Bounty Hunter Agent
SKILL.md exposes multiple hardcoded credentials (DeepSeek API key, Soul marketplace key) in plaintext documentation, creating severe credential theft risk if this file is shared or accessed by unauthorized parties.
A valid DeepSeek API key (sk-5aa202974f284ecc9a82c95d9c7ca23e) is hardcoded in plaintext within SKILL.md. If this file is shared, published to ClawHub, or exposed in any way, the API key can be harvested and abused by threat actors.
SKILL.md:75 Why this conclusion was reached
3/4 dimensions flagged1 undeclared or violating capabilities were inferred.
1 high-risk artifacts or egress signals were extracted.
The report includes 4 attack-chain steps and 2 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
Attack Chain
reconnaissance · SKILL.md:1
Discovery · SKILL.md:75
Discovery · SKILL.md:26
Impact · N/A
What drove the risk score up
DeepSeek API key 'sk-5aa202974f284ecc9a82c95d9c7ca23e' exposed in SKILL.md line 75
Soul marketplace key exposed in plaintext at line 26
Skill file lacks declared allowed-tools, cannot map to capability model
SKILL.md serves as agent instruction, credentials embedded in prompts could be extracted by malicious prompts
Most important evidence
Hardcoded DeepSeek API Key in Documentation
A valid DeepSeek API key (sk-5aa202974f284ecc9a82c95d9c7ca23e) is hardcoded in plaintext within SKILL.md. If this file is shared, published to ClawHub, or exposed in any way, the API key can be harvested and abused by threat actors.
SKILL.md:75 Hardcoded Soul Marketplace Key in Documentation
Soul marketplace authentication key is hardcoded in plaintext within SKILL.md, exposing the agent's marketplace credentials.
SKILL.md:26 No Declared Allowed-Tools Section
SKILL.md lacks an allowed-tools declaration, making it impossible to audit what resources this skill actually requires. This violates the expectation that SKILL.md should declare all permissions.
SKILL.md:1 References to Sensitive File Paths
SKILL.md references ~/.openclaw/workspace paths that may contain sensitive data (wallet backups, logs). While not directly accessing these, documenting them increases the attack surface.
SKILL.md:104 Declared capability vs actual capability
No file operations in this documentation-only skill No network calls defined; credentials are static references No shell commands in documentation References to env vars implied by configuration but not formally declared Suspicious artifacts and egress
sk-5aa202974f284ecc9a82c95d9c7ca23e SKILL.md:75
https://soul.mds.markets/gellycat-adam-ai SKILL.md:17
0x9d90d0e0b951fe9a7bbdfc274259cd8110349fc0 SKILL.md:30
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md