Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/powwow.js register
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its stated PowPow chat-management purpose, but it stores and prints reusable chat/account tokens in a local plaintext file, which users should review before installing.
Install only if you are comfortable with PowPow account tokens and digital-human webhook tokens being saved in a local plaintext credentials.json file and displayed in terminal output. Treat that file and any copied plugin config as secrets; do not commit or share them, and prefer using this on a private machine/account.
Referenced artifact was not completely inspected
node scripts/powwow.js register
Referenced artifact was not completely inspected
node scripts/powwow.js register
Referenced artifact was not completely inspected
node scripts/powwow.js register
This line explicitly states that login credentials are stored locally in credentials.json. Storing authentication material in a local file without any stated protection mechanism raises a real credential-exposure risk, especially on shared machines or when the file is accidentally included in backups, logs, or source control.
# 1. 注册(输出引导链接,浏览器完成;一辈子一次)
node scripts/powwow.js register
# 2. 登录(凭据保存在本机 credentials.json)
node scripts/powwow.js login --username <你的邮箱或用户名> --password <你的密码>
# 3. 创建数字人(自动生成 webhookToken,输出渠道插件安装引导与配置)
The skill states that the webhookToken is automatically generated and stored in credentials.json. That token appears sufficient to post as the digital human and possibly read or send chat data, so leakage would allow impersonation and unauthorized interaction with visitors.
"powpow": {
"enabled": true,
"digitalHumanId": "<create 返回的 ID>",
"webhookToken": "<自动生成,已存 credentials.json>",
"dmPolicy": "open",
"pollIntervalMs": 3000
}
The troubleshooting guidance normalizes reading tokens from credentials.json for authentication recovery, reinforcing a workflow that depends on locally stored reusable secrets. In context, this increases the likelihood that users will manually handle, copy, or expose tokens, making compromise and impersonation more likely.
| HTTP 401 | 登录过期(Token 24h),重新执行 login |
| HTTP 402 | 徽章不足,用 status 查余额,通过活动/订阅获取 |
| chat history 401 | 历史接口已鉴权:确认已登录,或该数字人经本 skill 创建(token 在本机);否则用 `--token` 传入 |
| chat send 401 | webhookToken 与平台不一致——核对 `--token` / 本机 credentials.json,或重新创建数字人 |
| HTTP 410 | 数字人已过期(1 徽章 = 30 天,续费后恢复),到平台续期 |
| 数字人不回复 | 确认渠道插件已安装、配置中 digitalHumanId/webhookToken 正确、数字人未过期 |
| 拉不到历史 | 确认数字人 ID 正确(list 命令核对)+ 已登录或有 token |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* PowPow Agent Skill CLI
* 把 OpenClaw agent 放上泡泡地图:登录 / 创建数字人 / 管理订阅 / 与地图访客对话
* 零依赖(Node 18+ 原生 fetch);凭据保存在 skill 根目录 credentials.json(勿提交/发布)
*/
'use strict';
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* PowPow Agent Skill CLI
* 把 OpenClaw agent 放上泡泡地图:登录 / 创建数字人 / 管理订阅 / 与地图访客对话
* 零依赖(Node 18+ 原生 fetch);凭据保存在 skill 根目录 credentials.json(勿提交/发布)
*/
'use strict';
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
/**
* PowPow Agent Skill CLI
* 把 OpenClaw agent 放上泡泡地图:登录 / 创建数字人 / 管理订阅 / 与地图访客对话
* 零依赖(Node 18+ 原生 fetch);凭据保存在 skill 根目录 credentials.json(勿提交/发布)
*/
'use strict';
Defining a fixed credentials.json path in the skill root establishes a plaintext local secret store for login tokens and webhook tokens. Storing reusable authentication material in a predictable project file materially increases exposure to accidental source control inclusion, local file disclosure, and misuse by other local processes or users.
const BASE_URL = (process.env.POWPOW_API_BASE || 'https://global.powpow.online').replace(/\/+$/, '');
const SINK_URL = `${BASE_URL}/api/openclaw/webhook/sink`;
const CRED_FILE = path.join(__dirname, '..', 'credentials.json');
const CHANNEL_PLUGIN = 'clawhub:@durenzidu/openclaw-channel-powpow';
// ----------------------------------------------------------------------------
The CLI prints the webhookToken to stdout after creation. This token appears to authorize chat history access and message sending as the digital human, so exposing it in terminal logs, CI logs, transcripts, or shell history can enable account impersonation and unauthorized message access.
`位置: ${body.locationName} (${body.lat}, ${body.lng})`,
`有效期至: ${expiresAt}(30 天,续期 1 枚徽章)`,
`剩余徽章: ${badgesRemaining} 枚`,
`WebhookToken(已保存到本机 credentials.json): ${webhookToken}`,
'',
'在地图上查看: ' + BASE_URL + '/map',
'',
The skill documentation describes capabilities that require environment-variable access and network communication, but it does not declare any explicit tool scope or allowed-tools boundary. This creates an authorization ambiguity where a host agent may grant broader access than users expect, increasing the chance of unintended credential use or external communication.
The skill's instructional content is presented in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy when a specific language is imposed without user opt-in or clear justification.
The skill instructs users that login credentials and webhook tokens are stored locally in credentials.json, but provides no warning about file permissions, plaintext storage, rotation, or secure handling. If that file is readable by other local users, backup systems, or other tools, an attacker could reuse the account token or webhook token to access chat history or impersonate the digital human.
The script persists bearer tokens and webhook tokens to credentials.json in the skill directory without setting restrictive file permissions, encrypting the data, or presenting a runtime warning/consent at the write point. Local plaintext credential storage increases the chance of token theft through accidental commits, backup leakage, shared workstations, or other local compromise.
cmdLogin collects credentials from flags or environment variables and transmits them with a POST request to /api/openclaw/auth/login. While login logically requires a network request, this function provides no runtime disclosure that the supplied credentials are being sent to an external service.
Detected: suspicious.secret_argv_exposure