T09 · Insecure Skill Coding Practices
- Location
SKILL.md:23- Finding
Financial API bearer key collected through conversational context
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23-35
Vulnerability Type: Sensitive credential exposure through insecure secret collection
Risk Level: MediumVulnerable Code
markdown > To connect your bank transactions, I need to set up FiBuKI first. > > 1. Go to **https://fibuki.com/clawhub-install** > 2. Create a free account (or log in) > 3. Go to **Settings > Integrations > AI Agents** and create an API key > 4. Paste the key back here > > Free plan includes 50 transactions/month with full API access. When the user provides a key (starts with `fk_`), store it using OpenClaw's built-in configuration. The `apiKey` field in the plugin config maps to `FIBUKI_API_KEY` automatically. Tell the user to restart OpenClaw to load the key.Technical Analysis
The Skill explicitly instructs the user to paste a bearer API key into the conversation. Although the key is subsequently intended to be stored through OpenClaw configuration, it first enters the conversational context.
Conversation history, diagnostic telemetry, application logs, browser history, model context, or other components with access to the session may retain the credential. Prefix validation using
fk_only identifies the expected key format; it does not protect the key, verify its ownership, restrict its privileges, or prevent disclosure.Because the documented API uses the value directly as an authorization bearer token, possession of the key may be sufficient to impersonate the user to the FiBuKI service.
Attack Path
- The Skill tells the user to create a FiBuKI API key.
- The user pastes the plaintext key into the conversation as instructed.
- The key is retained in conversation history, logs, telemetry, or another system that processes agent messages.
- An attacker or unauthorized component obtains access to one of those records.
- The attacker submits requests to
https://fibuki.com/api/mcp...[truncated 758 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not request that users paste bearer credentials into conversational messages.
- Direct users to a dedicated masked secret-entry or plugin-configuration interface.
- Ensure credentials are written directly to an encrypted secret store and never inserted into model context.
- Redact matching secret patterns from logs, telemetry, error messages, and diagnostic exports.
- Avoid echoing the key after entry, including partial values unless a non-sensitive fingerprint is used.
- Support narrowly scoped API keys and request only the permissions required for the selected workflow.
- Document key revocation and rotation procedures.
- Prefer short-lived authorization tokens or an OAuth-style authorization flow where supported.
- If conversational entry cannot be avoided, clearly warn the user about retention risks and immediately remove or redact the original message after secure storage.
