T09 · Insecure Skill Coding Practices
- Location
SKILL.md:13- Finding
Plaintext Storage of High-Impact OKX Trading Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13–22
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: HighVulnerable Code
markdown ### Setup Credentials Save to `~/.openclaw/credentials/okx.json`: ```json { "apiKey": "YOUR_API_KEY", "secretKey": "YOUR_SECRET_KEY", "passphrase": "YOUR_PASSPHRASE" }text ### Technical Analysis The setup instructions direct users to persist an OKX API key, signing secret, and passphrase in a plaintext JSON file. They do not require restrictive file permissions, verify file ownership, recommend encryption or a secret manager, or warn users against backups and accidental disclosure. These are high-impact credentials because the documented integration supports authenticated balance and position queries, spot and futures orders, leveraged trading, order cancellation, position closure, and leverage changes. The actual request helper consumes environment variables rather than the documented JSON file, so retaining a second plaintext credential copy is not required by the demonstrated implementation and exceeds minimum privilege and data-retention needs. This does not establish intentional credential theft: the reviewed content sends authentication values only to the declared OKX endpoint. Nevertheless, insecure local storage creates an avoidable credential-disclosure path. ### Attack Path 1. A user follows the setup instructions and writes valid OKX credentials to `~/.openclaw/credentials/okx.json`. 2. The file is created using default filesystem permissions, with no mandatory `0600` protection or ownership validation. 3. Another local user, compromised process, malicious Skill, backup service, or overly broad synchronization tool obtains read access to the file. 4. The attacker extracts the API key, signing secret, and passphrase. 5. The attacker uses those values to sign direct OKX V5 API requests. 6. Subject to th ...[truncated 936 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the plaintext JSON credential-storage instruction because the documented request helper already uses environment variables.
- Prefer an operating-system keychain, dedicated secret manager, or runtime secret injection mechanism.
- If file-based storage is unavoidable:
- Create
~/.openclaw/credentialswith mode0700. - Create
okx.jsonwith mode0600. - Verify that the current user owns both the directory and file.
- Refuse to use credentials when permissions or ownership are unsafe.
- Exclude the file from source control, cloud synchronization, diagnostics, logs, and unencrypted backups.
- Create
- Use a dedicated OKX API key with only the permissions required by this Skill.
- Disable withdrawal permissions and unrelated account-management permissions.
- Configure an exchange-side IP allowlist where operationally possible.
- Use separate demo and production credentials, defaulting to demo trading.
- Document credential rotation and immediate revocation procedures.
- Avoid printing secrets, authentication headers, signed requests, or the credential file contents during debugging and error handling.
