T09 · Insecure Skill Coding Practices
- Location
auto_capture.py:52- Finding
Automatic Capture Can Upload Credentials and Sensitive Session Data Without Effective Redaction
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill clearly backs up knowledge to Supermemory, but its optional auto-capture feature can repeatedly upload sensitive session memory with weak filtering and unsafe cron setup.
Install only if you are comfortable sending selected OpenClaw memory-log content to Supermemory.ai. Do not enable the cron job unless you have reviewed the memory directory contents and accept ongoing unattended uploads; prefer dry-run/manual storage. Treat the .env sourcing and weak redaction as risks, and avoid using this with secrets, credentials, private customer data, or regulated information in session memory.
auto_capture.py:52Automatic Capture Can Upload Credentials and Sensitive Session Data Without Effective Redaction
install_cron.sh:53Installer Creates Persistent Unattended Session-Memory Collection Through Cron
install_cron.sh:10Unsafe Cron Command Construction and Shell-Sourcing of .env Enable Scheduled Command Execution
Installing and removing system cron jobs, sourcing workspace .env, and writing logs are materially different from a simple backup/retrieval utility. In context, these hidden operational behaviors increase persistence and automation risk, especially because they can continue scanning and uploading session-derived content after initial setup.
Installing and removing system cron jobs, sourcing workspace .env, and writing logs are materially different from a simple backup/retrieval utility. In context, these hidden operational behaviors increase persistence and automation risk, especially because they can continue scanning and uploading session-derived content after initial setup.
Installing and removing system cron jobs, sourcing workspace .env, and writing logs are materially different from a simple backup/retrieval utility. In context, these hidden operational behaviors increase persistence and automation risk, especially because they can continue scanning and uploading session-derived content after initial setup.
Installing and removing system cron jobs, sourcing workspace .env, and writing logs are materially different from a simple backup/retrieval utility. In context, these hidden operational behaviors increase persistence and automation risk, especially because they can continue scanning and uploading session-derived content after initial setup.
Referenced artifact was not completely inspected
| `SKILL.md` | This file |
This script automatically scans session memory logs and uploads selected content to an external cloud service without an explicit runtime warning or confirmation about sensitive data transfer. Because memory logs can contain user prompts, environment details, file paths, internal notes, and possibly secrets, silent automatic transmission materially increases privacy and data-leak risk.
The code comment says it handles only credential locations, but the actual matcher \bapi[\s_-]?key\b.{5,} can match lines containing real API key values and then upload the full line to the cloud. The skip rules only block some formats like token= and do not reliably prevent secrets embedded in prose, markdown bullets, or api key: ... lines from being exfiltrated.
The code reads .env files directly to locate SUPERMEMORY_OPENCLAW_API_KEY, which constitutes credential access from local secret storage. In a skill that already processes memory logs and performs network uploads, this combination is more dangerous because the component has both access to secrets and a ready exfiltration path.
Path("/mnt/openclaw/openclaw/.openclaw/workspace"),
]
for d in search_dirs:
env_path = Path(d) / ".env"
if env_path.exists():
for line in env_path.read_text().splitlines():
line = line.strip()
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"
# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"
# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"
# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"
# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"
# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"
# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
os.path.expanduser("~/.openclaw/workspace"),
]
for d in search_dirs:
env_path = os.path.join(d, ".env")
if os.path.isfile(env_path):
with open(env_path) as f:
for line in f:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
os.path.expanduser("~/.openclaw/workspace"),
]
for d in search_dirs:
env_path = os.path.join(d, ".env")
if os.path.isfile(env_path):
with open(env_path) as f:
for line in f:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
os.path.expanduser("~/.openclaw/workspace"),
]
for d in search_dirs:
env_path = os.path.join(d, ".env")
if os.path.isfile(env_path):
with open(env_path) as f:
for line in f:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
os.path.expanduser("~/.openclaw/workspace"),
]
for d in search_dirs:
env_path = os.path.join(d, ".env")
if os.path.isfile(env_path):
with open(env_path) as f:
for line in f:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
os.path.expanduser("~/.openclaw/workspace"),
]
for d in search_dirs:
env_path = os.path.join(d, ".env")
if os.path.isfile(env_path):
with open(env_path) as f:
for line in f:
The README expands the skill from manual cloud backup/search into automatic cron-based extraction of OpenClaw session logs, which is materially broader than the stated backup/retrieval scope. That creates a hidden data-flow from potentially sensitive local conversations and artifacts to a third-party cloud service, increasing the risk of over-collection and unintended exfiltration.
Automatically harvesting session logs is not clearly necessary for a skill whose core purpose is manual cloud backup and retrieval. In this context, the unjustified background collection is dangerous because session logs often contain prompts, outputs, file paths, API keys, and other sensitive operational data that users would not expect to be uploaded.
The README describes automatic extraction of session logs to cloud backup without any warning about privacy or data sensitivity. This is dangerous because users may enable the cron job without understanding that confidential conversations, credentials, proprietary code, or personal data could be continuously sent to an external service.
The skill advertises and instructs use of capabilities including environment-variable access, file read/write, network access, shell execution, and cron installation, but it does not declare any explicit tool scope or permissions boundaries. In a skill that uploads memory content to a third-party cloud service and installs scheduled jobs, missing scope declarations weakens reviewability and increases the chance of over-privileged execution or unintended data access.
The skill promotes cloud backup and auto-capture of memory-derived content but does not clearly warn that potentially sensitive user/session data may be sent to a third-party service. In this context, memory logs can easily contain secrets, personal data, internal URLs, tokens, or incident details, so missing consent and sensitivity warnings materially raise privacy and data-handling risk.
The prerequisite section tells users to place an API key in .env but gives no guidance on protecting that credential or preventing secrets from being uploaded through stored memory. In a skill that scans logs and environment-backed configuration, failure to warn about credential hygiene increases the likelihood of accidental exposure of both the API key and unrelated secrets.
No suspicious patterns detected.