T09 · Insecure Skill Coding Practices
- Location
scripts/setup.sh:22- Finding
Telegram bot token is exposed through command-line arguments and stored without enforced restrictive permissions
- Content
View full analysis
&1 echo "OK (${CONFIG_FILE})" ``` The README also recommends supplying the secret directly on the command line: ```bash bash ~/.openclaw/workspace/skills/neverdie/scripts/setup.sh \ --telegram-token YOUR_BOT_TOKEN \ --chat-id YOUR_CHAT_ID \ --hostname my-openclaw \ --timezone America/New_York ``` ### Technical Analysis The setup interface accepts the Telegram bot token as a command-line argument. Depending on the operating system and shell configuration, command-line secrets may be exposed through: - Shell history files. - Process listings while setup is running. - Process-monitoring or auditing systems. - Terminal logs and copied command transcripts. The token is subsequently written in plaintext to `.neverdie-config.json`. The `fs.writeFileSync()` call does not specify a restrictive file mode, and the setup script does n ...[truncated 1997 chars]- Remediation
View remediation
