T09 · Insecure Skill Coding Practices
- Location
scripts/credentials.js:22- Finding
Predictable Path-Derived Credential Encryption Key
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its email-marketing purpose, but it needs review because it stores powerful Kit credentials with weak, misdescribed protection and gives the agent broad email/account authority.
Review this before installing if the Kit account has a valuable subscriber list. Use a narrowly scoped Kit credential if possible, avoid entering secrets in command-line arguments, do not connect broad MEMORY.md-style files, keep sends in draft/test mode until you confirm audience, subject, send time, and recipient count, and rotate credentials if you previously stored them with this version.
scripts/credentials.js:22Predictable Path-Derived Credential Encryption Key
scripts/credentials.js:123Unnecessary Collection and Storage of the Kit API Secret
SKILL.md:51Overbroad Access to General Agent Memory Files
INSTALLATION.md:239Installation Commands Expose Credentials in Shell and Process Metadata
scripts/kit-api.js:70Automatic Retries Can Duplicate Non-Idempotent API Operations
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/skills/kit-email-operator/
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/skills/kit-email-operator/
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm ~/.kit-credentials
rm ~/.kit-voice-samples.json
rm ~/.kit-business-context.json
rm ~/.kit-custom-fields.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm ~/.kit-credentials
rm ~/.kit-voice-samples.json
rm ~/.kit-business-context.json
rm ~/.kit-custom-fields.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm ~/.kit-credentials
rm ~/.kit-voice-samples.json
rm ~/.kit-business-context.json
rm ~/.kit-custom-fields.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm ~/.kit-credentials rm ~/.kit-voice-samples.json rm ~/.kit-business-context.json rm ~/.kit-custom-fields.json
**Note:** Your data in Kit (subscribers, broadcasts) is never affected.
Referenced artifact was not completely inspected
Once approved, use `scripts/kit-api.js` to:
Referenced artifact was not completely inspected
Once approved, use `scripts/kit-api.js` to:
Referenced artifact was not completely inspected
Once approved, use `scripts/kit-api.js` to:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
You: "Create a nurture email"
The guide tells users to pass the Kit API key and secret directly on the command line via node scripts/credentials.js store --key="..." --secret="...". Secrets supplied as CLI arguments can be exposed through shell history, audit logs, and process listings to other local users or monitoring tools, which can lead to credential compromise. The surrounding 'security-first' framing makes this more concerning because users may assume the setup is safe end-to-end.
The optional voice training asks users to provide past emails but does not clearly warn about privacy, third-party data, or the possibility of including subscriber PII and confidential business content. That omission can lead users to paste sensitive communications into the system without understanding retention, minimization, or consent implications.
The README promotes sending and scheduling real emails to subscribers without a prominent confirmation/safety warning at the point of action. In an agentic environment, this increases the risk of unintended mass outreach, mis-targeted broadcasts, or premature sends if a user request is ambiguous or the operator assumes approval from conversational context.
The setup guide tells users to invoke the skill with very broad natural-language prompts like 'I want to send an email campaign' and 'Help me write an email to my list' without any explicit activation boundary. In an agentic environment, such generic phrases can cause unintended routing to this skill during ordinary email-assistance requests, increasing the chance of overbroad access to stored credentials, voice-profile data, or outbound email actions when the user did not specifically intend to use this skill.
The post-setup guidance encourages users to 'just ask OpenClaw naturally' with common email-marketing requests, but does not define when this skill should or should not activate. That vagueness makes accidental invocation likely during normal writing help, which can lead the system to access business context, local files, or email-sending capabilities under an overly broad interpretation of user intent.
The skill instructs the agent to collect Kit API credentials and optionally ingest past email samples and business-context files, but it does not require an explicit consent/privacy warning before gathering, analyzing, and persisting that sensitive data. Even if credentials are encrypted at rest, users may unknowingly provide secrets and private communications without clear notice of storage scope, retention, or exposure risks, increasing the chance of accidental disclosure or misuse.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- ✅ Regular list cleaning
3. **Single Opt-In Only**
- ❌ No confirmation required
- ✅ Double opt-in for quality (consider trade-offs)
4. **No Segmentation**
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
❌ **Missing fallback for first_name**
→ Results in "Hey ," if name not provided
❌ **Using custom fields without checking they exist**
→ Displays blank or "null"
❌ **Forgetting unsubscribe link**
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
(Clean break, no hard feelings)
[Auto-Remove Warning]
If I don't hear from you by [deadline], I'll automatically remove you from the list.
[Gratitude]
Thanks for being here, even if it's time to say goodbye.
The docstring says this method will 'Tag a subscriber', implying it will subscribe the given email to the specified tag. However, the code sends the request to '/tags/{tagId}/subscribe' literally rather than interpolating the tagId variable, so it does not perform the documented operation correctly.
The CLI testing paths print full subscriber and broadcast API responses directly to stdout, which can expose sensitive personal or campaign data in terminals, shell history captures, logs, CI output, or shared sessions. In an agent skill context, this is more dangerous because debugging output is often collected automatically and may be visible to other operators or systems.
The uninstall section includes direct rm commands for deleting stored files but does not clearly warn that these actions are irreversible or recommend verifying paths first. While this is standard shell usage, omission of caution in an installation guide increases the chance of accidental data loss by less experienced users.
The README says to "Just ask OpenClaw to help with email marketing" and gives the example "I want to send an email to my list," which is a fairly broad natural-language trigger. In a markdown skill description, this lacks clear scope boundaries or negative examples, so it could encourage unintended invocation for ordinary email-related requests.
This reference includes multiple subject-line formulas that rely on urgency, curiosity gaps, pattern interrupts, and social proof in ways that can encourage deceptive or manipulative email practices if used without guardrails. Although it briefly warns against clickbait and misleading content, that warning is limited and does not clearly address ethical, reputational, or compliance risks of using examples like false scarcity, vague baiting, or misleading personalization.
No suspicious patterns detected.