T09 · Insecure Skill Coding Practices
- Location
SKILL.md:56- Finding
Documentation Encourages Plaintext Storage of Reusable Service Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears purpose-aligned, but it handles third-party credentials, sends audio through external services, persists configuration, and has avoidable security weaknesses that users should review before installing.
Review this before installing. Use least-privilege Feishu and Volcengine credentials, avoid putting real secrets in the JSON config, restrict any local secret file permissions, and assume test operations contact Volcengine and Feishu. Avoid running the script as root or on shared machines until the temporary-file handling is fixed.
SKILL.md:56Documentation Encourages Plaintext Storage of Reusable Service Credentials
scripts/voice-config.sh:299Predictable Shared Temporary Files Permit Symlink-Based File Overwrite
The README explicitly promotes generating test audio and sending it to Feishu, but it does not clearly warn users that synthesized voice content will be transmitted to a third-party messaging platform. This can lead to unintentional disclosure of sensitive prompts, personal data, or internal content during testing, especially in an agent-skill context where users may assume local-only processing.
The README shows API keys, app secrets, and user IDs stored in a local JSON config file without an explicit warning that these are sensitive credentials. Users may copy this pattern directly, increasing the chance of secrets being left in plaintext on disk, accidentally committed to repositories, or exposed through backups and logs.
The README explicitly instructs users to export sensitive credentials such as API keys and app secrets into shell startup files and to place secrets into a config file, but provides no warning about secure storage, file permissions, secret rotation, or avoiding accidental commits/logging. This can lead to credential exposure through shell history, inherited environment variables, readable dotfiles, process inspection, backups, or checked-in config files, especially in shared or developer workstation environments.
The trigger phrases are broad natural-language terms like '设置音色' and '默认音色' that can plausibly appear in ordinary conversation, increasing the chance the skill activates without clear user intent. In a skill that can write configuration and send external test audio, accidental invocation can lead to unintended state changes or outbound actions.
The skill clearly describes saving configuration, using API credentials, and sending generated audio to Feishu, but it does not present a centralized, explicit risk notice about secret handling, local file modification, and data egress. This makes users less likely to understand that invoking the skill may persist changes and transmit content to third-party services.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
## 配置文件位置
- **主配置**: `~/.openclaw/workspace/config/bot-voice-config.json`
- **技能文档**: `~/.openclaw/workspace/skills/bot-voice-config/SKILL.md`
## 自动化脚本
Entries such as '性感魅惑', '娇喘女声', and similar intimate-roleplay labels present potentially sensitive output modes, but the document provides no warning or usage guidance. For markdown skill documentation, omission of user-facing warnings about behavior that may affect safety expectations or appropriateness can be a quality and safety issue.
The script's user-facing comments and command aliases are entirely in Chinese, and later output/help text also assumes Chinese-only interaction. This can violate language/locale policy when a skill forces a specific language without opt-in or justification that it is intended only for a Chinese-language environment.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
return 1
fi
TOKEN=$(curl -sL -X POST 'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal' \
-H 'Content-Type: application/json' \
-d "{
\"app_id\": \"$FEISHU_APP_ID\",
The script sends user-provided text and selected speaker metadata to an external TTS provider, and explicitly disables the markdown filter in the request additions. In this skill context, external transmission is expected, but the lack of consent/validation and deliberate reduction of content filtering increases the risk of sending sensitive or unsafe content to a third party.
print_info "正在生成 TTS 音频..."
RESPONSE=$(curl -sL -X POST 'https://openspeech.bytedance.com/api/v3/tts/unidirectional' \
-H "x-api-key: $VOLC_API_KEY" \
-H "X-Api-Resource-Id: $VOLC_RESOURCE_ID" \
-H 'Content-Type: application/json' \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
print_info "正在发送语音消息..."
SEND_RESPONSE=$(curl -sL -X POST 'https://open.feishu.cn/open-apis/im/v1/messages?receive_id_type=open_id' \
-H "Authorization: Bearer $TOKEN" \
-H 'Content-Type: application/json' \
-d "{
The README presents the skill name, instructions, and in-product usage phrases entirely in Chinese, including example invocations, but does not state that the skill is intentionally limited to Chinese-speaking users or offer an opt-in language choice. This can constitute a language/locale policy issue when a skill appears to enforce a single language by default.
整份技能说明、触发词、示例回复和命令语法均以中文固定呈现,没有说明是否支持其他语言或允许用户按偏好切换语言。按照语言/区域策略,这种默认强制单一语言且未提供用户选择的做法可能构成自然语言政策问题。
This markdown file documents voice options and repeatedly includes ASMR-oriented voices and emotional styles such as '低语 (ASMR)' without any warning about how these styles may produce intimate, suggestive, or privacy-sensitive audio output. Under the markdown-specific warning rule, descriptions that can affect user expectations or content sensitivity should disclose such behavior.
The display name, description, and several keywords are presented only in Chinese, which can amount to forcing a specific language for users who may not have opted into that locale. The file does not indicate that the skill is region-specific or that users can choose another language.
The script updates and overwrites the persistent config file and creates backups via cp/mv/jq, but there is no prior warning in the file header or usage comments that running set will modify files under the user's home directory. Although a success message is printed afterward, the skill lacks advance disclosure in its description/comments about this file-modifying behavior.
The bind command writes to the user's config file and backup file, changing default and bot-specific speaker mappings. The file includes runtime status output, but its top-level description and usage comments do not warn users that invoking bind will persistently alter configuration on disk.
No suspicious patterns detected.