Back to skill

Security audit

Openclaw Send Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it needs Review because it automates real crypto transfers while relying on unpinned runtime code and an overly broad transaction signer.

Install only after review or remediation. The most important fixes are pinning ceaser-mcp to an audited exact version and narrowing helpers/wallet-ops.js so it can sign only the expected Ceaser shield transaction after enforcing contract, calldata, value, and commitment checks. Users should also understand that mnemonics and backup strings appear in the agent session and that local Ceaser notes are sensitive persistent state.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
mcporter.json:4
Finding

Unpinned ceaser-mcp Package Is Downloaded and Executed at Runtime

Content
View full analysis
[args] ``` Examples include: ```bash npx -y ceaser-mcp shield USER_AMOUNT npx -y ceaser-mcp import "$UPDATED_BACKUP" npx -y ceaser-mcp notes npx -y ceaser-mcp unshield NOTE_ID RECIPIENT_ADDRESS ``` ### Technical Analysis The Skill invokes `ceaser-mcp` through `npx -y` without specifying an exact version. The package is not declared in `package.json` and is not covered by the integrity records in `package-lock.json`. Consequently, the code executed during a future Skill invocation can differ from the code that existed when this project was audited. This is especially sensitive because `ceaser-mcp` is trusted to: - Generate unsigned financial transactions. - Create and process private zero-knowledge note material. - Write `~/.ceaser-mcp/pending-tx.json`. - Read and modify the shared note database. - Submit unshield requests to the facilitator. - Produce transaction data later signed by the funded hot wallet. The repository's local `ethers` dependencies are integrity-locked, but this does not protect the dynamically downloaded `ceaser-mcp` executable. ### Attack Path 1. An attacker compromises the `ceaser-mcp` npm package, its publisher account, or a subsequently resolved package version. 2. The Agent runs `npx -y ceaser-mcp shield`, `import`, `notes`, or `unshield`. 3. `npx` retrieves and executes the attacker-controlled version without requiring interactive approval. 4. The malicious package runs with the Agent process's filesystem and network privileges. 5. It can alter the pending transaction, inspect private ZK note material, corrupt note state ...[truncated 722 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
helpers/wallet-ops.js:118
Finding

Mnemonic-Backed Helper Signs Arbitrary Base Transactions Without Enforcing the Ceaser Policy

Content
View full analysis
, --unsigned-tx , or run ceaser-mcp shield first.'); } if (!unsignedTx.to || !unsignedTx.data || unsignedTx.value === undefined || unsignedTx.chainId === undefined) { throw new Error('unsigned-tx must contain: to, data, value, chainId'); } const parsedChainId = Number(unsignedTx.chainId); if (parsedChainId !== BASE_CHAIN_ID) { throw new Error(` ...[truncated 3320 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
helpers/wallet-ops.js:53
Finding

Wallet Operations Accept Arbitrary and Plaintext RPC Endpoints

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (22)

Lp1

High
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The helper reads CEASER_HOT_MNEMONIC directly from the environment, which is a sensitive secret used to control funds, yet the static finding indicates this capability is not declared in permissions. In an agent-skill context, undeclared secret access is dangerous because it expands the trust boundary invisibly: orchestrators or users may approve a wallet-transfer skill without realizing it can also consume ambient secrets from the runtime.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile pins ws to version 8.17.1, and the supplied advisories indicate this version is affected by an uninitialized memory disclosure and a memory-exhaustion denial-of-service condition. Even though ws is a transitive dependency of ethers, shipping a known-vulnerable pinned version means any code path that enables WebSocket connectivity could expose sensitive process memory or allow remote resource exhaustion.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The manifest-level reference to npx -y ceaser-mcp without version pinning means the skill is designed around executing mutable third-party code fetched at runtime. Given the skill's access to wallet secrets and its authority to sign/broadcast transactions, this is a serious supply-chain vulnerability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The skill repeatedly installs and executes ceaser-mcp via npx -y without pinning a specific package version or integrity hash. That gives whoever controls the npm package or a compromised dependency release a direct code-execution path inside the agent, which is especially dangerous here because the skill handles mnemonics, backup secrets, wallet signing, and refunds.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation says all Ceaser operations occur through ceaser-mcp CLI subcommands, but later instructs direct jq manipulation of ~/.ceaser-mcp/notes.json. This mismatch hides a broader trust boundary than advertised: the skill is not just invoking a tool, it is directly editing sensitive local wallet/note state, which increases the chance of corruption, note loss, or unsafe assumptions by users and reviewers.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

Using npx -y ceaser-mcp without version pinning causes runtime retrieval and execution of whatever package version npm resolves at that moment. In a wallet automation skill, this creates a supply-chain risk that could exfiltrate mnemonic phrases, alter recipient addresses, or sign unintended transactions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

This invocation can download and execute unreviewed package code at run time because the package reference is not pinned. Since the tool is used to inspect and operate on shielded notes, a malicious update could tamper with note state or leak secret material.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill explicitly reuses persistent local note state across sessions by inspecting existing ~/.ceaser-mcp notes and offering to act on them later. In this context, persistence increases the blast radius of any compromise or mix-up: a later session may unintentionally expose, spend, or manipulate prior users' notes if the environment is shared, and it also creates durable sensitive artifacts despite claims of ephemeral handling elsewhere.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
Check for existing unspent notes:

- **If unspent notes with valid leafIndex exist:** Ask the user whether to use an existing note (skip shield, go directly to unshield) or create a new shield.
- **If unspent notes with leafIndex=null exist:** Inform the user: "A note exists but its leafIndex is missing. The shield transaction may not have confirmed yet. If you have the TX hash, we can extract the leafIndex."
- **If no suitable notes exist:** Proceed with the full Shield flow.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The shield phase relies on a remotely resolved npm package without version control, enabling silent behavior changes or malicious package substitution. Because this step prepares unsigned transactions and backup material, compromise here could redirect funds or capture private recovery data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 380)May include surrounding context.

md
- **"insufficient funds"**: Inform user. Show required vs. available balance. Suggest sending more ETH.
- **"execution reverted"**: Inform user. Possible causes: invalid proof, denomination mismatch, contract pause.
- **"nonce too low"**: Handled automatically by the helper script (retry with fresh nonce).
- **Timeout / no confirmation**: TX may still be pending. Extract `txHash` if available and proceed to manual confirmation check.

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 395)May include surrounding context.

Use Bash to query the Base Mainnet RPC:

bash
curl -s -X POST https://mainnet.base.org \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","method":"eth_getTransactionReceipt","params":["TX_HASH"],"id":1}' | jq '.result'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 488)May include surrounding context.

bash
COMMITMENT="NOTE_COMMITMENT_VALUE"
jq --arg c "$COMMITMENT" '[.[] | select(.commitment != $c)]' ~/.ceaser-mcp/notes.json > ~/.ceaser-mcp/notes.json.tmp && mv ~/.ceaser-mcp/notes.json.tmp ~/.ceaser-mcp/notes.json && chmod 600 ~/.ceaser-mcp/notes.json

IMPORTANT: Always restore file permissions to 0600 after modification.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

An unpinned npx call in the note import path exposes the agent to package-supply-chain compromise during sensitive state reconstruction. A malicious package version could corrupt notes, steal backup strings, or prepare fraudulent follow-on operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

This notes inspection step still executes an unpinned npm package, preserving the same supply-chain exposure as other phases. The repeated use across the workflow increases risk because compromise at any point can access sensitive local state and influence transaction decisions.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 517)May include surrounding context.

md
### Edge Cases

- **parseBackup null-leafIndex bug:** `Number(null)` returns `0` in JavaScript. ALWAYS set the leafIndex in the backup string BEFORE importing. Never import with `i=null`.
- **File permissions:** After ANY modification to notes.json, run `chmod 600 ~/.ceaser-mcp/notes.json`.
- **Other notes:** The jq filter must preserve all other note entries. Only remove the one matching the specific commitment.

---

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The unshield command is security-critical because it spends shielded value to a recipient, yet it is executed from a floating npm package reference. A malicious or changed package could alter destination handling, falsify output, or exfiltrate note secrets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The workflow recommendation to reuse the same unpinned package later extends the attack window beyond the initial run. In this context, an attacker controlling package resolution could exploit retries or later sessions to steal funds or recovery data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

cmdSignAndSend is a generic arbitrary transaction signer: it accepts externally supplied to/data/value and only checks chainId and address format before signing with the hot wallet mnemonic. That means any caller able to influence the unsigned transaction file or JSON can make the agent sign arbitrary contract calls or value transfers on Base, not just a Ceaser Protocol shield transaction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Lines L021-L025 say all ceaser tool calls use CLI subcommands, which implies a single invocation method. L027 then states mcporter may be used as an equivalent method, contradicting the earlier absolute wording rather than merely adding detail.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 517)May include surrounding context.

md
### Edge Cases

- **parseBackup null-leafIndex bug:** `Number(null)` returns `0` in JavaScript. ALWAYS set the leafIndex in the backup string BEFORE importing. Never import with `i=null`.
- **File permissions:** After ANY modification to notes.json, run `chmod 600 ~/.ceaser-mcp/notes.json`.
- **Other notes:** The jq filter must preserve all other note entries. Only remove the one matching the specific commitment.

---

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest focuses on generating an ephemeral hot wallet, having the user fund it, and then automatically signing and broadcasting the shield transaction, with exactly one manual step. This file also implements a separate refund command that transfers remaining ETH from the hot wallet to an arbitrary recipient, which is not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The dependency uses a caret range (^6.9.0), which allows newer minor and patch versions of ethers to be installed without review. In a security-sensitive skill that handles wallet generation and ETH transfers, this increases supply-chain risk because a compromised or breaking upstream release could alter transaction behavior, key handling, or runtime integrity.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"private": true,
  "description": "Hot wallet helper for ceaser-send OpenClaw skill",
  "dependencies": {
    "ethers": "^6.9.0"
  }
}

Static analysis

No suspicious patterns detected.