T09 · Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Telegram Bot Token Exposed Through Command-Line URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a documentation-only OpenClaw setup guide whose agent, Telegram, and model-provider steps fit its purpose, though users should tighten credential handling when following the examples.
Install only if you intend to configure additional OpenClaw agents and Telegram bots. Use interactive onboarding where possible, avoid pasting real bot or API tokens directly into shell commands, set auth-profiles.json and openclaw.json to mode 600, and remove OpenRouter fallback or heartbeat entries if you require fully local Ollama-only operation.
SKILL.md:16Telegram Bot Token Exposed Through Command-Line URL
references/troubleshooting.md:92OpenRouter Credential File Created Without Enforcing Restrictive Permissions
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Create two Telegram bots via @BotFather and extract chat IDs:
curl https://api.telegram.org/bot{TOKEN}/getUpdates | jq '.result[0].message.chat.id'
Authenticate agents:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Create two Telegram bots via @BotFather and extract chat IDs:
curl https://api.telegram.org/bot{TOKEN}/getUpdates | jq '.result[0].message.chat.id'
Authenticate agents:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
openclaw onboard
> ⚠️ Never pass API keys directly on the CLI (e.g. `--anthropic-api-key ...`) — it exposes them in shell history. Always use `openclaw onboard` interactively. Credential files (`auth-profiles.json`, `openclaw.json`) should be `chmod 600`.
3. **Configure** `openclaw.json` with two agents, separate bindings, and Telegram accounts.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Common Usage
**Adding a free agent:**
- Create agentDir at `/Users/YOUR_USERNAME/.openclaw/agents/free-agent/agent`
- Add agent entry to `openclaw.json` with `model.primary: "openrouter/..."`
- Create `auth-profiles.json` with OpenRouter API key in agent's directory
- Add binding with unique `accountId` (e.g., `"tg2"`)
The troubleshooting guide explicitly directs users to persist API credentials in a local auth-profiles.json file under the agent directory. Persistent local secret storage is not inherently malicious, but without warnings, permission hardening, or a stronger preference for secret-management mechanisms, it increases the chance of credential theft from disk, backups, or accidental disclosure.
Cause: Missing or incorrectly placed auth-profiles.json.
Fix: Create auth-profiles.json in the free agent's agentDir:
cat > ~/.openclaw/agents/free-agent/agent/auth-profiles.json <<'EOF'
The document instructs users to create an auth file containing an API key in plaintext on disk, but it does not explicitly warn that the file is sensitive secret material or recommend restrictive permissions/secure secret storage. Even though the value shown is a placeholder, the workflow normalizes storing real credentials in a local file, which increases the risk of accidental exposure through backups, screenshots, logs, world-readable permissions, or source control.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
grep -A 2 '"id"' ~/.openclaw/openclaw.json | grep -E 'id|name'
# Test Anthropic auth (uses env var, no key in command)
curl -s https://api.anthropic.com/v1/models \
-H "x-api-key: $ANTHROPIC_API_KEY" \
-H "anthropic-version: 2023-06-01"
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
Inspect active sessions:
ls -la ~/.openclaw/agents/*/store/sessions/
Check recent logs:
No suspicious patterns detected.