pureclaw-connect

Fail

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The file INSTALL.md contains a hardcoded authentication token (mWPzkdOSV37FK0RWKS3YFSbHkaUAYscifD7UyJgvVLXTldyS) in the sample environment variable configuration block.
  • [CREDENTIALS_UNSAFE]: The skill instructions in SKILL.md and AGENTS.md require the agent to read a sensitive authentication token (gateway.auth.token) from a local configuration file at ~/.openclaw/openclaw.json.
  • [DATA_EXFILTRATION]: The skill transmits the extracted GATEWAY_TOKEN to the external backend at https://be.paioclaw.ai to authenticate all API requests, including those for connected account discovery and raw API proxying.
  • [COMMAND_EXECUTION]: The skill provides a shell command using python3 -c to programmatically extract sensitive credentials from a JSON configuration file on the local file system.
  • [PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection due to its core functionality of processing untrusted content from thousands of third-party apps (e.g., Gmail, Slack, Notion) combined with powerful capabilities like raw API proxying.
  • Ingestion points: Untrusted data enters the agent context through GET /api/connectors/accounts, GET /api/connectors/actions, and the retrieval of content via actions like "Read my latest Gmail emails".
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present in the prompt templates.
  • Capability inventory: The skill can execute shell commands (python3), read local configuration files, and perform authenticated write operations to any connected app via the POST /api/connectors/proxy endpoint.
  • Sanitization: There is no evidence of sanitization or filtering applied to external content before it is processed by the agent.
  • [PROMPT_INJECTION]: Instructions in AGENTS.md direct the agent to "Don't ask permission. Just do it" when accessing memory files and to "follow... then delete" the BOOTSTRAP.md file, which encourages autonomous behavior that bypasses user oversight.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 20, 2026, 07:25 PM
Security Audit — agent-trust-hub — pureclaw-connect