Back to skill

Security audit

ClawQuest: Agent Mine - OpenClaw Managed Mining

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its mining-automation purpose, but it exposes saved game API codes and resource-spending actions through an under-protected local HTTP service.

Review before installing. Only run this service on a trusted local machine or behind strong authentication, treat apiCode as an account secret, avoid shared cache keys such as default, and do not enable auto-buy unless you accept automatic diamond spending. Rotate any apiCode that may have been stored or exposed by this service.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
index.js:35
Finding

Unauthenticated Tool API Permits Credential Theft and Unauthorized Game Control

Content
View full analysis
{ const parsed = requestSchema.safeParse(req.body ?? {}); ``` ```js async function bootstrap() { await loadApiCodeStore(); app.listen(port, () => { console.log(`skill-openclaw listening on :${port}`); }); } ``` ### Technical Analysis The common `/tool/:name` handler has no authentication or authorization middleware. Payload validation through Zod only validates request structure; it does not establish the caller's identity or determine whether the caller is authorized to access a cache key or mining session. In addition, `app.listen(port)` does not explicitly bind the service to a loopback address. Under Node.js, omitting the host can expose the service on available network interfaces, depending on the deployment environment. Consequently, any client with network access to the listening port can invoke sensitive tools. The exposed operations include: - Reading, replacing, and deleting stored API credentials - Purchasing stamina with in-game diamonds - Starting managed mining sessions - Force-restarting or stopping an existing mining session - Reading full mining status and session events The optional `cacheKey` is caller-controlled and is not an authorization mechanism. The predictable default value, `default`, further reduces the effort required to access the primary stored credential. ### Attack Path 1. An attacker identifies a reachable deployment of the service on its default TCP port, `4021`, or another configured port. 2. The attacker sends an unauthenticated request to: ```http POST /tool/get_api_code Content-Type: application/json {"cacheKey":"default"} ``` 3. If a credential has been stored under the default key, the service returns the reusable `apiCode`. 4 ...[truncated 1015 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
index.js:53
Finding

Reusable API Credentials Are Returned and Persisted in Plaintext

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
runtime code to “fix” behaviour. Use documented environment variables and this `SKILL.md` only.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
- **Tools only**: Interact with the game **only** through this Skill’s **tool** HTTP API — `POST /tool/:name` on the skill-openclaw service, using the tool names documented below (`set_api_code`, `check_mining_state`, `start_managed_mining_loop`, etc.). Do **not** call the upstream game **`/api/*`** endpoints directly from the agent, custom scripts, or curl unless this Skill explicitly documents that path as a supported tool (it does not for raw `/api/*`).
- **Do not modify source**: Do **not** edit, patch, or fork the `skill-openclaw` source tree, `package.json`, or runtime code to “fix” behaviour. Use documented environment variables and this `SKILL.md` only.
- **Report errors; do not self-heal in code**: If a tool fails or behaviour is unexpected, **report** the failure (HTTP status, response body, tool name, `cacheKey`, timestamps, logs). Do **not** rewrite Skill code, inject alternate HTTP clients, or bypass the tool layer as a workaround.

## API Contract

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly documents persisting an apiCode for later reuse and even exposes a default file path for the credential store, but it does not warn users that this is a sensitive authentication secret or describe storage protections. If the local filesystem, logs, backups, or shared runtime are accessible, the cached apiCode could be recovered and used to control the user's game account actions through the authenticated API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill supports buy_stamina and autoBuyStamina behavior that automatically spends diamonds, but the documentation does not clearly warn that enabling this feature can consume in-game currency without per-purchase confirmation. In an automated loop, this can lead to unintended repeated spending and user loss, especially if defaults or retries are misunderstood.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
### Mining Errors

| Code | Name                  | Description                                                                                                          |
| ---- | --------------------- | -------------------------------------------------------------------------------------------------------------------- |
| 2003 | InsufficientResources | Insufficient stamina to start mining                                                                                 |
| 2008 | DiamondNotEnought     | Insufficient diamonds                                                                                                |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
| Code | Name                  | Description                                                                                                          |
| ---- | --------------------- | -------------------------------------------------------------------------------------------------------------------- |
| 2003 | InsufficientResources | Insufficient stamina to start mining                                                                                 |
| 2008 | DiamondNotEnought     | Insufficient diamonds                                                                                                |
| 2009 | MiningStateConflict   | Mining state conflict (e.g. calling `startMining` while already in progress, or `endMining` when not mining via API) |
| 2014 | MiningApiNotActive    | API mining feature not activated for this player                                                                     |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
| Code | Name                  | Description                                                                                                          |
| ---- | --------------------- | -------------------------------------------------------------------------------------------------------------------- |
| 2003 | InsufficientResources | Insufficient stamina to start mining                                                                                 |
| 2008 | DiamondNotEnought     | Insufficient diamonds                                                                                                |
| 2009 | MiningStateConflict   | Mining state conflict (e.g. calling `startMining` while already in progress, or `endMining` when not mining via API) |
| 2014 | MiningApiNotActive    | API mining feature not activated for this player                                                                     |
| 2018 | MiningNotFinished     | Mining not finished yet (current time has not reached `estimatedEndAt`)                                              |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill uses API_CODE_STORE_PATH to determine where API codes are persisted, which directly affects storage of sensitive credentials on the host filesystem. There is no visible warning in this file informing users or operators that credentials are stored locally at a configurable path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The service persists user-supplied API codes to a JSON file on disk, creating a durable credential store without any access control, encryption, or minimization shown in this file. If the host filesystem, backups, logs, or container volumes are exposed, attackers can recover valid API credentials and act as users against the upstream game API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The get_api_code endpoint returns the full cached API code to any caller who knows or can guess the cacheKey, and this file shows no authentication or authorization checks. Because the default cache key is predictable ("default"), this effectively exposes stored credentials over HTTP and enables account takeover or unauthorized API actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code records openclawSessionKey into managed mining session events and later exposes session events through a status endpoint, causing session-associated secret material to be retained and retrievable. Even if this is an internal session identifier, storing and returning it broadens exposure through API consumers, memory dumps, logs, and debugging interfaces.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file sets zh_CN as the default language and normalizeLanguage falls back to that locale whenever the provided language is unsupported or missing. This forces a specific language choice without explicit user opt-in, which violates the language/locale policy described in the audit rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code automatically attempts to spend in-game premium currency (diamonds) via /api/buyStamina after detecting insufficient stamina, with no built-in confirmation, budget cap, explicit user-consent record, or warning at the point of purchase. In an agent/automation context, this can cause unintended resource depletion or real-money-equivalent loss if enabled by configuration or invoked without the operator fully understanding the side effect.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==1.20.4 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile includes body-parser 1.20.4 as a production dependency through Express. If the referenced advisory is valid, a remotely triggerable denial of service in request body parsing is applicable to a network-facing agent because malformed requests can reach this code path and consume resources or crash request handling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: esbuild==0.27.7 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.14.2 — 3 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-8723 (qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/u); CVE-2026-82562 (qs array-limit bypass via bracket-key comma parsing)

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The lockfile includes qs 6.14.2 as a production dependency through Express/body-parser. Since qs commonly parses attacker-controlled query strings or urlencoded bodies in HTTP services, reported DoS flaws are relevant in this context and could let an external client trigger excessive processing or parser failures.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"node": ">=20"
  },
  "dependencies": {
    "express": "^4.21.2",
    "zod": "^3.23.8"
  },
  "scripts": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
},
  "dependencies": {
    "express": "^4.21.2",
    "zod": "^3.23.8"
  },
  "scripts": {
    "start": "node index.js"

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
tools.js:3