T09 · Insecure Skill Coding Practices
- Location
scripts/lib.sh:112- Finding
Bankr API Key Can Be Exfiltrated Through an Unvalidated API Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/lib.sh:112-130; credential transmission occurs atscripts/deploy-via-bankr.sh:109-127
Vulnerability Type: Unvalidated sensitive API endpoint configuration
Risk Level: HighVulnerable Code
scripts/lib.sh:112-130:bash resolve_bankr_api_url() { local config_path for config_path in \ "$HOME/.openclaw/skills/bankr/config.json" \ "$HOME/.openclaw/workspace/skills/bankr/config.json" \ "$HOME/.bankr/config.json" do if [ -f "$config_path" ]; then local value value="$(jq -r '.apiUrl // empty' "$config_path")" if [ -n "$value" ]; then echo "$value" return fi fi done echo "https://api.bankr.bot" }scripts/deploy-via-bankr.sh:109-127:bash BANKR_API_KEY="$(resolve_bankr_api_key)" BANKR_API_URL="$(resolve_bankr_api_url)" REQUEST_PAYLOAD="$(jq -n \ --arg to "$FACTORY_ADDRESS" \ --argjson chainId "$CHAIN_ID" \ --arg data "$CALLDATA" \ --arg description "$DESCRIPTION" \ '{ transaction: { to: $to, chainId: $chainId, value: "0", data: $data }, description: $description, waitForConfirmation: true }')" RESPONSE="$(curl -sS --max-time "$BANKR_SUBMIT_TIMEOUT_SECONDS" -X POST "$BANKR_API_URL/agent/submit" \ -H "X-API-Key: $BANKR_API_KEY" \ -H "Content-Type: application/json" \ -d "$REQUEST_PAYLOAD")"Technical Analysis
The Bankr API endpoint is read from locally writable JSON configuration files and accepted without validation. The implementation does not require HTTPS, verify that the hostname belongs to Bankr, restrict ports, or otherwise enforce an approved origin.
Credential resolution is independent of endpoint resolution. Consequently, a legitimate API key obtained from
BANKR_API_KEY, the systemd user environment, or another searched configuration fi ...[truncated 2130 chars]- Remediation
View remediation
Remediation Suggestions
- Hard-code or allowlist the official Bankr API origin, such as
https://api.bankr.bot, for normal operation. - If custom endpoints are required, make them an explicit opt-in and prominently display the selected endpoint before broadcasting.
- Parse and validate custom URLs before transmitting credentials:
- Require the
httpsscheme. - Reject embedded usernames or passwords.
- Reject fragments, unexpected ports, malformed hosts, and non-allowlisted domains.
- Resolve and reject loopback, link-local, private, or otherwise disallowed destinations when arbitrary hosts are unnecessary.
- Require the
- Harden the request with appropriate
curlcontrols, for example:bash curl --proto '=https' --proto-redir '=https' \ --max-redirs 0 \ --fail-with-body \ --max-time "$BANKR_SUBMIT_TIMEOUT_SECONDS" \ ... - Do not resolve the API credential and API URL from independent trust sources. Bind each credential to its explicitly configured and validated service origin.
- Check ownership and restrictive permissions on credential-bearing configuration files before reading them.
- After receiving a transaction hash, retrieve the transaction and verify its chain, recipient, calldata, value, and expected sender before accepting its receipt.
- Restrict deployment event extraction to logs emitted by the expected factory address rather than accepting any matching event signature in the receipt.
- Hard-code or allowlist the official Bankr API origin, such as
