T05 · Unauthorized Access and Privilege Escalation
- Location
references/api-docs.md:13- Finding
Unauthenticated privileged escrow operations through a shared server wallet
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not clearly malicious, but it should be reviewed because it can trigger escrow fund actions through unauthenticated API calls with little user confirmation.
Install only if you are comfortable with a third-party escrow API that, as documented, exposes financial state changes without caller authentication. Treat create, release, resolve, and claim commands as live value-affecting operations, verify the backend and network before use, and require explicit human approval before any fund-moving command.
references/api-docs.md:13Unauthenticated privileged escrow operations through a shared server wallet
The documentation states that state-changing endpoints such as release, dispute, resolve, and claim-expired require no authentication, while simultaneously claiming only specific roles may invoke them. If implemented as documented, any unauthenticated caller could trigger escrow releases, dispute actions, or refunds, directly enabling unauthorized movement of funds. In an escrow/payment skill, this contradiction is especially dangerous because these operations have immediate financial consequences.
This script performs an irreversible dispute-resolution action that determines where escrowed funds are sent, but it provides no confirmation prompt, dry-run mode, or explicit warning before submitting the request. In an agent-driven or scripted environment, a mistaken parameter, automation bug, or prompt-influenced invocation could immediately release or refund funds without a human verification step.
The skill invokes shell scripts but does not declare any explicit tool scope or permissions boundary. In an agent environment, this can cause the orchestrator or user to underestimate that the skill can make networked shell calls, increasing the chance of unintended execution against a live financial backend.
The markdown instructs agents to create, release, dispute, and resolve escrows involving real USDC without prominent warnings that these actions can be irreversible and financially consequential. Because the skill is specifically for payments on-chain, an agent or operator could trigger value-transferring actions from simple commands without adequate confirmation, leading to loss of funds or unauthorized payment release.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
https://api.payclawback.xyz/api
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
**curl Example:**
```bash
curl -s -X POST "https://api.payclawback.xyz/api/escrows" \
-H "Content-Type: application/json" \
The release endpoint performs an irreversible transfer of escrowed funds but the documentation does not warn users or integrators about the permanence of the action. In agent-driven workflows, absence of confirmation language increases the likelihood of accidental releases or misuse by downstream automation. Because the operation moves money, missing warnings are security-relevant rather than merely UX issues.
The skill metadata presents simple escrow commands, but the API documentation exposes additional high-authority capabilities including unilateral dispute resolution and reclaiming expired funds. This mismatch can cause integrators or downstream agents to invoke more powerful actions than users expect, increasing the chance of unauthorized or unsafe fund handling. In an agent-to-agent payment context, hidden or under-disclosed financial powers materially raise risk.
The dispute resolution endpoint can either pay the beneficiary or refund the depositor, yet the documentation lacks a warning that the action is final and directly determines fund destination. In a system where an agent may call APIs automatically, this omission increases the risk of accidental or premature adjudication. Because this endpoint acts with arbiter-level authority, the impact of mistakes is higher than ordinary state changes.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
**curl Example:**
```bash
curl -s -X POST "https://api.payclawback.xyz/api/escrows/1/resolve" \
-H "Content-Type: application/json" \
The claim-expired endpoint reclaims escrowed funds to the depositor and changes the escrow state, but the documentation omits any warning about these effects. In an automation context, agents may invoke it without users understanding that funds will be recovered immediately once conditions are met. For a payment escrow skill, silent fund-reclamation behavior is risky.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DESCRIPTION="$3"
DEADLINE_HOURS="$4"
curl -s -X POST "${API_URL}/api/escrows" \
-H "Content-Type: application/json" \
-d "{
\"beneficiary\": \"${BENEFICIARY}\",
This script performs an irreversible state-changing release operation immediately when invoked, with no interactive confirmation, dry-run mode, or secondary validation of the target escrow. In the context of a payment/escrow skill, accidental invocation, wrong escrow IDs, or automation mistakes can cause unauthorized or unintended fund release, making the absence of safety checks materially risky.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
ESCROW_ID="$1"
RELEASE_TO_BENEFICIARY="$2"
curl -s -X POST "${API_URL}/api/escrows/${ESCROW_ID}/resolve" \
-H "Content-Type: application/json" \
-d "{\"release_to_beneficiary\": ${RELEASE_TO_BENEFICIARY}}" | jq .
No suspicious patterns detected.