T09 · Insecure Skill Coding Practices
- Location
scripts/oc_call.py:40- Finding
Bearer Token, Session Identifier, and User Prompts Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/oc_call.py, lines 40-41 and 106-115
Vulnerability Type: Sensitive-data transmission over an unencrypted channel
Risk Level: HighVulnerable code:
python OC_URL = "http://192.168.123.106:28789/v1/chat/completions" OC_TOKEN = "87654321"python payload = { "model": "openclaw/default", "messages": [{"role": "user", "content": question}], "max_tokens": 4096 } data = json.dumps(payload).encode("utf-8") headers = { "Authorization": f"Bearer {OC_TOKEN}", "Content-Type": "application/json", "x-openclaw-session-key": session_key } req = urllib.request.Request(OC_URL, data=data, headers=headers, method="POST") try: with urllib.request.urlopen(req, timeout=120) as resp:Technical Analysis
The gateway URL uses plaintext HTTP. The request contains the bearer token in the
Authorizationheader, a persistent session identifier in thex-openclaw-session-keyheader, and the user's prompt in the request body. HTTP provides neither confidentiality nor authenticated transport.An attacker capable of observing or modifying traffic between the host and
192.168.123.106can read these values or alter the request and response. Relevant attack positions include a compromised device on the local network, a malicious wireless access point, ARP-spoofing malware, or a compromised router. Because no TLS authentication is performed, the client also cannot cryptographically verify that it is communicating with the intended gateway.Attack Path
- The user invokes the Skill with a question.
- The script creates an HTTP request containing the static bearer token, persistent session key, and prompt.
- An attacker obtains a network-path position, such as through ARP spoofing or control of a local router.
- The attacker captures the plaintext request and extracts the bearer token and session key.
- If the ...[truncated 808 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the HTTP endpoint with an HTTPS endpoint using a certificate valid for the gateway hostname.
- Preserve Python's default TLS certificate and hostname verification; do not install an unverified SSL context.
- Reject non-HTTPS URLs whenever authorization credentials or session identifiers will be transmitted.
- Store the endpoint in an explicitly configured environment variable, but validate that its scheme is
https. - Rotate the currently embedded bearer token because it has been stored in source code and transmitted without encryption.
- Consider short-lived, narrowly scoped credentials rather than a reusable bearer token.
- Avoid transmitting sensitive prompts unless users have been informed that their content is sent to a remote service.
- Apply network controls so the gateway accepts connections only from authorized systems, as defense in depth.
