T09 · Insecure Skill Coding Practices
- Location
scripts/capabilities/configure/service.py:77- Finding
Plaintext API Key Storage Without Enforced File Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears intended for Chinese company risk lookup, but its access-key setup handles credentials in ways users should review before installing.
Install only if you trust the 1688/OpenClaw integration and are comfortable sending company identifiers and risk-query activity to the external service. Before configuring an AK, ensure OPENCLAW_GATEWAY_URL points only to a trusted local gateway, protect the OpenClaw config file, and be aware the key may be stored under the shared cha88-base configuration namespace.
scripts/capabilities/configure/service.py:77Plaintext API Key Storage Without Enforced File Permissions
scripts/capabilities/configure/service.py:36Environment-Controlled Gateway URL Can Receive API and Bearer Credentials
scripts/capabilities/companyRisk/cmd.py:45Untrusted API Response Fields Are Rendered as Active Markdown
The gateway URL is taken directly from an environment variable and used to send a PATCH request containing the API key and optional bearer token. If an attacker can influence the environment, they can redirect credentials to an attacker-controlled endpoint, causing secret exfiltration or unauthorized configuration changes.
headers = {}
if token:
headers["Authorization"] = f"Bearer {token}"
resp = requests.patch(f"{gateway_url}/api/config",
headers=headers, json=payload, timeout=5)
return resp.ok
except Exception:
The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.
The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.
The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.
The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.
The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.
The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.
The Chinese description promises enterprise risk lookup, but the documented behavior also includes API-key configuration, credential reads, and local gateway configuration changes. In this context, the mismatch is especially risky because the skill is positioned as a passive legal-risk analysis tool, lowering user suspicion while enabling secret and configuration handling.
This referenced capability is for basic enterprise search and information retrieval, which conflicts with the skill manifest stating that pure company-info queries must not trigger this risk-analysis skill. That mismatch can cause the skill to activate on out-of-scope requests, leading to unnecessary collection, processing, or disclosure of legal-risk data when the user only asked for ordinary company information.
The manifest says this skill is a tool for querying and analyzing mainland China company legal/risk data, triggered only for enterprise risk intents. However, this file documents a cross-cutting telemetry mechanism in cha88-base that reports skill invocation metadata to a gateway, which is materially different from the claimed risk-query behavior.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。
环境变量(从项目根目录 .env 读取):
SKILL_NAME skill 名称,默认 cha88-base
SKILL_VERSION skill 版本,默认 1.0.0
SKILL_CHANNEL 发布渠道,默认 clawhub
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
职责:每次 CLI 命令执行时,向 skill 网关上报一次调用记录,用于统计 skill 调用次数。
上报失败不影响主流程,静默处理。
环境变量(从项目根目录 .env 读取):
SKILL_NAME skill 名称,默认 cha88-base
SKILL_VERSION skill 版本,默认 1.0.0
SKILL_CHANNEL 发布渠道,默认 clawhub
Opening and parsing the project .env file causes the module to ingest potentially sensitive configuration into the runtime environment, even though the feature only needs simple tracking metadata. In this skill context, that creates unnecessary secret exposure surface and could enable accidental downstream leakage if other code reads or transmits environment variables.
def _load_env_file() -> None:
"""解析项目根目录的 .env 文件,将变量注入 os.environ(已有环境变量不覆盖)。"""
env_path = _ROOT_DIR / ".env"
if not env_path.exists():
return
with open(env_path, encoding="utf-8") as f:
Executing _load_env_file() at import time injects .env contents into os.environ before any caller has a chance to constrain behavior. In an agent skill, import-time loading of potentially sensitive configuration is risky because it silently broadens accessible secrets and couples unrelated runtime state to telemetry support.
os.environ[key] = value
# 模块加载时解析一次 .env
_load_env_file()
The manifest says this skill is for querying and analyzing company legal/risk signals only, and explicitly says pure enterprise information lookup should not trigger this skill. However, the file is documented and implemented as '企业搜索/企业查询', accepts a company-name keyword, calls company_search, and formats general company profile fields such as legal representative, registered capital, establishment date, type, and address rather than risk data.
The implementation performs a generic company search against /api/companySearch/1.0.0 rather than a risk- or legal-risk-specific query as promised by the skill manifest. This mismatch can cause the router to invoke the skill for sensitive compliance or risk-review tasks while returning broader enterprise-search data, creating unauthorized data access, policy bypass, and misleading outputs in a security-sensitive context.
This file implements an AK credential configuration and storage workflow even though the advertised skill is only for enterprise risk/legal-risk lookup. Introducing secret-handling functionality that is outside the declared purpose expands the attack surface, may enable unauthorized credential capture or persistence, and violates least privilege for the skill. The mismatch between stated functionality and actual behavior makes the skill context more dangerous because users invoking a company-risk tool would not reasonably expect it to write or manage access keys.
This configuration service persists credentials under SKILL_NAME = "cha88-base", which does not match the manifested enterprise-risk skill. That cross-skill credential targeting can cause this skill to modify another skill's configuration, violating least privilege and potentially enabling credential confusion or unauthorized access paths.
The skill declares no explicit tool scope even though the documented behavior requires environment access, file reads/writes, and network calls. Without an allowlisted permission boundary, an agent/runtime may grant broader capabilities than users expect, increasing the chance of unintended secret access, local-state modification, or exfiltration via networked commands.
The manifest describes a tool focused on querying and analyzing company legal/risk information, with triggering restricted to enterprise-risk lookup intents. However, the CLI explicitly advertises a separate configure command for setting an AK, which is an additional administrative capability not reflected in the manifest’s described behavior.
The CLI dynamically discovers and imports every capabilities/*/cmd.py module found under the scripts directory, allowing functionality beyond the skill's declared scope to become executable without explicit registration. This increases attack surface and can enable hidden or unintended commands to run if additional modules are introduced into the package or environment.
The code reports usage after every command via _tracker.report_skill_usage() with no visible disclosure or consent mechanism in this file. In a tool handling enterprise risk queries, silent telemetry can expose sensitive business interests, searched entities, or operational metadata, making undisclosed tracking materially risky even if the main function is legitimate.
The document for an enterprise-search capability explicitly instructs the agent to chain into companyRisk queries, expanding behavior beyond the capability’s stated scope. This creates scope drift and can cause the parent skill to invoke more sensitive risk-analysis actions than intended, especially when the capability is reused in contexts that should only return basic company lookup data.
The skill instructs the agent to transmit company identifiers such as unified social credit codes or companyId values to an external API without any user-facing notice about data handling, third-party transmission, or sensitivity. In an enterprise or compliance context, this can cause unintended disclosure of identifiers and risk-query activity, especially when users may assume the lookup is local or internal.
The instructions and quoted agent responses are entirely in Chinese, including prescribed output such as the AK acquisition prompt and success guidance. There is no indication that the skill is region-specific or that users may choose another language, so this creates a natural-language locale policy concern.
No suspicious patterns detected.