T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned Third-Party Azure SDK Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed Azure/Bing web-grounding helper that uses Azure credentials and sends user queries to Azure services as expected for its purpose.
Install this only if you intend to let the skill send your search queries to Azure/Bing and use your Azure project credentials. Prefer Azure CLI, managed identity, or tightly scoped short-lived credentials over storing AZURE_CLIENT_SECRET in ~/.openclaw/.env, keep that file private, and use a virtual environment with pinned dependencies where possible.
SKILL.md:10Unpinned Third-Party Azure SDK Dependencies
scripts/bing_grounding.py:10Plaintext Azure Client Secret Stored in a Shared Environment File
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if val:
return val.strip()
env_path = os.path.expanduser("~/.openclaw/.env")
if os.path.exists(env_path):
import re
with open(env_path, "r", encoding="utf-8", errors="ignore") as f:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if val:
return val.strip()
env_path = os.path.expanduser("~/.openclaw/.env")
if os.path.exists(env_path):
import re
with open(env_path, "r", encoding="utf-8", errors="ignore") as f:
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
g="utf-8", errors="ignore") as f:
txt = f.read()
m = re.search(rf"^\s*{name}\s*=\s*(.+?)\s*$", txt, re.M)
if m:
v = m.group(1).strip().strip('"').strip("'")
if v:
return v
return None
def main():
default_model = load_env_var("FOUNDRY_MODEL_DEPLOYMENT_NAME") or "gpt-4o"
ap = argparse.ArgumentParser(description="Azure Bing Grounding Search Tool using Agents SDK")
ap.add_argument("--query", required=True, help="Question or query to send to the grounded agent")
ap.add_argument("--model", default=default_model, help="Model deployment name to use (defaults to FOUNDRY_MODEL_DEPLOYMENT_NAME or gpt-4o)")
ap.add_argument("--format", default="raw", choices=["raw", "md"], help="Output format: raw (JSON) or md (Markdown)")
args = ap.parse_args()
project_endpoint = load_env_var("FOUNDRY_PROJECT_ENDPOINT")
bing_connection_id = load_env_var("BING_PROJECT_CONNECTION_ID")
if
The documentation presents the markdown output example entirely in Chinese, which implies the skill may produce or expect a specific language without offering user choice. The stated purpose of the skill is general web grounding, and the README does not document any region-specific or language-specific constraint that would justify this locale behavior.
The skill invokes a local Python script and instructs users to provide Azure credentials via environment variables, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates a trust boundary issue: the skill can access environment data and local files without transparent restriction metadata, making it easier for a caller or agent framework to over-grant access and accidentally expose secrets.
The script sends the user-supplied --query directly to Azure Agents/Bing Grounding, which forwards potentially sensitive content to an external service without any consent prompt, warning, or data-classification check. In a grounding/search skill, users may mistakenly include secrets, internal URLs, customer data, or incident details that then leave the local environment and become subject to external processing.
No suspicious patterns detected.