T09 · Insecure Skill Coding Practices
- Location
scripts/security-audit.sh:22- Finding
Credential Scanner Prints Detected Secrets into Agent-Visible Output
- Content
View full analysis
/dev/null | grep -v "SECURITY" | grep -v "KNOWLEDGE" | grep -v "template" | grep -v "example" || true) if [ -n "$MATCHES" ]; then echo "⚠️ Potential credentials found:" echo "$MATCHES" | head -20 ISSUES=$((ISSUES + 1)) else echo "✅ No leaked credentials detected" fi ``` ### Technical Analysis The script recursively searches the workspace for credential-like strings, stores the complete matching lines in `MATCHES`, and prints up to twenty of those lines without redaction. While the scan itself is local and contains no direct network operation, its output may be exposed to: - The AI agent's context and conversation transcript - Tool execution logs - OpenClaw or platform monitoring logs - Users in a shared or incorrectly configured delivery channel - External observability and support systems A matching line can contain the complete secret as well as confidential surrounding content. This behavior also conflicts with the project's own credential-handling guidance, which says that credentials should not be repeated or copied. The exclusions based on filenames are not an adequate security boundary. They may suppress legitimate detections while doing nothing to redact secrets found in other files. ### Attack Path 1. A valid API key, password, bearer token, private key marker, ...[truncated 1240 chars]- Remediation
View remediation
