T09 · Insecure Skill Coding Practices
- Location
scripts/personal_hooks.py:7705- Finding
Automatic Transmission of Raw User Dialogue to an Unrestricted Embedding Endpoint
- Content
View full analysis
Optional[dict]: if not OPENCLAW_CONFIG_PATH.exists(): return None try: config = json.loads(OPENCLAW_CONFIG_PATH.read_text(encoding="utf-8")) except Exception: return None embedding = ( config.get("plugins", {}) .get("entries", {}) .get("memory-lancedb-pro", {}) .get("config", {}) .get("embedding", {}) ) if not isinstance(embedding, dict): return None api_key = embedding.get("apiKey") if isinstance(api_key, list): api_key = next((str(item).strip() for item in api_key if str(item).strip()), "") api_key = resolve_env_vars(str(api_key or "")).strip() model = str(embedding.get("model") or "").strip() base_url = resolve_env_vars(str(embedding.get("baseURL") or "")).strip() if not api_key or not model or not base_url: return None return { "api_key": api_key, "model": model, "base_url": base_url.rstrip("/"), "dimensions": embedding.get("dimensions"), "task_query": embedding.get("taskQuery"), "task_passage": embedding.get("taskPassage"), "normalized": embedding.get("normalized"), } ``` ```python def jina_embed_inputs(texts: list[str], config: dict, task: Optional[str]) -> list[list[float]]: if not texts: return [] mode = "query" if task and task == config.get("task_query") else "passage" payload = { "texts": texts, "mode": mode, "plugin_root": EMBEDDER_ROOT or None, "config": { "api_key": config["api_key"], "model": config["model"], "base_url": config["base_url"], "dimensions": config.get("dimensions"), ...[truncated 4603 chars]- Remediation
View remediation
