T09 · Insecure Skill Coding Practices
- Location
scripts/configure.mjs:39- Finding
Sensitive credential files are created without restrictive permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Asana skill is mostly purpose-aligned, but it has real credential-handling and live-data mutation risks that users should review before installing.
Install only if you are comfortable giving the skill access to your Asana account and letting it modify live tasks. Prefer environment variables or a secret manager over saved plaintext files, avoid passing secrets on the command line, restrict permissions on ~/.openclaw/asana, and use a low-privilege Asana token or test workspace when possible.
scripts/configure.mjs:39Sensitive credential files are created without restrictive permissions
SKILL.md:34Documented command-line authentication flow exposes secrets through process arguments
scripts/asana_api.mjs:342Task search forwards authentication and control flags into the request URL
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Recommended auth
Use a Personal Access Token (PAT).
Supported auth order:
1. `ASANA_PAT` env var
Referenced artifact was not completely inspected
node scripts/oauth_oob.mjs authorize --client-id "$ASANA_CLIENT_ID"
Referenced artifact was not completely inspected
node scripts/oauth_oob.mjs authorize --client-id "$ASANA_CLIENT_ID"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
function credentialsPath() {
return path.join(asanaDir(), 'credentials.json');
}
function loadJsonIfExists(p, fallback = {}) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
function credentialsPath() {
return path.join(asanaDir(), 'credentials.json');
}
function loadJsonIfExists(p, fallback = {}) {
The markdown documents that configuration, credentials, and token files are stored under the user's home directory, but it does not warn that these files contain sensitive authentication material. For a skill handling PATs and OAuth secrets, omitting a user-facing warning about protecting or securing those files is a meaningful safety disclosure gap.
The skill exposes capabilities that can access environment variables and make network calls, but it does not declare any explicit tool scope such as permissions or allowed-tools. That weakens policy enforcement and user awareness, increasing the chance the skill can access secrets or perform remote actions beyond what operators expected.
The skill is designed around persistent local storage of authentication state, including PATs and OAuth tokens, which creates session persistence beyond a single invocation. While common for API integrations, persistent auth material increases exposure if the host is compromised or if multiple users/processes can access the same home directory.
---
name: asana
description: "Manage Asana via the Asana REST API. Use when you need to list workspaces, projects, tasks, search tasks, comment, update, complete, or create tasks."
metadata:
openclaw:
homepage: "https://developers.asana.com/docs"
The skill instructs users to store PAT/OAuth credentials in local files under ~/.openclaw/asana without an explicit warning that these are sensitive secrets. Storing API tokens locally without handling guidance raises the risk of credential leakage through weak file permissions, backups, shared machines, or accidental disclosure.
The command list includes state-changing operations such as update-task, complete-task, comment, and create-task, but it does not clearly warn that these commands will modify live Asana data. In an agent setting, that omission can lead to unintended writes to production workspaces or tasks if a user assumes the commands are read-only or merely demonstrative.
The flagged commands (update-task, complete-task, comment, and create-task) immediately perform authenticated state-changing requests against the Asana API with no confirmation prompt, dry-run mode, or explicit safeguard. In an agent/tooling context, this increases the risk of unintended remote writes from prompt injection, user misunderstanding, or argument mix-ups, especially because the script is designed to act on live project-management data.
The script saves the full OAuth token response to ~/.openclaw/asana/token.json and logs only the file path. While the operation is commented and printed, there is no user-facing warning that sensitive access credentials will be persisted locally, which is a safety-relevant file write involving secrets.
The script reads ASANA_CLIENT_SECRET from the environment to perform the token exchange, but provides no warning or explanatory note that a secret credential will be consumed from environment variables. The existing usage text shows how to set it, but does not disclose the sensitivity or handling implications of that secret.
The script sends the authorization code, client ID, and client secret to Asana's token endpoint. Although this is expected for OAuth, the file does not provide a user-facing warning that sensitive data will be transmitted over the network as part of the token exchange.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal