Apex
ProductHow it worksProofFAQ
Book a demoUse Apex

AI security engineer for modern teams

The findings your team will actually fix.

Apex finds real, exploitable vulnerabilities in mission-critical code and hands your team fix-ready guidance — in a workspace built for validating and shipping fixes.

Start scanningBook a demo
OpenClaw Foundation/openclaw
OpenClaw Audit stopped at its 200-credit budgetMore findings likely remaining·17 findings · est. 0–10 more remain at this depth

OpenClaw audit

ValidityInvalid18 of 19
CRITOPEN-8
Hook-triggered CLI cron runs receive owner MCP bearer tokens
AcceptedApr 28, 2026, 4:01 PM UTC
CRITOPEN-1
Trusted-proxy Control UI auth skips new-device pairing and accepts attacker-declared WS admin scopes
No fix reviewApr 28, 2026, 4:00 PM UTC
CRITOPEN-2
Paired chat users can mint a setup code that silently auto-promotes a durable operator device
Pending MergeApr 28, 2026, 4:00 PM UTC
CRITOPEN-3
Spoofed Control UI locality silently mints persistent admin device tokens
AcceptedApr 28, 2026, 4:00 PM UTC
HIGHOPEN-15
Attacker-controlled skillKey lets one skill overwrite another skill's tools root
No fix reviewApr 28, 2026, 4:03 PM UTC
HIGHOPEN-20
Bundle-MCP loopback bypasses its own exec denylist via sessions_spawn
No fix reviewApr 28, 2026, 4:04 PM UTC
HIGHOPEN-11
Forged node exec lifecycle events bypass reduced-surface hardening and reach gateway host exec
No fix reviewApr 28, 2026, 4:02 PM UTC
HIGHOPEN-19
Forwarded/UI exec approvals can blindly authorize hidden host commands because approval records store only truncated display text
No fix reviewApr 28, 2026, 4:04 PM UTC
HIGHOPEN-16
Marketplace package installs can redirect runtime into unscanned hidden payloads via runtimeExtensions
No fix reviewApr 28, 2026, 4:03 PM UTC
HIGHOPEN-13
Playwright act/select and fill paths bypass browser SSRF policy, then evaluate executes on the private page
No fix reviewApr 28, 2026, 4:02 PM UTC
HIGHOPEN-10
Plugin install publishes executable code that the dangerous-code gate never scans
No fix reviewApr 28, 2026, 4:02 PM UTC
HIGHOPEN-17
POSIX node system.run safe-bin auto-allow executes unquoted shell payload and leaks host secrets
No fix reviewApr 28, 2026, 4:03 PM UTC
HIGHOPEN-9
Revoked node tokens can be self-restored from a pairing-only operator session
No fix reviewApr 28, 2026, 4:01 PM UTC
HIGHOPEN-14
Setup-mode provider discovery auto-enables and executes untrusted workspace plugins
No fix reviewApr 28, 2026, 4:03 PM UTC
HIGHOPEN-12
Shared-auth paired sessions bypass device ownership checks on pairing/token RPCs
No fix reviewApr 28, 2026, 4:02 PM UTC
HIGHOPEN-18
Shell positional carriers let allowlisted find bypass strictInlineEval
No fix reviewApr 28, 2026, 4:04 PM UTC
HIGHOPEN-6
First-time node connects expose system.run before node-pair admin approval
In reviewApr 28, 2026, 4:01 PM UTC
HIGHOPEN-7
Device-pair approval bypass exposes system.run before node.pair.approve
SkippedApr 28, 2026, 4:01 PM UTC
apex — openclawApex CLI

$apex scan --mode audit

workspace  openclaw · openclaw/openclaw @ main

threat model  threat_model.md · generated

✓Scan #1 queued · Audit scan

$apex status

OpenClaw audit · running · 34% · ETA ~18m

$apex findings --workspace --filter severity:critical

OPEN-1CRITTrusted-proxy Control UI auth skips new-device pairing…

OPEN-2CRITPaired chat users can mint a setup code that silently…

OPEN-3CRITSpoofed Control UI locality silently mints persistent…

OPEN-8CRITHook-triggered CLI cron runs receive owner MCP bearer…

$apex findings feedback OPEN-3 valid

✓OPEN-3 marked valid

$

GitHub · pull request #312

MK

maya-k commented 2 minutes ago

@cantina-apex scan this pr focus on the pairing path

cantina-apexbotcommented just now

Apex PR Scan

Status: Completed

1. Critical Spoofed Control UI locality silently mints persistent admin device tokens

Same-LAN or shared-token caller can spoof Control UI locality and retain admin authority after token rotation.

Open findingOpen scan

A live workspace preview — explore findings, scan insights, and fix reviews

Apex found bugs in

GitLab logoGitLabAnthropic logoAnthropicApple logoAppleCoinbase logoCoinbaseSentry logoSentrySupabase logoSupabaseSierra AI logoSierra AITikTok logoTikTokSuperhuman logoSuperhumanGitLab logoGitLabAnthropic logoAnthropicApple logoAppleCoinbase logoCoinbaseSentry logoSentrySupabase logoSupabaseSierra AI logoSierra AITikTok logoTikTokSuperhuman logoSuperhuman

The product

01Findings02Fix review03Scans & schedule04Threat model05Where you work
01Finding detail

Every finding tells the full story.

Summary, affected code, a recorded proof of concept, and a fix checklist in one view. Validate it, comment on it, or hand it straight to a fix review.

  • Impact context on every issue
  • PoC code with highlighted lines and terminal replay
  • Fix-ready recommendations
CritOPEN-3ValidMerged

Spoofed Control UI locality silently mints persistent admin device tokens

OpenClaw auditopenclaw/openclaw @ mainConfidence 0.99
CommentFix review

Summary

Same-LAN or shared-token caller can spoof Control UI locality, silently pair an admin device, and retain admin authority after shared-token rotation.

Proof of concept

Copy

1const config = {

2 gateway: {

3 bind: "lan",

4 auth: { mode: "token", token },

5 controlUi: {

6 enabled: true,

7 allowedOrigins: [`http://localhost:${port}`],

8 },

9 },

10};

Recommendation

Verify the immediate peer before trusting proxy headers; derive scopes from stored paired device records.

02Fix review

Ship the fix. Apex re-tests it.

Link a pull request and Apex replays the original proof of concept against it. Confirmed fixes get merged status; incomplete ones come back with what still reproduces.

Fix reviews

Apex re-tests each linked PR against the original proof of concept.

2 need attention
All · 4Needs attention · 2Active · 1Confirmed · 1
  • Fix confirmedOPEN-2

    Paired chat users can mint a setup code that silently auto-promotes a durable operator device

    OpenClaw audit · openclaw/openclaw · #287

    Fix confirmed in the latest review.

    Open PR
  • Fix in reviewOPEN-6

    First-time node connects expose system.run before node-pair admin approval

    OpenClaw audit · openclaw/openclaw · #296

    Fix review is checking the candidate patch.

    Open PR
  • Fix pendingOPEN-3

    Spoofed Control UI locality silently mints persistent admin device tokens

    OpenClaw audit · openclaw/openclaw · #291

    Fix review still reproduces the vulnerable flow.

    Open PR
03Scans & schedule

Connect in minutes. Findings in a few hours.

Connect GitHub, pick repositories, and watch the scan progress live. Set a weekly or daily schedule and every new commit range gets the same treatment.

Audit scan running· scanning openclaw/openclaw13m 57s
ETA ~15m · +3 newView
First scan completeSchedule the next scan to keep this workspace current. Set schedule
Schedule scans

Future scans start automatically on this cadence.

Weekly · Monday at 9:00 AM UTC

Daily · 9:00 AM UTC

Manual only

Next run: Mondays at 9:00 AM UTC.

04Threat model

Hunts guided by your threat model.

Before a scan starts, Apex writes a threat model for the repository: what an attacker can reach, which impacts matter most, and what to ignore. Edit it, then let the hunters optimize for it.

OpenClaw threat model

threat_model.md · Generated Apr 24, 2026

CopyEdit threat modelExpand

THREAT_MODEL

Scope Summary

This repo is an AI agent gateway/control-plane system. The highest-value findings turn untrusted chat, web, API, or plugin input into operator-equivalent control over the Gateway, paired nodes, browser state, secrets, or host execution.

Prioritized Impacts

Unauthorized host exec on gateway or node100%
Sandbox escape to host or node99%
Gateway auth / trusted-proxy / pairing bypass98%
Credential theft with durable replay value97%
05Where you work

Findings land where your team already works.

Summon a PR scan from a GitHub comment, or run the whole loop from your terminal: scan, watch progress, triage findings, and kick off fix reviews.

  • GitHubComment @cantina-apex scan this pr and the review lands on the PRCheck passed
  • Terminalapex scan, apex status, apex findings, apex findings fix-reviewApex CLI
  • TrackersSend findings to Linear or Jira, or export Markdown for the audit reportExport
  • SharingPassphrase-protected, client-safe views of the workspaceai.cantina.xyz/share/8f3a…

Proof, not promises

Trained on real audits, not synthetic data.

n01

50,000+

Real-world vulnerabilities analyzed

n02

9,000+

Expert security researchers contributing signal

n03

10+

Criticals and highs found in production code

n04

$25B+

In live funds secured

I was truly impressed by the subtle bugs that Cantina uncovered in an open-source cryptographic repository that I maintain, which had already gone through thorough reviews. Their AI-powered tool acts as a valuable safety net to catch bugs that humans and other tools may have missed.
Coinbase logo

Arash Afshar · Coinbase Cryptography Team

FAQ

Questions, answered.

What teams usually want to know before connecting their first repository.

Apex uses AI-assisted code understanding to surface practical vulnerabilities, reduce false positives, and provide remediation guidance with context.

See your first findings today.

From a single scan to enterprise coverage, Apex shows what matters and helps your team fix it fast.

Start scanningBook a demo
Apex— 2026. All rights reserved.
ProductHow it worksProofFAQPrivacyTerms