T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
Insecure Plaintext Storage and Command-Line Handling of Access Tokens
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39–45; related examples at lines 23–31 and 73–76
Vulnerability Type: Plaintext credential exposure
Risk Level: MediumVulnerable Code
bash # Temporary use (single invocation) GITHUB_TOKEN="ghp_your_token_here" clawhub publish <path> --version 1.0.0 --tags "..." # Permanent configuration (add to ~/.bashrc or environment variables) echo 'export GITHUB_TOKEN="ghp_your_token_here"' >> ~/.bashrc source ~/.bashrcRelated token-handling instructions include:
bash # 1. Obtain a clawhub token clawhub login # 2. Log in using the token (without a browser) clawhub login --token <clh_token> # 3. Verify clawhub whoamibash GITHUB_TOKEN="ghp_your_token" clawhub publish ...Technical Analysis
The Skill advises users to place a GitHub access token directly in
~/.bashrc. This stores the credential as plaintext in a persistent shell configuration file. The file may subsequently be exposed through configuration backups, support bundles, accidental repository commits, insecure file permissions, or access by another process or account capable of reading the user's files.The examples also encourage users to type GitHub and ClawHub tokens directly into interactive command lines. Such commands may be retained in shell history. A ClawHub token passed through
--tokenmay additionally be exposed as a process argument while the command is running. The prefixedGITHUB_TOKENassignment may be observable through process-environment inspection by sufficiently privileged local processes.No hardcoded live credential or deliberate credential-exfiltration endpoint was identified. The examples use placeholders, and the documented GitHub requests target the official
https://api.github.comservice. The issue is therefore insecure credential-handling guidance rather than an embedded secret or malicious exfiltration mechanism.Attack Path
- A user follows the ...[truncated 1505 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the recommendation to write access tokens directly into
~/.bashrc. - Prefer the official GitHub CLI credential store, an operating-system keychain, a dedicated secrets manager, or ClawHub's secure credential-storage mechanism.
- Avoid placing tokens directly in interactive command text. Read secrets without terminal echo or retrieve them programmatically from a credential manager.
- If an environment variable is required, populate it from a protected secret source only for the lifetime of the command and unset it immediately afterward.
- Warn users not to commit shell configuration, environment files, command histories, or diagnostic bundles containing credentials.
- Recommend fine-grained, least-privilege tokens restricted to only the required repositories and operations.
- Prefer short expiration periods and document token rotation and immediate revocation procedures.
- Document restrictive permissions for any unavoidable local secret file, such as owner-only access, while clarifying that file permissions do not replace secure secret storage.
- Replace
clawhub login --token <token>with an interactive standard-input or credential-helper workflow if supported, preventing token exposure through command arguments and shell history.
- Remove the recommendation to write access tokens directly into
