T09 · Insecure Skill Coding Practices
- Location
scripts/biz/configure/service.py:35- Finding
Access Key Can Be Transmitted to an Attacker-Controlled Gateway
- Content
View full analysis
`. 3. `configure_via_gateway` constructs a request containing the complete AK in `payload.skills.entries`. 4. The Skill sends the payload to the attacker-controlled URL. 5. If present, the OpenClaw gateway bearer token is also included in the `Authorization` header. 6. ...[truncated 477 chars]- Remediation
View remediation
