T09 · Insecure Skill Coding Practices
- Location
references/selfhost.md:3- Finding
Insecure Self-Hosting Defaults Expose Credentials and Sensitive Fitness Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This wger integration is not deceptive, but it can read and change sensitive fitness data and lacks enough guardrails for account writes and self-hosting.
Review this before installing if you plan to connect a real wger account. Use a limited token, require explicit approval before any create/update action, avoid putting tokens directly in commands, and harden any self-hosted deployment with unique secrets, loopback or VPN-only exposure, HTTPS, and pinned container versions.
references/selfhost.md:3Insecure Self-Hosting Defaults Expose Credentials and Sensitive Fitness Data
references/selfhost.md:15Mutable Container Image Tag Permits Unreviewed Dependency Changes
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
'workout': workout_id,
'exercises': exercises # List of dicts: [{'reps': 10, 'weight': 135, 'exercise': exercise_id}]
}
response = requests.post(f'{BASE_URL}workoutlog/', json=data, headers=headers)
if response.status_code in [200, 201]:
print(f"Log created: {response.json()}")
else:
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
url = f'{BASE_URL}workoutlog/?limit={limit}&format=json'
if workout_id:
url += f'&workout={workout_id}'
response = requests.get(url, headers=headers)
if response.status_code == 200:
data = response.json()
print(json.dumps(data, indent=2))
The manifest description uses very broad trigger wording such as general fitness/gym/wger queries and multiple action categories, which increases the chance the skill is invoked in situations the user did not clearly intend. Because the skill supports authenticated API writes, overbroad activation can lead to unintended account modifications rather than merely informational responses.
The skill explicitly transmits user fitness data to an external API and routes analysis through subagents, which is a genuine data egress concern. While external transmission is expected for an API integration skill, the danger is increased by the lack of clear consent, data-minimization guidance, and privacy boundaries around what is sent to third parties or additional agents.
# wger Fitness Manager
wger is an open-source fitness tracker with REST API for routines, logs, nutrition, and progress. This skill handles API interactions for seamless integration with OpenClaw (exec/curl for calls, subagents for analysis).
## Setup (One-Time)
- API Base: https://wger.de/api/v2/ (or self-hosted URL).
The setup text encourages passing an API token in commands and examples without warning about shell history, logs, process inspection, or transcript exposure. Even when an environment variable is shown, the wording normalizes credential handling in command context that may leak secrets in agent logs or operational telemetry.
This section instructs the agent to perform authenticated POST and PATCH operations that modify workouts, logs, and nutrition data without any warning or requirement for explicit user confirmation. In an agentic environment, that creates a real risk of silent or mistaken state-changing actions against the user's account.
This markdown file describes bringing up a web service and accessing its API endpoint, but it does not clearly warn users about authentication, default exposure risks, or protecting any personal fitness data the service may hold. Although line L31 suggests securing with Tailscale/VPN, it is phrased as a brief recommendation rather than a user warning about privacy and system integrity implications.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
'workout': workout_id,
'exercises': exercises # List of dicts: [{'reps': 10, 'weight': 135, 'exercise': exercise_id}]
}
response = requests.post(f'{BASE_URL}workoutlog/', json=data, headers=headers)
if response.status_code in [200, 201]:
print(f"Log created: {response.json()}")
else:
The script retrieves workout log data using an API token and prints the full API response to stdout without any minimization, warning, or access control. In shared environments, terminals, logs, shell history workflows, or agent pipelines, this can disclose potentially sensitive personal fitness data to unintended viewers.
The when-to-use section includes broad trigger phrases and automation language like crons/subagents, but it does not define limits for when autonomous actions are appropriate. That ambiguity is risky because the skill can perform external authenticated operations and may be selected for loosely related requests.
This markdown file describes POST and PATCH endpoints that create or modify user workout and nutrition records, but it does not include any user-facing warning about data-changing behavior. For markdown files, omissions around behaviors that affect user data should be flagged when the description presents those operations without disclosure.
No suspicious patterns detected.