T09 · Insecure Skill Coding Practices
- Location
SKILL.md:84- Finding
Credential Archives Are Stored and Potentially Transmitted Without Encryption
- Content
View full analysis
压缩包.sha256` 3. **邮件通知**(如配置了邮件功能): a. 尝试发送邮件附件 ``` The security section acknowledges the sensitivity but does not require encryption: ```text - 备份包含 `credentials/` 目录,请妥善保管备份文件 - 建议对备份存储位置设置适当权限 ``` ### Technical Analysis The Skill directs the Agent to copy the entire `~/.openclaw/credentials/` directory into a standard ZIP archive. It then permits that archive to be sent as an email attachment. ZIP compression alone does not provide confidentiality, and the generated SHA-256 file only verifies integrity; it does not encrypt the archive or prevent unauthorized disclosure. Reading credentials is functionally related to a complete system-state backup. However, including credentials by default and transmitting them through email creates exposure beyond the minimum privileges necessary for ordinary configuration, workspace, or state backup. The Skill provides only advisory language about permissions and does not mandate restrictive filesystem modes, authenticated encryption, secure key management, recipient validation, or explicit consent specifically covering credential export. This is especially dangerous because the archive also contains identity, agent, messaging, workspace, and configuration data. Consequently, one compromised backup can expose several security domains si ...[truncated 1495 chars]- Remediation
View remediation
