T09 · Insecure Skill Coding Practices
- Location
scripts/shared/storage/base.js:28- Finding
Unencrypted Private Keys Stored Without Enforced Owner-Only Permissions
- Content
View full analysis
entry.alias === args.alias); if (index >= 0) { keys[index].privateKeyHex = args.key; } else { keys.push({ alias: args.alias, privateKeyHex: args.key }); } await this.writeFile(keys); } ``` The containing directory is also created without an explicit restrictive mode: ```js // scripts/shared/storage/base.js:8-11 async ensureDirectory() { const dir = path.dirname(this.filePath); await fs.mkdir(dir, { recursive: true }); } ``` ### Technical Analysis `KeysFileStorage` serializes private keys as plaintext JSON entries in `$HOME/.openclaw/billions/kms.json`. The generic storage implementation creates the directory and writes the temporary file without specifying owner-only permission modes. The resulting permissions depend on the process umask. Under a common `0022` umask, the directory may be created as `0755` and the key file as `0644`, allowing other local users to traverse the directory and read the unencrypted private keys. The implementation also does not correct insecure permissions on pre-existing directories or files. The temporary file `${this.filePath}.tmp` contains the same sensitive data and is subject to the same permissions. Although renaming the temporary file reduces partial-write risk, it does not protec ...[truncated 1470 chars]- Remediation
View remediation
