T09 · Insecure Skill Coding Practices
- Location
SKILL.md:19- Finding
ERP bearer token can be transmitted to an unrestricted environment-configured destination
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 19–38
Vulnerability Type: Unrestricted credential destination
Risk Level: HighVulnerable Code
javascript const ERP_TOKEN = process.env.ERP_API_TOKEN; const ERP_BASE_URL = process.env.ERP_API_BASE_URL; const erpQuery = async (table, params = {}) => { const url = `${ERP_BASE_URL}/v1/${table}/lists`; const body = { page: 1, pagenum: 50, like: {}, where: {}, order: {}, ...params }; const response = await fetch(url, { method: 'POST', headers: { 'Content-Type': 'application/json', 'authorization': `Bearer ${ERP_TOKEN}` }, body: JSON.stringify(body) }); return await response.json(); };Technical Analysis
The Skill reads a sensitive bearer credential from
ERP_API_TOKENand attaches it to requests sent to a URL derived entirely fromERP_API_BASE_URL. Sending a credential over the network is necessary for the declared ERP-query functionality, but allowing an unrestricted environment value to determine the credential recipient exceeds minimum privilege.The implementation does not validate:
- The destination hostname against an approved allowlist.
- Whether the URL uses HTTPS.
- Whether the URL contains embedded credentials or an unexpected port.
- Whether redirects can forward the request to another origin.
- Whether the configured destination is authorized to receive the ERP token.
Environment variables are not inherently trusted security boundaries. Configuration tampering, deployment mistakes, or a compromised configuration file could redirect requests to an attacker-controlled server. The request body can also expose order numbers, customer or supplier search terms, inventory models, and other sensitive ERP filters.
Attack Path
- An attacker or compromised deployment process modifies
ERP_API_BASE_URLin the runtime environment or referencedopenclaw.jsonconfiguration. - The value is changed to a ...[truncated 1307 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse
ERP_API_BASE_URLwith a standard URL parser before issuing any request. - Require the
https:scheme and reject plaintext HTTP. - Allowlist the exact production ERP hostname and, if applicable, the expected port and base path.
- Reject URLs containing embedded usernames or passwords, fragments, unexpected ports, or non-approved origins.
- Disable automatic redirects or validate every redirect target before following it. Never forward authorization credentials across origins.
- Bind the token to the intended ERP audience and use narrowly scoped, read-only permissions for a query-only Skill.
- Prefer short-lived credentials and implement rotation and revocation procedures.
- Keep the token out of logs, exception messages, telemetry, and debugging output.
- Separate credentials by environment so development or test services cannot use production tokens.
- Consider moving authenticated ERP communication into a trusted backend proxy that enforces the destination, route allowlist, request schema, and response limits.
- Parse
