T09 · Insecure Skill Coding Practices
- Location
scripts/capabilities/configure/service.py:57- Finding
API Key Exposed Through Command-Line Arguments and Unprotected Plaintext Storage
- Content
View full analysis
bool: """Directly write openclaw.json as a fallback.""" try: config: dict = {} if OPENCLAW_CONFIG_PATH.exists(): try: with open(OPENCLAW_CONFIG_PATH, "r", encoding="utf-8") as config_file: content = config_file.read().strip() if content: config = json.loads(content) except json.JSONDecodeError: return False config.setdefault("skills", {}) config["skills"].setdefault("entries", {}) config["skills"]["entries"].setdefault(SKILL_NAME, {}) skill_entry = config["skills"]["entries"][SKILL_NAME] skill_entry["apiKey"] = api_key # Remove the legacy format. if "env" in skill_entry and isinstance(skill_entry["env"], dict): skill_entry["env"].pop(ENV_AK_NAME, None) if not skill_entry["env"]: del skill_entry["env"] OPENCLAW_CONFIG_PATH.parent.mkdir(parents=True, exist_ok=True) with open(OPENCLAW_CONFIG_PATH, "w", encoding="utf-8") as config_file: json.dump(config, config_file, ensure_ascii=False, indent=2) return True except Exception: return False ``` ### Technical Analysis The configuration interface r ...[truncated 2231 chars]- Remediation
View remediation
