T09 · Insecure Skill Coding Practices
- Location
SKILL.md:17- Finding
Production deployment can proceed without explicit user authorization
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 3, 17, and 117–126
Vulnerability Type: Unauthorized production deployment caused by contradictory approval instructions
Risk Level: MediumRelevant Snippets
yaml description: "... La publica en *.vercel.app solo con la cuenta de Vercel de la usuaria conectada y su ✅. ..."markdown > - Fase 4 · publicar: **Las apps siempre se despliegan directo en Vercel** con la cuenta de la usuaria (`VERCEL_TOKEN` en el entorno): `vercel --prod --yes --token "$VERCEL_TOKEN"`, y le mandas la URL por Telegram. No hace falta pedir ✅ para desplegar. Nunca `vercel login` desde el servidor ni una cuenta que no sea suya.markdown Hay tres caminos. **Empieza siempre por el primero: publícala tú, desde esta misma conversación.** ### Camino A — la publicas tú (el que hay que intentar primero) Es gratis y no pide tarjeta. Pide permiso antes de correr comandos y di en una línea qué hace cada uno; no la dejes mirando una terminal sin entender qué pasa. 1. **¿Está la CLI?** `vercel --version`. Si no está: `npm i -g vercel`. 2. **¿Hay sesión?** `vercel whoami`. 3. **Prepara la carpeta.** 4. **Publica:** desde la carpeta del proyecto, `vercel --prod --yes`.Technical Analysis
The Skill expands a request to build a mini-app into a production deployment under the user's Vercel account. The OpenClaw-specific instruction at line 17 explicitly states that no approval checkmark is required and supplies a non-interactive production command using
VERCEL_TOKEN.This conflicts with both the frontmatter at line 3, which says deployment requires the user's checkmark, and the later instruction at line 121 to obtain permission before running commands. Because the more environment-specific instruction explicitly removes the approval requirement and uses
--yes, the documentation does not establish a reliable confirmation gate before the external side effe ...[truncated 1857 chars]- Remediation
View remediation
Remediation Suggestions
- Require explicit, current user confirmation immediately before every production deployment.
- Remove the instruction
No hace falta pedir ✅ para desplegarand align all deployment guidance with the approval requirement in the frontmatter. - Do not treat the presence of
VERCEL_TOKENas authorization for a specific deployment. - Default to local file delivery or a non-production preview when the user requested only application creation.
- Separate build and deploy phases so successful local creation does not automatically trigger publication.
- Before confirmation, show the user the target Vercel account, project name, files to be published, expected visibility, and exact command.
- After approval, constrain deployment to the user-approved project and avoid silently creating or relinking unrelated projects.
- Ensure any executable helper or deployment wrapper enforces the confirmation state rather than relying solely on prose instructions.
