Credential Access
High
- Category
- Privilege Escalation
- Content
Have the user complete browser authorization and choose their HCTI organization. Do not overwrite an existing `hcti` entry pointing elsewhere. For an existing correct connection, run `openclaw mcp login hcti` to authorize it. Check connectivity with `openclaw mcp doctor hcti --probe`, then ensure the current agent session exposes the HCTI tools before rendering. If it does not, reload the MCP connection or start a new session as supported by the client. Installing this skill supplies instructions; it does not automatically register or authorize the MCP server. Use the client's OAuth credential storage, and never copy access tokens into skill files, shell commands, or chat. If the installed OpenClaw version lacks these MCP commands, consult its supported connection setup or update it before proceeding. HTML, CSS, target URLs, template values, and rendering options are processed by the hosted HCTI service. See [HCTI MCP documentation](https://docs.htmlcsstoimage.com/integrations/mcp/) and [OpenClaw MCP setup](https://docs.openclaw.ai/cli/mcp/registry).
- Confidence
- 70% confidence
- Finding
- Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
