T09 · Insecure Skill Coding Practices
- Location
SKILL.md:36- Finding
Authentication Secret Exposed in a GET Request URL
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 36–38
Vulnerability Type: Secret exposure through URL query parameters
Risk Level: HighVulnerable Code
http **Add exchange_id=polymarket to order-request**: GET {DECKER_API_URL}/api/v1/link/slack/order-request?slack_user_id={sender_id}&symbol=will-x-win&side=buy&quantity=10&exchange_id=polymarket&outcome=yes&openclaw_secret={OPENCLAW_SECRET}Technical Analysis
The documented request places
OPENCLAW_SECRETdirectly in the query string of a GET request. Although HTTPS protects the URL while it is in transit, query strings are commonly retained by HTTP access logs, reverse proxies, API gateways, monitoring systems, debugging tools, browser history, and error-reporting platforms.A secret embedded in a URL can therefore be disclosed to systems and personnel that do not require access to authentication credentials. This violates secure credential-handling and least-exposure principles. Because the endpoint submits a Polymarket order request, disclosure may expose an authentication capability associated with financially consequential operations.
Attack Path
- The agent constructs the documented GET request containing
OPENCLAW_SECRET. - The complete URL passes through the client, proxy, gateway, application server, or monitoring infrastructure.
- One or more components record the query string in logs or telemetry.
- An attacker or unauthorized operator obtains access to those records.
- The attacker extracts
OPENCLAW_SECRET. - The attacker reuses the secret against endpoints that accept it, subject to the credential's actual privileges and any additional authorization controls.
Impact Assessment
Successful exploitation could disclose an authentication secret and permit unauthorized requests under the affected user's or integration's identity. The precise scope depends on server-side authoriza ...[truncated 212 chars]
- The agent constructs the documented GET request containing
- Remediation
View remediation
Remediation Suggestions
- Replace the state-changing GET request with an HTTPS POST request.
- Transmit credentials in an
Authorizationheader, such as a short-lived bearer token, rather than in the URL. - Do not include secrets in query strings, path parameters, browser-visible links, or generated chat output.
- Configure clients, gateways, application servers, and observability platforms to redact authorization data.
- Use short-lived, narrowly scoped credentials restricted to the required operation, user, and exchange.
- Add nonce, timestamp, expiration, and replay-prevention controls for financially consequential requests.
- Require explicit user confirmation immediately before placing an order.
- Rotate any
OPENCLAW_SECRETthat may already have appeared in URL logs and purge retained copies where feasible.
