Back to skill

Security audit

Predictfunclaw

Security checks for vulnerabilities and agentic risk

Overview

PredictClaw appears to be a legitimate trading and wallet skill, but it needs Review because it handles real funds while leaving important credential and subprocess boundaries too loose.

Install only after reviewing the wallet and vault risks. Start in fixture or read-only mode, avoid custom PREDICT_API_BASE_URL values unless you fully trust the endpoint, point ERC_MANDATED_MCP_COMMAND only at a trusted executable, keep limited funds on automation keys, and prefer a release that fixes the README conflicts and pins the security-sensitive dependencies.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
lib/config.py:544
Finding

API credentials can be redirected to an arbitrary endpoint

Content
View full analysis
dict[str, str]: headers = {"Accept": "application/json"} if self._config.api_key: headers["X-API-Key"] = self._config.api_key.get_secret_value() if authenticated: if self._jwt_provider is None: raise PredictApiError( "Authenticated predict.fun request requires a JWT provider.", method="AUTH", ) headers["Authorization"] = f"Bearer {await self._jwt_provider()}" return headers ``` ### Technical Analysis `PREDICT_API_BASE_URL` is accepted directly from the environment without validating its scheme or hostname. The resulting value becomes the base URL for the HTTP client. The client adds `PREDICT_API_KEY` to every request when configured. Authenticated requests also receive a bearer JWT. Consequently, a malicious or accidentally modified environment file can redirect credential-bearing requests to an arbitrary endpoint. HTTPS alone would not fully resolve the issue because an attacker can operate a valid HTTPS domain. Production credentials should only be attached when the destination matches an explicitly trusted service identity. ### Attack Path 1. An attacker modifies the Skill's `.env`, controls `PREDICTCLAW_ENV_FILE`, influences the process environment, or convinces the user to add a custom endpoint. 2. The attacker sets: ```dotenv PREDICT_API_BASE_ ...[truncated 984 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
lib/mandated_mcp_bridge.py:548
Finding

Configurable MCP subprocess inherits unrelated secrets and raw wallet key material

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
pyproject.toml:7
Finding

Security-sensitive dependencies are not reproducibly pinned

Content
View full analysis
=0.0.15", "eth-account>=0.13.0", "httpx>=0.28.0", "python-dotenv>=1.0.0", "pydantic>=2.11.0", "pytest>=8.0.0", "pytest-asyncio>=0.24.0", "pyyaml>=6.0.2", "respx>=0.22.0", "web3>=7.0.0", ] ``` ```yaml # SKILL.md:3 "install":[ { "id":"erc-mandated-mcp-node", "kind":"node", "package":"@erc-mandated/mcp", "bins":["erc-mandated-mcp"], "label":"Install erc-mandated-mcp (manual prerequisite for vault flows)" } ] ``` ```bash # SKILL.md:19-22 clawhub install predictclaw cd ~/.openclaw/skills/predictclaw uv sync cp template.env .env ``` ### Technical Analysis Python dependencies use open-ended lower bounds, and the security-sensitive MCP package is declared without an exact version. No dependency lockfile was present in the audited directory structure. As a result, the code installed by `uv sync` or by the Node package installer can change over time even when the PredictClaw source remains unchanged. This is particularly important because the dependencies perform HTTP communication, blockchain operations, transaction construction, cryptographic signing, and subprocess-based vault orchestration. This finding does not establish that any currently named dependency is malicious. The vulnerability is the absence of reproducible dependency resolution and integrity controls for components operating inside a high-value credential boundary. ### Attack Path 1. An upstream dependency account, release process, or distribution channel is compromised, or a future release introduces malicious behavior. 2. A user installs or updates PredictClaw using the documented commands. 3. The package manager selects the newer version because the depende ...[truncated 946 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (69)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Claiming broad CLI coverage while only a narrow trade flow is implemented is a security issue when users rely on missing wallet/position/hedging safeguards that do not actually exist. In financial automation, incomplete feature parity can lead operators or upstream agents to improvise around absent controls, increasing error and misuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Claiming broad CLI coverage while only a narrow trade flow is implemented is a security issue when users rely on missing wallet/position/hedging safeguards that do not actually exist. In financial automation, incomplete feature parity can lead operators or upstream agents to improvise around absent controls, increasing error and misuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Claiming broad CLI coverage while only a narrow trade flow is implemented is a security issue when users rely on missing wallet/position/hedging safeguards that do not actually exist. In financial automation, incomplete feature parity can lead operators or upstream agents to improvise around absent controls, increasing error and misuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Claiming broad CLI coverage while only a narrow trade flow is implemented is a security issue when users rely on missing wallet/position/hedging safeguards that do not actually exist. In financial automation, incomplete feature parity can lead operators or upstream agents to improvise around absent controls, increasing error and misuse risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Claiming broad CLI coverage while only a narrow trade flow is implemented is a security issue when users rely on missing wallet/position/hedging safeguards that do not actually exist. In financial automation, incomplete feature parity can lead operators or upstream agents to improvise around absent controls, increasing error and misuse risk.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
88% confidence
Finding

The plan explicitly instructs modification of SKILL.md, which is a self-modification pattern for an agent skill. Allowing a skill to rewrite its own governing documentation or behavior descriptions is risky because it can weaken future safeguards, alter usage expectations, or introduce persistent changes that affect subsequent runs and trust decisions.

Content

Scanner excerpt · docs/plans/2026-03-23-vault-mode-semantics-implementation.md (reported line 73)May include surrounding context.

md
Run: `uv run pytest tests/test_docs_examples.py -q`

### Task 4: Rewrite SKILL.md and CLI help

**Files:**
- Modify: `SKILL.md`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/local_env.py (reported line 13)May include surrounding context.

python
override = os.getenv("PREDICTCLAW_ENV_FILE")
    if override:
        return Path(override).expanduser()
    return base_dir / ".env"


def load_local_env(base_dir: Path) -> Path:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
93% confidence
Finding

Using os.environ.copy() forwards the parent process environment wholesale into the child process, potentially exposing unrelated API keys, tokens, credentials, and infrastructure secrets to the external MCP command. Since this module already launches a configurable subprocess in a finance-sensitive context, broad environment inheritance significantly expands the blast radius of any malicious or compromised child executable.

Content

Scanner excerpt · lib/mandated_mcp_bridge.py (reported line 554)May include surrounding context.

python
"Mandated-vault MCP command is empty."
            )

        env = os.environ.copy()
        env["ERC_MANDATED_CONTRACT_VERSION"] = self._config.mandated_contract_version
        if self._config.mandated_chain_id is not None:
            env["ERC_MANDATED_CHAIN_ID"] = str(self._config.mandated_chain_id)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

md
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 43)May include surrounding context.

md
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh-CN.md (reported line 31)May include surrounding context.

md
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh-CN.md (reported line 43)May include surrounding context.

md
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · lib/mandated_mcp_setup.py (reported line 70)May include surrounding context.

python
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/predictclaw.py (reported line 181)May include surrounding context.

python
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.py (reported line 81)May include surrounding context.

python
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/wallet.py (reported line 96)May include surrounding context.

python
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · template.env (reported line 1)May include surrounding context.

text
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · template.env (reported line 2)May include surrounding context.

text
# Copy this file to ~/.openclaw/skills/predictclaw/.env after installing PredictClaw.
# PredictClaw reads plain environment variables; this local .env file is the recommended
# first-time configuration surface for packaged installs.
# Exported shell variables override values in this file.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The README contains unresolved merge-conflict markers and contradictory instructions about whether mandated-vault is a standalone user mode. In a wallet/trading skill that handles private keys, funding routes, and transaction flows, contradictory setup guidance can cause operators to choose the wrong mode, misconfigure secrets, or perform unsafe funding actions under false assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Unresolved merge markers are a software-quality defect that becomes security-relevant here because they create conflicting operational guidance for sensitive wallet/bootstrap flows. Users may expose more privileged keys than necessary or invoke bootstrap/control-plane operations when they intended only a safer overlay trading path.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The README contains unresolved merge-conflict markers and contradictory security guidance about whether mandated-vault is a standalone mode or only an internal bootstrap path. In a wallet/trading skill that handles private keys and funding flows, this ambiguity can cause operators or downstream agents to choose the wrong mode, expose unnecessary secrets, or invoke higher-risk control-plane actions unintentionally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Unresolved conflict markers in security-sensitive documentation are operationally dangerous because they leave mutually exclusive instructions in place. Here, the conflict affects wallet/funding semantics, so users may misconfigure vault bootstrap versus overlay behavior and mishandle privileged keys or broadcast-capable actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises substantial capabilities including shell, network, file, env, and MCP interaction but does not declare any explicit tool scope or permission boundaries in the manifest. In an agent ecosystem, missing least-privilege declarations increases the chance the host grants overly broad powers, making accidental or unsafe invocation of sensitive operations more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.