T09 · Insecure Skill Coding Practices
- Location
src/config.ts:54- Finding
Device API Keys and Passwords Are Persisted in Plaintext Without Enforced Access Restrictions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real Daikin AC controller, but it stores device credentials locally and can send network traffic to user-supplied addresses, so it should be reviewed before installation.
Install only if you are comfortable with this skill controlling HVAC devices on your network and storing AC IPs plus any API keys or passwords in a local JSON file. Use it only on networks and devices you own or administer, avoid shared workspaces for real credentials, and prefer a version that validates local device addresses, clears credentials when changing IPs, restricts file permissions, and pins dependencies.
src/config.ts:54Device API Keys and Passwords Are Persisted in Plaintext Without Enforced Access Restrictions
src/tools/devices.ts:273Unvalidated Device Destinations Permit Arbitrary Network Targeting and Credential Redirection
The skill description presents the capability as simple AC control, but the documented behavior also includes device inventory management and handling of sensitive data such as IP addresses, API keys, and passwords. That mismatch can cause users to disclose credentials and network-identifying information without clear informed consent, and it broadens the skill from control into persistent secret management.
The skill description presents the capability as simple AC control, but the documented behavior also includes device inventory management and handling of sensitive data such as IP addresses, API keys, and passwords. That mismatch can cause users to disclose credentials and network-identifying information without clear informed consent, and it broadens the skill from control into persistent secret management.
The skill description presents the capability as simple AC control, but the documented behavior also includes device inventory management and handling of sensitive data such as IP addresses, API keys, and passwords. That mismatch can cause users to disclose credentials and network-identifying information without clear informed consent, and it broadens the skill from control into persistent secret management.
The skill states that configuration is stored in data/devices.json and the documented fields include IP addresses, location identifiers, API keys, and passwords, but the user-facing description does not clearly warn that this sensitive configuration persists across sessions. Persisting secrets and network metadata without explicit disclosure increases privacy risk and can expose home network details or device credentials if the storage is later accessed by other components or users.
This file performs persistent file writes to devices.json and is also used by methods that remove device records, but the code provides no confirmation prompt and no user-facing disclosure beyond internal error logging. For code files, safety-relevant data modification operations should have some visible warning, comment, or documented disclosure unless clearly covered elsewhere.
The skill exposes additional actuator functionality beyond the stated description by allowing powerful, econo, streamer, and holiday mode changes. Scope drift in a control skill is dangerous because policy, user-consent, and downstream agent routing may rely on the manifest text; an agent or user expecting only basic HVAC controls could unintentionally trigger higher-impact or privacy/energy-relevant behaviors.
This code removes a configured device via config.removeDevice(...), which is a destructive operation affecting saved user configuration. The function provides only a success message after deletion and includes no prior confirmation prompt, warning comment, or other disclosure in this file that the action is irreversible.
This tool performs local network discovery and returns sensitive network identifiers including private IP addresses and MAC addresses. In an agent context, that can disclose internal topology and device identity information to users or downstream systems without any explicit consent, warning, or minimization, which increases privacy and reconnaissance risk.
The README explicitly promotes automatic device discovery by scanning the local network via UDP broadcast, but it does not warn users that invoking discovery performs active network probing. In a smart-home skill this is expected functionality, but the lack of disclosure can still create privacy and policy concerns, especially in managed or sensitive networks where unsolicited scanning may be unexpected or disallowed.
The runtime dependency daikin-ts is specified with a caret range, which allows newer compatible releases to be installed without explicit review. This increases supply-chain risk because a compromised or breaking upstream release could be pulled into the skill and affect production behavior.
"author": "",
"license": "GPL-3.0",
"dependencies": {
"daikin-ts": "^1.0.0"
},
"devDependencies": {
"@types/node": "^20.10.0",
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"daikin-ts": "^1.0.0"
},
"devDependencies": {
"@types/node": "^20.10.0",
"typescript": "^5.3.0",
"vitest": "^1.0.0"
},
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
},
"devDependencies": {
"@types/node": "^20.10.0",
"typescript": "^5.3.0",
"vitest": "^1.0.0"
},
"openclaw": {
vitest is unpinned and has known advisories in some versions, so allowing a floating compatible version increases the chance of pulling in a vulnerable release during development or CI. Although it is a dev dependency, compromise here can still affect the build/test environment and potentially the software supply chain.
"devDependencies": {
"@types/node": "^20.10.0",
"typescript": "^5.3.0",
"vitest": "^1.0.0"
},
"openclaw": {
"skill": {
The manifest includes vitest without an exact version, and the analyzer notes multiple known advisories affecting some Vitest releases. Because the actual installed version cannot be verified from this file, there is credible supply-chain and development-environment risk if an affected version is resolved.
This code constructs a device connection using optional key/password credentials and then performs network communication via DaikinFactory(...) and device.updateStatus(). There is no confirmation prompt, logging, comment, or docstring in this file disclosing that the skill connects to a device over the network and may use supplied credentials.
This code binds a UDP socket, enables broadcast, and sends discovery messages across local network broadcast addresses. While this appears to be the skill's intended function, the file contains no confirmation prompt, user-facing log, or explanatory comment/docstring warning that local network traffic will be generated.
No suspicious patterns detected.