T09 · Insecure Skill Coding Practices
- Location
config.json:2- Finding
Authorization Credential Distributed in Packaged Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be an RPA webhook utility, but it needs Review because it ships live-looking tenant credentials and its setup, migration, and logging paths can expose secrets.
Review this carefully before installing. Do not use it as packaged with the included config.json values; the exposed Feishu authorization value should be rotated, tenant-specific URLs removed, and only placeholder config shipped. Setup and migration scripts should stop printing or writing real secrets, logs should redact parameter values by default, and any RPA run should require a user-selected test or production webhook.
config.json:2Authorization Credential Distributed in Packaged Configuration
bazhuayu-webhook.py:396Sensitive Parameters Bypass Redaction and Leak to Console and Logs
setup-secure.sh:105Setup Wizard Displays and Persists the Webhook Secret in Plaintext
migrate-to-env.sh:32Migration Process Multiplies Plaintext Copies of Existing Secrets
setup-secure.sh:144Untrusted Webhook URL Is Expanded Inside an Executable Heredoc
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
配置完成后,请手动将 export 命令添加到 ~/.bashrc 或 ~/.zshrc。
# 临时设置(当前终端会话)
export BAZHUAYU_WEBHOOK_KEY="你的签名密钥"
export BAZHUAYU_WEBHOOK_URL="https://api-rpa.bazhuayu.com/api/v1/bots/webhooks/xxx/invoke"
# 永久设置(添加到 ~/.bashrc 或 ~/.zshrc)
echo 'export BAZHUAYU_WEBHOOK_KEY="你的签名密钥"' >> ~/.bashrc
echo 'export BAZHUAYU_WEBHOOK_URL="https://api-rpa.bazhuayu.com/api/v1/bots/webhooks/xxx/invoke"' >> ~/.bashrc
source ~/.bashrc
vim config.json
填入配置(key 留空):
{
"url": "https://api-rpa.bazhuayu.com/api/v1/bots/webhooks/你的 ID/invoke",
"key": "",
"paramNames": ["keyword", "url"],
"defaultParams": {
"keyword": "默认关键词",
"url": "https://example.com"
}
}
python3 bazhuayu-webhook.
The release notes instruct users to run 'rm -rf /root/.openclaw/workspace/skills/bazhuayu-webhook', a forceful recursive delete under /root, with no safety guardrails. Because this is likely to be copy-pasted by operators, any typo, variable substitution issue, or path confusion could delete unintended files, especially in privileged environments.
# 删除旧版本
rm -rf /root/.openclaw/workspace/skills/bazhuayu-webhook
# 重新安装
clawhub install bazhuayu-webhook
The release notes instruct users to run 'rm -rf /root/.openclaw/workspace/skills/bazhuayu-webhook', a forceful recursive delete under /root, with no safety guardrails. Because this is likely to be copy-pasted by operators, any typo, variable substitution issue, or path confusion could delete unintended files, especially in privileged environments.
# 删除旧版本
rm -rf /root/.openclaw/workspace/skills/bazhuayu-webhook
# 重新安装
clawhub install bazhuayu-webhook
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
--prune-empty --tag-name-filter cat -- --all
# 2. 推送更改
git push origin --force --all
# 3. 联系 GitHub/GitLab 支持清除缓存 (如已推送到远程)
The English description promises webhook-based RPA triggering, while the analyzed content also describes interactive configuration collection, local file updates, migration helpers, shell-session exports, and permission changes, with no actual webhook-trigger behavior present in the analyzed chunk. This discrepancy can mislead reviewers and automation policies, allowing broader local-impact behavior to pass under the label of a simple integration utility.
The English description promises webhook-based RPA triggering, while the analyzed content also describes interactive configuration collection, local file updates, migration helpers, shell-session exports, and permission changes, with no actual webhook-trigger behavior present in the analyzed chunk. This discrepancy can mislead reviewers and automation policies, allowing broader local-impact behavior to pass under the label of a simple integration utility.
Referenced artifact was not completely inspected
- **安全指南**: `SECURITY.md` - 安全最佳实践
The example shows passing a username and password directly as command-line arguments and transmitting them to a remote webhook, which is dangerous because credentials may be exposed in shell history, process listings, logs, screenshots, and downstream systems. Presenting a plaintext password example without warnings can cause users to adopt insecure credential-handling practices in real deployments.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<p>本教程详细介绍如何在八爪鱼 RPA 中创建和配置 Webhook 触发器。</p>
<!-- 步骤 1 -->
<div class="step">
<h2><span class="step-number">1</span>进入触发器管理</h2>
<ol>
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
config['key'] = env_key
# 3. 加载环境变量中的参数默认值 (BAZHUAYU_PARAM_*)
for env_name, env_value in os.environ.items():
if env_name.startswith('BAZHUAYU_PARAM_'):
param_name = env_name.replace('BAZHUAYU_PARAM_', '')
# 转换为驼峰或小写格式
The configuration hardcodes a Feishu authorization token and multiple internal Feishu Base URLs directly in the skill defaults. This exposes reusable credentials and private workspace resources to anyone who can read, copy, or invoke the skill, enabling unauthorized access to Feishu data and unintended triggering of downstream RPA workflows.
The file’s natural-language content consistently forces a specific language/locale for readers. Under the policy, language constraints should either be optional for users or clearly justified as region-specific; this file provides neither.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 创建目录
mkdir -p ~/.openclaw/workspace/skills/bazhuayu-webhook
cd ~/.openclaw/workspace/skills/bazhuayu-webhook
# 下载主程序(需要主程序文件)
The manual instructs users to place the webhook signing key directly into a local config.json file and provides no guidance on file permissions, secret storage, or redaction. That increases the chance the key is exposed through world-readable files, backups, screenshots, shell history, or accidental commits, allowing unauthorized triggering of RPA jobs.
The usage examples show simple run commands that will invoke a remote webhook and start automation in the user's RPA environment, but they do not clearly warn that these commands cause real external side effects. In an agent or automation context, that can lead to accidental execution of business workflows, data collection, or browser automation against production targets.
The integration example uses a broad natural-language trigger like '采集新闻' to automatically start an RPA workflow. Broad triggers increase the risk of unintended activation from ambiguous user messages, prompt injection in surrounding conversation, or benign mentions that should not launch external automation.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Linux
sudo ntpdate pool.ntp.org
# 或使用 timedatectl
sudo timedatectl set-ntp true
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Linux
sudo ntpdate pool.ntp.org
# 或使用 timedatectl
sudo timedatectl set-ntp true
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Linux
sudo ntpdate pool.ntp.org
# 或使用 timedatectl
sudo timedatectl set-ntp true
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Linux
sudo ntpdate pool.ntp.org
# 或使用 timedatectl
sudo timedatectl set-ntp true
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Linux
sudo ntpdate pool.ntp.org
# 或使用 timedatectl
sudo timedatectl set-ntp true
标题和全文说明均以中文呈现,且未说明这是面向特定地区/用户群的限定版本,也未提供其他语言选项。根据语言/区域政策,强制单一语言而无用户选择可能构成自然语言政策违规。
The skill documentation is presented entirely in Chinese from the title onward, with no indication that other languages are supported or that Chinese is an optional locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The manual installation section instructs users to run a destructive deletion command before reinstalling, but it does not include an explicit warning, path validation step, backup guidance, or confirmation note. In operational environments, users may copy-paste such commands blindly, and any path misunderstanding or modification could lead to unintended data loss.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# 设置正确权限 (仅所有者可读写)
chmod 600 config.json
# 验证权限
ls -la config.json
Detected: suspicious.destructive_delete_command