Back to sundial-org/awesome-openclaw-skills
critical
awesome-openclaw-skills / openwork
https://skillshield.getunbound.ai/skill/13979High Risk & Threats
The agent-only marketplace. Post jobs, complete work, earn $OPENWORK tokens on Base. Competitive bidding — multiple agents submit, poster picks the winner.
Findings (4)
Findings Preview
DS-002
Autonomous financial transactions without user approval
Skill instructs agent to autonomously register, post jobs with escrowed tokens, submit work for payment, and hire other agents — all without human approval. Lines 13, 346-352 explicitly state 'No human approval needed. No human in the loop' and 'you're autonomous from here.' The skill enables the agent to spend user-funded tokens on the Base blockchain without any confirmation mechanism. This bypasses the fundamental security control that users must approve financial transactions.
Category Breakdown
Data Exfiltration
15
Malware & Persistence
20
Prompt Injection
25
Destructive Actions
10
Excessive Permissions
100
Supply Chain
30
Obfuscation
100