T09 · Insecure Skill Coding Practices
- Location
SKILL.md:157- Finding
Persistent Plaintext Storage of an API Token
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:157
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Mediumbash export MINERU_TOKEN="your_api_key_here"Technical Analysis
The Skill documentation recommends assigning the MinerU API token through a persistent shell configuration file or the OpenClaw configuration. Although using an environment variable avoids embedding the token directly into API commands, placing its plaintext value in a shell startup file or inadequately protected application configuration leaves the credential readable at rest.
Any process or account capable of reading the relevant configuration file could recover the token. It may also be exposed through workstation backups, diagnostic bundles, accidental repository commits, configuration synchronization, or disclosure of the user's home directory.
Attack Path
- A user follows the documented guidance and stores a valid MinerU token in a persistent configuration file.
- An attacker, malicious local process, compromised backup service, or unintended repository recipient obtains read access to that file.
- The attacker extracts the value assigned to
MINERU_TOKEN. - The attacker supplies the stolen token in the
Authorization: Bearerheader when calling the MinerU API. - The API accepts requests under the victim's account until the credential is revoked or expires.
Impact Assessment
Exploitation requires access to the configuration file or a copy of it; the documented instruction does not independently grant such access. A recovered token could permit unauthorized MinerU API requests within the permissions and service limits associated with the token, potentially causing quota consumption, financial cost, unauthorized task submission, and access to API resources available to that credential. This issue does not provide operating-system privilege escalation by itself.
- Remediation
View remediation
Remediation Suggestions
- Prefer an operating-system keychain, OpenClaw secret store, or dedicated secrets manager instead of storing the token directly in a shell startup file.
- If file-based storage is unavoidable, use a dedicated credential file outside the project directory and restrict it to the owning user, such as with permissions equivalent to
0600. - Add explicit guidance never to commit credentials to source control, synchronize them through untrusted services, include them in support bundles, or place them in shared shell profiles.
- Keep only a placeholder in documentation and configuration templates.
- Use narrowly scoped and short-lived credentials where the MinerU service supports them.
- Rotate the token immediately if its configuration file is accidentally disclosed, committed, or copied to an untrusted location.
- Configure secret scanning and repository ignore rules to detect or prevent accidental token commits.
