T09 · Insecure Skill Coding Practices
- Location
scripts/seedream_cover.py:36- Finding
API Credential Can Be Transmitted to an Unvalidated Configurable Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/seedream_cover.py, lines 36-41 and 73-94
Vulnerability Type: Credential disclosure through insufficient endpoint validation
Risk Level: MediumEvidence
python _CREDENTIALS = _load_credentials() API_URL = _CREDENTIALS.get("endpoint", "https://ark.cn-beijing.volces.com/api/v3/images/generations") API_KEY = _CREDENTIALS.get("api_key", "") MODEL = _CREDENTIALS.get("model", "doubao-seedream-5-0-260128")python headers = { "Content-Type": "application/json", "Authorization": f"Bearer {API_KEY}", } req = urllib.request.Request( API_URL, data=json.dumps(payload).encode("utf-8"), headers=headers, method="POST", ) try: with urllib.request.urlopen(req, timeout=60) as resp: result = json.loads(resp.read().decode("utf-8"))Technical Analysis
The destination receiving the bearer API credential is loaded directly from the credentials file. The code does not require HTTPS, validate the hostname against an allowlist, reject embedded user information, or constrain redirects.
Consequently, a malformed or malicious configuration can set
endpointto an attacker-controlled server or an unencrypted HTTP endpoint. The script then transmits the Seedream bearer token in theAuthorizationheader.This issue requires the credentials file to be misconfigured or modified. It is not an unauthenticated remote compromise by itself. Nevertheless, configuration files are frequently provisioned through automation, copied from examples, or modified by users who may not realize that
endpointcontrols where the secret is sent.Attack Path
- An attacker influences deployment configuration, provisioning instructions, or the contents of
/root/.openclaw/credentials/seedream.json. - The attacker sets
endpointto an attacker-controlled HTTPS URL or an unencrypted HTTP URL. - A user invokes `seed ...[truncated 668 chars]
- An attacker influences deployment configuration, provisioning instructions, or the contents of
- Remediation
View remediation
Remediation Suggestions
- Do not make the credential destination freely configurable unless custom endpoints are an explicit requirement.
- Pin the API hostname to
ark.cn-beijing.volces.com, or enforce a strict allowlist of approved hosts. - Require
httpsand reject HTTP,file, FTP, and other schemes. - Disable automatic cross-origin redirects or validate every redirect target before forwarding the authorization header.
- Separate endpoint configuration from secret storage and apply restrictive file permissions such as mode
0600. - Use a narrowly scoped token with quota limits and rotation support.
- Fail closed when endpoint validation fails, without including the credential in logs or error messages.
- Add tests covering hostile endpoints, insecure schemes, embedded credentials, alternate ports, and redirect-based credential leakage.
