T09 · Insecure Skill Coding Practices
- Location
openclaw.json:17- Finding
API Credential Exposed in HTTP URL Paths
- Content
View full analysis
Vulnerability Details
File Location:
openclaw.json:17,openclaw.json:31,openclaw.json:45,openclaw.json:59,openclaw.json:73,openclaw.json:87,openclaw.json:101,openclaw.json:110,openclaw.json:123,openclaw.json:143, andopenclaw.json:152
Vulnerability Type: Credential exposure through URL paths
Risk Level: HighThe following representative configuration demonstrates the issue:
json { "name": "cooltrade_stock_quote", "description": "Get deep market quote and financial fundamentals for any A-share stock (China Market). Provide stock name or code.", "type": "http", "config": { "method": "GET", "url": "https://api.cooltrade.xyz/api/market/agent-skills/{{COOLTRADE_API_KEY}}/ashare/quote/", "params": { "stock": "{{query}}" } } }The same credential-in-path construction is used by all configured CoolTrade HTTP endpoints, including market-data, report, cryptocurrency, and alert-management operations.
Technical Analysis
The user's
COOLTRADE_API_KEYis interpolated directly into the URL path. Although HTTPS protects the request while it is in transit, full URLs are commonly retained outside the encrypted transport layer by origin-server access logs, reverse proxies, application-performance monitoring systems, diagnostic traces, exception reports, and client-side request histories.Authentication credentials should not be placed in URL paths or query strings. They should be transmitted through an authorization header or another dedicated secret-bearing header and redacted from telemetry. Sending the key to CoolTrade is necessary for the declared functionality, but exposing it through a broadly logged URL field is not necessary and violates least-disclosure principles.
Attack Path
- A user installs the Skill and supplies a valid
COOLTRADE_API_KEY. - OpenClaw interpolates the key into the URL path whenever a Skill endpoint i ...[truncated 1149 chars]
- A user installs the Skill and supplies a valid
- Remediation
View remediation
Remediation Suggestions
-
Remove
{{COOLTRADE_API_KEY}}from every URL path. -
Send the credential through a standard header, such as:
http Authorization: Bearer {{COOLTRADE_API_KEY}}Alternatively, use a dedicated header such as
X-API-Keyif required by the service. -
Update the CoolTrade server to reject credentials supplied through URLs.
-
Configure clients, reverse proxies, API gateways, and telemetry systems to redact authorization headers and other secret-bearing fields.
-
Search existing access logs, diagnostics, and monitoring records for exposed keys, then securely purge or restrict those records.
-
Rotate all keys that have previously been used with the URL-based authentication scheme.
-
If supported by the platform, use distinct scoped credentials for read-only market data and state-changing alert management.
-
