T09 · Insecure Skill Coding Practices
- Location
config.json:2- Finding
Hardcoded Feishu Application Credentials and Recipient Identifier
- Content
View full analysis
"$CONFIG_FILE" << 'EOF' { "feishu": { "app_id": "YOUR_APP_ID", "app_secret": "YOUR_APP_SECRET", "user_id": "YOUR_USER_OPEN_ID" }, "qclaw": { "health_url": "http://127.0.0.1:28789/health" }, "watchdog": { "check_interval_ms": 180000, "restart_delay_ms": 10000, "max_retries": 3 }, "logs": { "main_log": "./watchdog.log", "command_log": "./commands.log" } } EOF ``` The resulting permissions depend on the user's current `umask`, which may allow other local users to read the secret. ### Attack Path 1. An attacker obtains the Skill archive, repository contents, backup, or another copy of `config.json`. 2. The attacker extract ...[truncated 860 chars]- Remediation
View remediation
