T09 · Insecure Skill Coding Practices
- Location
scripts/openclawarena.sh:12- Finding
Hard-Coded Shared API Credential
- Content
View full analysis
Vulnerability Details
File Location:
scripts/openclawarena.sh:12-13
Vulnerability Type: Hard-coded credential
Risk Level: MediumVulnerable Code
bash API_HOST="${OCA_ENDPOINT:-https://api.openclawarena.achaninc.net}" API_KEY="${OCA_API_KEY:-735BLLoQuk9NuDT3Z2nqO4IqGYBWcpmH96OGgzv9}"The documentation also makes a contradictory security claim at
SKILL.md:417-420:markdown - A shared platform API key is bundled as the default — override with `OCA_API_KEY` if needed - Optional `OCA_AGENT_KEY` for agent-owned actions (queue, discussions) - Data sent: agent names, agent IDs, match IDs, owner strings (no PII beyond what the user provides) - No secrets stored in script filesTechnical Analysis
The script embeds an API key and automatically uses it whenever
OCA_API_KEYis unset. Because the project is distributed to users, this credential must be considered publicly disclosed. The key is attached to requests through thex-api-keyheader and permits access to the supported platform API operations.Embedding a shared credential prevents effective attribution and least-privilege separation between users. It also contradicts the explicit claim that no secrets are stored in script files. Even if the key is intended for shared public access, representing it as a secret-style API key creates abuse, rotation, and quota-management risks.
Attack Path
- An attacker obtains or downloads the Skill package.
- The attacker reads
scripts/openclawarena.shand extracts the value assigned toAPI_KEY. - The attacker submits requests directly to the documented REST endpoint with the extracted value in the
x-api-keyheader. - The attacker invokes any API operations authorized for that shared key without possessing an independently provisioned platform credential.
- Requests are charged, rate-limited, or attributed to the shared credential rather than an individual user.
...[truncated 615 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke and rotate the embedded API key because it must be treated as publicly disclosed.
- Remove the fallback value and require callers to provide
OCA_API_KEYexplicitly:bash API_KEY="${OCA_API_KEY:-}" - Retain the existing
require_api_keycheck so execution fails safely when the variable is absent. - Provision separate, scoped credentials per user or installation instead of distributing a shared credential.
- Restrict each credential to only the required API methods and resources.
- Apply server-side rate limits, anomaly monitoring, expiration, and revocation controls.
- Use a secret manager or another secure provisioning mechanism where automated credential delivery is required.
- Correct
SKILL.mdso its security statements accurately describe credential handling.
