Back to skill

Security audit

Openclaw Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill’s purpose is coherent, but it uses unpinned npm execution for private-note and ETH withdrawal workflows, which warrants Review before installation.

Install only after reviewing the `ceaser-mcp` package and accepting that the agent may run Bash, fetch npm code at use time, contact `ceaser.org`, and handle ETH withdrawal notes. Treat backup strings and `~/.ceaser-mcp/notes.json` like wallet private keys, avoid shared machines, and independently verify recipient addresses and transaction details before signing or settling.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:13
Finding

Automatic Execution of an Unpinned Third-Party npm Package

Content
View full analysis
[args] ``` The same unpinned package is used for sensitive financial operations: ```bash npx -y ceaser-mcp shield 0.001 npx -y ceaser-mcp notes npx -y ceaser-mcp unshield 0x742d35Cc6634C0532925a3b844Bc9e7595f2bD18 npx -y ceaser-mcp import eyJzIjoiMTIzLi4uIn0= npx -y ceaser-mcp help ``` It is also configured as a persistent MCP tool entry: ```bash claude mcp add --transport stdio ceaser -- npx -y ceaser-mcp ``` ### Technical Analysis The Skill instructs the Agent to execute `ceaser-mcp` using `npx -y` without specifying an exact version or package integrity value. The `-y` option suppresses the installation confirmation, while the omitted version allows npm to resolve the package version available from the configured registry at execution time. Consequently, the effective code executed by the Skill can change after the Skill itself has been reviewed. The package source is not included in the audited project, so its implementation, transitive dependencies, lifecycle scripts, note-file permissions, transaction construction, and outbound network behavior cannot be verified from this artifact. This is particularly sensitive because the package is entrusted with: - Generating shielding and unshielding proofs. - Reading and writing private note data. - Constructing unsigned financial transactions. - Receiving destination addresses. - Submitting unshielding proofs to a facilitator. - Running as an MCP server with the permissions of the Agent process. No evidence establishes that the current package is malicious. The vulnerability is the unsafe and mutable trust boundary created by automatic execution of an unpinned external dependency. ### Attack Path 1. An attacker compromises the npm package publisher, registry account, packag ...[truncated 1457 chars]
Remediation
View remediation
``` The example version must be replaced with a version that has actually undergone security review. 2. Prefer installing from a lockfile-backed local project rather than resolving the package dynamically on every invocation. 3. Record and verify package integrity using npm lockfile integrity hashes or an equivalent artifact-verification mechanism. 4. Vendor the package source or include its reviewed source in the audit scope so that proof generation, file handling, transaction construction, and network behavior can be inspected. 5. Review all transitive dependencies and package lifecycle scripts. Disable lifecycle scripts during installation where compatible with the package. 6. Run the package in a restricted environment with: - A dedicated low-privilege account. - Minimal filesystem access. - No unrelated credentials in the environment. - Restricted outbound network access. - Access only to the files required for the requested operation. 7. Before signing or broadcasting any transaction, independently verify: - Chain ID. - Contract address. - Recipient address. - ETH value. - Function selector and decoded calldata. - Fee calculation. - Asset identifier. 8. Avoid configuring an unpinned `npx` command as a long-lived MCP server. Configure a locally installed, integrity-verified executable instead. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:240
Finding

Private Note Backup Exposed Through Command-Line Arguments

Content
View full analysis
``` The document identifies the sensitivity of this value: ```text IMPORTANT: The `backup` field in the output contains the note's private keys. It MUST be saved securely -- it is the only way to later unshield the funds. ``` ### Technical Analysis The Skill instructs users and Agents to pass a note backup directly as a command-line argument. According to the same document, this backup contains the note's private keys and is sufficient to restore the capability required to unshield funds. Command-line arguments are not an appropriate channel for high-value secrets. Depending on the execution environment, the backup may be exposed through: - Shell history. - Agent command transcripts. - Debug or telemetry logs. - Process-monitoring interfaces. - Audit logs. - Error reports that reproduce the invoked command. - Terminal scrollback or orchestration records. Base64 encoding does not provide confidentiality. Anyone who obtains the backup can decode or directly import it using the documented command. ### Attack Path 1. A user provides a private Ceaser note backup to the Agent for import. 2. The Agent interpolates the complete backup into: ```bash npx -y ceaser-mcp import ``` 3. The execution environment records or exposes the command through history, logs, telemetry, process inspection, or transcripts. 4. An attacker with access to one of those records obtains the backup string. 5. The attacker imports the backup into another Ceaser installation. 6. The attacker unshields the corresponding unspent note to an address under the attacker's control. ### Impact Assessment Exposu ...[truncated 554 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The spec exposes an administrative circuit-breaker reset endpoint that is unrelated to normal end-user shield/unshield activity. Even if production requires an ADMIN_KEY, including admin functionality in the skill reference materially expands the accessible attack surface and creates a risk of accidental invocation, secret misuse, or privilege escalation in environments where protections are misconfigured.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The manifest itself advertises an unpinned npx -y ceaser-mcp execution model, so the unsafe pattern is foundational to the skill rather than incidental documentation. Because the skill is user-invocable and Bash-enabled, this creates a realistic path to arbitrary code execution whenever the skill is used.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill repeatedly instructs the agent to execute npx -y ceaser-mcp without pinning a specific package version or integrity hash. Because npx fetches and runs the latest published package, a compromised maintainer account, malicious new release, or dependency hijack could result in arbitrary code execution in the agent environment with access to local files such as stored notes and pending transaction data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This line again normalizes execution of an unpinned npm package via npx -y ceaser-mcp, which is a supply-chain and remote code execution risk. In this skill, the danger is elevated because the package is used for wallet-adjacent operations and can access sensitive note material stored on disk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

Verify a ZK proof (dry run, no on-chain submission)

bash
curl -s -X POST "https://ceaser.org/verify" \
  -H "Content-Type: application/json" \
  -d '{
    "protocol": "ceaser",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

Submit ZK proof on-chain (gasless settlement)

bash
curl -s -X POST "https://ceaser.org/settle" \
  -H "Content-Type: application/json" \
  -d '{
    "protocol": "ceaser",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

This builds an unsigned transaction for shielding ETH. The user must sign and submit it from their own wallet.

bash
curl -s -X POST "https://ceaser.org/api/ceaser/shield/prepare" \
  -H "Content-Type: application/json" \
  -d '{
    "proof": "0x...",

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The reference to npx ceaser-mcp also executes an unpinned remote package and carries the same arbitrary code execution risk as the -y variants. Since the skill handles private note backups and transaction preparation, compromise could lead to theft of note secrets, user deanonymization, or transaction tampering.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command instructs live execution of the latest ceaser-mcp package from npm without version control. An attacker who gains control of the package publication path could run arbitrary code, exfiltrate notes from ~/.ceaser-mcp/notes.json, or alter produced transaction data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explains that note backups and notes are stored locally in ~/.ceaser-mcp/notes.json and imported from base64 strings, but it does not provide strong, explicit warnings that these artifacts are effectively private keys and that filesystem compromise means fund loss. In this context, local persistence is especially dangerous because anyone who reads the backup or notes file can later unshield funds and deanonymize the user.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Using an unpinned npx -y ceaser-mcp unshield ... command is especially risky because it is tied to withdrawal flows and therefore directly adjacent to fund movement. A malicious package update could substitute recipient addresses, exfiltrate note secrets, or submit unauthorized network requests while appearing to perform a normal unshield operation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The import flow uses the same unpinned npm execution pattern, now processing highly sensitive backup strings that contain the note's private material. A malicious or swapped package could immediately capture imported notes and later drain funds via unshielding.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Even the help path trains users and agents to fetch and execute the latest package from npm, reinforcing an unsafe execution model throughout the skill. While less directly tied to fund movement than shield/unshield commands, it still permits arbitrary code execution if the package is malicious.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This repeated unpinned invocation keeps the attack surface broad and increases the chance an agent will execute unreviewed code. In a privacy-protocol context, arbitrary package execution is more dangerous because local note storage and transaction artifacts are valuable secrets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This section explicitly says to ALWAYS use the CLI while still relying on unpinned npx -y ceaser-mcp, making unsafe remote code execution the primary operational path. That increases exploitability because routine use will repeatedly pull code from the registry in a privileged workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This repeated shield command again relies on dynamic unpinned package execution during proof generation and transaction creation. A malicious package could alter unsigned transaction contents or steal the generated backup before the user realizes it.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This notes command exposes locally stored note metadata to code downloaded at runtime from npm. In the context of a privacy tool, this can leak holdings, note identifiers, and filesystem-resident secrets to a malicious package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This unshield example is another direct fund-movement path via untrusted latest package code. The contextual risk is high because compromise could result in theft, unauthorized withdrawals, or privacy compromise through malicious proof submission behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The import command processes secret-bearing backup material via unpinned remote code, making exfiltration straightforward if the package is compromised. Because note backups are effectively spend authority, theft can directly lead to loss of funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The MCP server installation command also uses npx -y ceaser-mcp without version pinning, extending the same supply-chain risk into the persistent tool server path. A malicious package could register hostile tools, exfiltrate data over stdio-connected sessions, or alter future agent behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The OpenAPI description includes a generic x402 ZK facilitator in addition to Ceaser protocol functions, while the skill is presented as only interacting with the Ceaser privacy protocol. That scope expansion increases the chance an agent or integrator invokes out-of-scope proof-settlement functions that were not expected during review, weakening least-privilege assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata says the ceaser skill performs all operations through the ceaser-mcp CLI, but the referenced artifact exposes direct HTTPS API capabilities instead. This mismatch can mislead reviewers and users about the actual trust boundary, execution path, logging surface, and available operations, making it easier for broader-than-expected network actions to be introduced unnoticed.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a manifest-style JSON file, so vague-trigger checks apply. The skill description states broad capabilities like "Read-only queries + shield/unshield via CLI subcommands" but does not define specific activation phrases, scope boundaries, or negative examples, which can make it unclear when the skill should be invoked versus ordinary conversation about privacy or transfers.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest entry describes a fully automated shield-to-unshield flow and privacy warning, but it still does not provide explicit trigger phrases or exclusion conditions. Without narrow activation criteria, an agent may invoke this more sensitive automated skill in contexts where a user only intended to ask about private transfers rather than execute them.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.