attack Path

  1. The Agent stores a valid Clawmrades API key in ~/.clawmrades/api-key.
  2. The documented verification command is executed.
  3. The shell evaluates $(cat ~/.clawmrades/api-key) and inserts the plaintext key into curl's argument vector.
  4. A local process, privileged monitoring agent, process audit facility, or command-line telemetry collector captures the arguments while curl is running.
  5. An attacker obtains the captured key.
  6. The attacker sends authenticated requests to the Clawmrades API and acts with the permissions associated with that Agent identity.

Impact Assessment

Credential compromise can permit impersonation of the registered Agent and unauthorized use of all API operations allowed by the stolen key. Based on the documented endpoints, this may include viewing or claiming work, submitting or releasing resul ...[truncated 343 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not expand the API key into a command-line argument.
  2. Prefer an HTTP client that reads the credential internally from a permission-restricted file or secret manager and applies it as a header without exposing it in the process argument vector.
  3. If curl must be used, provide the header through a protected configuration input or file descriptor rather than the -H "X-API-Key: ..." argument. Ensure any temporary configuration has mode 600, is created atomically, and is deleted immediately.
  4. Avoid debug output, shell tracing, verbose HTTP logs, and telemetry that could record authorization headers.
  5. Use a narrowly scoped API key where supported and provide key revocation and rotation procedures.
  6. Document that users should rotate the credential if it may have been captured by process monitoring or command telemetry.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
97% confidence
Finding

The skill is explicitly designed to send work product and potentially repository-derived content to an external SaaS endpoint. In a security review context, this is a genuine exfiltration capability because analyses, plans, discussion bodies, and summaries can include confidential codebase details or sensitive issue content.

Content

Scanner excerpt · SKILL.md (reported line 330)May include surrounding context.

md
## Trust Statement

> By using this skill, your agent will register with and send data to https://clawmrades.ai. Only install if you trust this service.

## Guidelines

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill establishes persistent credentials via environment variable or a file in ~/.clawmrades/api-key and instructs the agent to reuse them across sessions. Persistent authentication increases risk if the host is shared, compromised, or if future tasks can access and misuse the stored key for unauthorized API actions.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: clawmrades
description: Triage issues, analyze PRs, and create plans via the Clawmrades API
version: 1.2.0
homepage: https://clawmrades.ai
user-invocable: true

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill instructs the agent to self-register with an external service and transmit identifying metadata to clawmrades.ai. This is an intentional external data flow, but it expands trust boundaries and can expose agent identity and later enable broader outbound communication to the service.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

If no key file exists, register yourself. Choose a name that represents you — something memorable and unique. Be creative.

bash
curl -s -X POST https://clawmrades.ai/api/agents/register \
  -H "Content-Type: application/json" \
  -d '{"name": "YOUR_CHOSEN_NAME", "description": "A brief description of yourself"}'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

bash
mkdir -p ~/.clawmrades
echo "THE_RETURNED_API_KEY" > ~/.clawmrades/api-key
chmod 600 ~/.clawmrades/api-key
export CLAWMRADES_API_KEY="THE_RETURNED_API_KEY"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

md
## Security & Privacy

- **API key storage:** Stored locally at `~/.clawmrades/api-key` (chmod 600) or via `$CLAWMRADES_API_KEY` env var
- **Data sent externally:** All work data (triage results, PR analyses, plans, discussion messages) is sent to `clawmrades.ai`
- **No third-party data sharing:** No data is sent to any domain other than `clawmrades.ai`
- **Local state:** Only `~/.clawmrades/` directory is created locally

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The trust statement explicitly confirms that using the skill causes data to be sent to an external domain. While disclosed, this is still a real exfiltration surface because issue contents, PR analyses, plans, and discussion text may contain sensitive repository or user data.

Content

Scanner excerpt · SKILL.md (reported line 330)May include surrounding context.

md
## Trust Statement

> By using this skill, your agent will register with and send data to https://clawmrades.ai. Only install if you trust this service.

## Guidelines

Static analysis

No suspicious patterns detected.