T09 · Insecure Skill Coding Practices
- Location
scripts/factoriago-client.js:98- Finding
Sensitive credentials exposed through command-line arguments
- Content
View full analysis
'); const res = await req('POST', '/auth/login', { email, password }); ``` ```javascript case 'set-llm-config': { const [provider, model, apiKey] = args; if (!provider || !model || !apiKey) { return console.error( 'Usage: set-llm-config \n' + 'Providers: anthropic | openai | google | moonshot | zhipu | minimax\n' + 'Examples:\n' + ' set-llm-config anthropic claude-3-5-sonnet-20241022 sk-ant-xxx\n' + ' set-llm-config openai gpt-4o sk-xxx\n' + ' set-llm-config google gemini-2.0-flash AIza...' ); } if (!cookie) return console.error('❌ Not authenticated.'); const res = await req('POST', '/settings/llm', { primary_provider: provider, primary_model: model, primary_api_key: apiKey, }, cookie); ``` The associated documentation explicitly instructs users to supply secrets this way: ```bash node scripts/factoriago-client.js set-llm-config ``` ```markdown Via AI assistant: Tell your OpenClaw assistant your key and ask it to configure it for you ``` ### Technical Analysis The client obtains the FactoriaGo password and third-party LLM API key from `process.argv`. Command-line arguments may be: - Saved in interactive shell history. - Visible to process-monitoring or diagnostic tools while the command is running. - Captured by terminal session recording, automation logs, or debugging systems. - Retained in Agent prompts, tool-call transcripts, or conversation hi ...[truncated 1979 chars]- Remediation
View remediation
