Credential Access
- Category
- Privilege Escalation
- Confidence
- 90% confidence
- Finding
The authentication section instructs the agent to use a service account to sign JWTs and exchange them for access tokens to a specific Google Sheets target. While this is framed as intended functionality, it is still credential-access behavior, and in this context it is dangerous because the skill also provides the credential location and a live spreadsheet identifier, enabling direct access to external data if abused.
- Content
md ## Authentication - Service account: `/home/hobopi/.openclaw/secrets/google-service-account.json` - JWT flow: sign with RSA256, exchange for access token - Sheet API: `https://sheets.googleapis.com/v4/spreadsheets/{id}` - Spreadsheet ID: `1Ikbydh-Xzc6F3pk1Q5lbCTbdEERSb4Hq8obzbABVZbU`
