T09 · Insecure Skill Coding Practices
- Location
assets/cron/jobs.template.json:15- Finding
Trading API Key Stored in a Persistent Cron Job Payload
- Content
View full analysis
Vulnerability Details
File Location:
assets/cron/jobs.template.json:15andreferences/trading-playbook.md:32
Vulnerability Type: Plaintext credential storage in persistent automation configuration
Risk Level: HighRelevant code:
json "payload": { "kind": "agentTurn", "message": "...执行本任务时涉及的占位符:\n- PolySports API Key: __POLYSPORTS_API_KEY__\n- Telegram target: telegram:__TELEGRAM_CHAT_ID__\n- 所有 PolySports 请求都必须显式带 `X-PolySports-Api-Key`、`X-PolySports-Skill: polysports-trading-agent`、`X-PolySports-Client: chatgpt`..." }markdown - Fill placeholders such as `__POLYSPORTS_API_KEY__`, `__TELEGRAM_CHAT_ID__`, and `__POSITION_SIZE_USDC__` before enabling a job.Technical Analysis
The cron template places
__POLYSPORTS_API_KEY__directly inside the persistentpayload.message, and the playbook instructs the operator to replace that placeholder before enabling the job. Following these instructions results in a reusable trading credential being stored as plaintext within an OpenClaw cron definition.Persistent task definitions can be exposed through cron administration interfaces, configuration files, job exports, backups, debugging output, agent execution transcripts, or logs. The template also sets
enabledtotrueanddeleteAfterRuntofalse, so the job and its embedded credential are intended to remain available across runs.The scheduled workflow reads balances, positions, authorization state, and markets and may place real trades. Consequently, exposure of the credential is more serious than disclosure of a read-only integration token. The precise impact depends on the scopes and trading authorization associated with the API key.
Attack Path
- A user or operator replaces
__POLYSPORTS_API_KEY__with a real API key as instructed. - OpenClaw stores the resulting cron job, including the plaintext key in
payload.message. - An attacker gains read access to ...[truncated 960 chars]
- A user or operator replaces
- Remediation
View remediation
Remediation Suggestions
- Never place the actual API key in
payload.message, command-line arguments, delivery messages, or other persistent job metadata. - Store credentials in a dedicated secret manager or protected OpenClaw credential binding.
- Put only an opaque secret reference in the cron definition and resolve it at execution time.
- Prevent secrets from appearing in job exports, administrative views, debug output, model context, and execution logs.
- Use separate automation credentials with only the required scopes. A market scan should use read-only permissions unless trading is explicitly enabled.
- Prefer time-limited or time-boxed authorization for short-lived monitoring jobs.
- Ensure short-lived jobs delete both their schedules and any associated credential bindings after completion.
- Provide a documented disable, deletion, and credential-rotation procedure.
- If users have already embedded API keys in cron payloads, delete or sanitize those jobs and rotate the exposed keys.
- Never place the actual API key in
