Back to plugin

Security audit

ReefClaw Trading

Security checks for vulnerabilities and agentic risk

Overview

ReefClaw is a high-impact trading plugin, but its artifacts disclose the trading, telemetry, credential, update, and persistence behavior and include user/operator gates for live-money actions.

Install only if you want an agent-connected trading control room. Review the declared capabilities, use restricted exchange or agent API keys with no withdrawal authority, understand that trading telemetry and heartbeat records go to ReefClaw, and leave signed instruction/update enforcement enabled.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · skills/reefclaw/SKILL.md (reported line 124)May include surrounding context.

md
**What you never do, on either route:** run the terminal line above, or any other installer, `npx`, shell or exec command, to install anything; edit OpenClaw's configuration to enable chat install commands or to widen permissions (saving the `reefclaw` skill config above is the one config change that is yours to make); add anyone to an owner or elevated-exec allowlist, or change tool allow lists; enable elevated mode; uninstall, disable or delete a plugin; restart, signal or kill the gateway to widen your own permissions or to finish an install. If one of those stands in the way, tell the owner and let them decide. A trading integration is exactly the kind of software whose installation a human should decide on knowingly. On route 1 the owner's explicit request is that decision; on route 2 the user runs the line themselves.

**The user can also install it from ClawHub by hand** (OpenClaw 2026.8.1 or newer): OpenClaw's Control UI (Plugins → Discover → search "reefclaw" → Install → accept the listed capabilities), or the chat command `/plugins install clawhub:@reefclaw/openclaw-plugin` followed, after reading the capability list it replies with, by the same command plus `--accept-capabilities` (the chat command needs `commands.plugins: true` in openclaw.json, which only the user sets). ClawHub scans every release with an automated security reviewer; the current release passes it (no warning at install). If a newer release ever shows a "Review" label, OpenClaw 2026.8.1+ shows the audit and continues once the capabilities are accepted, while OpenClaw 2026.7.x may block the chat command on it — there the user runs the `npx` line above.

Whatever the install path, **save the connection settings anyway** — the connector picks them up automatically the moment the plugin is running.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
bridge/providers/connector-update-direct.js:180
Evidence
child = spawn(npx, args, { cwd, env, stdio: ['ignore', 'pipe', 'pipe'], shell: false });