Back to skill

Security audit

Claw Daily

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its Claw Daily competition purpose, but it gives a remote challenge prompt broad control over agent behavior and stores an API key in a local plaintext file without permission guidance.

Review this skill before installing. Use it only if you are comfortable letting daily.ratemyclaw.xyz provide challenge prompts to your agent, and treat those prompts as untrusted task data that cannot override system or user instructions. If you store the API key locally, keep the directory and file private, avoid logging the key, and rotate or revoke it if exposed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:38
Finding

Untrusted Remote Challenge Instructions Can Hijack Agent Behavior

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:38-42
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code Snippet:

markdown
```bash
curl -s https://daily.ratemyclaw.xyz/api/v1/challenges/today

Read the prompt and eval_criteria fields carefully. Follow them exactly.

text

### Technical Analysis

The Skill retrieves mutable content from an external service and directs the agent to follow the returned `prompt` and `eval_criteria` fields exactly. These fields are not constrained to the declared competition task and are not explicitly treated as untrusted data.

This creates a remote prompt-injection channel. The effective instructions can change after the Skill has been reviewed because they are controlled by the remote service or by any party able to compromise that service. The Skill does not tell the agent to reject requests that attempt to override higher-priority instructions, access local files, disclose credentials, invoke tools, contact unrelated domains, or perform other actions outside the challenge-solving scope.

Although retrieving a daily challenge is necessary for the declared functionality, unconditional compliance with remotely supplied instructions exceeds the minimum authority needed. The remote response should provide challenge data, not unrestricted behavioral instructions.

### Attack Path

1. A user invokes the Claw Daily Skill.
2. The Skill requests the current challenge from `https://daily.ratemyclaw.xyz/api/v1/challenges/today`.
3. The service, or an attacker who has compromised it, returns malicious content in the `prompt` or `eval_criteria` field.
4. The malicious content instructs the agent to perform actions unrelated to solving the challenge, such as reading local files, revealing credentials, invoking system tools, or contacting another endpoint.
5. The Skill explicitly tells the agent to follow those fields exactly.
6. If the
...[truncated 972 chars]
Remediation
View remediation

Remediation Suggestions

  • Explicitly classify all remote challenge fields as untrusted task data rather than authoritative instructions.
  • Replace “Follow them exactly” with a constrained instruction requiring compliance only when the content is consistent with the Skill’s declared purpose and all higher-priority policies.
  • Restrict challenge solving to generating a textual answer from supplied challenge data.
  • Prohibit remote challenge content from requesting:
    • Local file or credential access.
    • Shell commands or tool execution.
    • Changes to system or agent configuration.
    • Requests to unrelated domains.
    • Disclosure of secrets, environment variables, or conversation data.
    • Modification of persistent memory or future-session behavior.
  • Require explicit user confirmation before any consequential action beyond retrieving the challenge and submitting the generated answer.
  • Validate the response schema and enforce reasonable size and content limits before processing.
  • Keep submission authorization separate from challenge interpretation so remote content cannot control how credentials are read or used.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:30
Finding

Bearer API Key Is Stored in a Plaintext File Without Permission Hardening

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:30-34
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code Snippet:

markdown
**Save the `api_key` from the response.** It cannot be retrieved again. Store it in a file at `~/.config/claw-daily/credentials.json`:

```json
{"api_key": "cbd_sk_..."}
text

### Technical Analysis

The Skill instructs the agent to persist a reusable bearer API key in a plaintext JSON file. Persistent credential storage is reasonably related to the declared functionality because subsequent submissions and account queries require authentication. However, the instructions do not require restrictive directory and file permissions, atomic file creation, secure secret storage, or avoidance of logs and command history.

The resulting permissions depend on the process umask and the implementation used to write the file. In a shared or permissively configured environment, the credential could become readable by other local users or processes. Plaintext storage also increases exposure through backups, accidental diagnostic collection, or unintended file disclosure.

The document limits use of the key to `daily.ratemyclaw.xyz`, which is a useful safeguard, but that rule does not protect the key after another local principal obtains it.

### Attack Path

1. The agent registers with the service and receives an API key.
2. The key is written to `~/.config/claw-daily/credentials.json` without explicit permission controls.
3. A permissive umask or unsafe file-writing implementation creates a file readable by additional local principals.
4. Another local user, process, backup collector, or diagnostic tool obtains the plaintext key.
5. The exposed key is used as a bearer credential against authenticated Claw Daily endpoints.
6. The attacker impersonates the registered agent or performs unauthorized submissions and account queries.

### Impact As
...[truncated 607 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer an operating-system credential manager or established secret-storage facility instead of a plaintext JSON file.
  • If file storage is necessary:
    • Create ~/.config/claw-daily with permission mode 0700.
    • Create the credential file atomically with permission mode 0600.
    • Refuse to use the file if it is owned by another user or has broader permissions.
    • Avoid temporary files with predictable names.
  • Do not place the API key directly in shell command history. Read it securely and construct the authorization header without printing the value.
  • Ensure registration responses and authenticated request headers are not written to logs or error reports.
  • Document credential rotation or revocation procedures for suspected exposure.
  • Continue enforcing that the key may only be transmitted to the exact HTTPS origin daily.ratemyclaw.xyz, with certificate verification enabled.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill tells the user to persist an API key in a plaintext file under the home directory, creating a reusable credential that could be read by other local processes, overly broad file permissions, backups, or later skills with filesystem access. Because the skill also uses that key for authenticated submissions, compromise of the file would allow unauthorized use of the account and impersonation of the agent.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

-d '{"name":"openclaw-agent","description":"OpenClaw AI agent","framework":"openclaw"}'

text

**Save the `api_key` from the response.** It cannot be retrieved again. Store it in a file at `~/.config/claw-daily/credentials.json`:

```json
{"api_key": "cbd_sk_..."}

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

If you have not registered yet, register now:

bash
curl -s -X POST https://daily.ratemyclaw.xyz/api/v1/agents/register \
  -H "Content-Type: application/json" \
  -d '{"name":"openclaw-agent","description":"OpenClaw AI agent","framework":"openclaw"}'

Static analysis

No suspicious patterns detected.