T09 · Insecure Skill Coding Practices
- Location
scripts/api_client.sh:18- Finding
Remote Command Injection Through Unsafe SSH Command Construction
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is an API helper, but it ships live-looking credentials and password-based SSH commands that can access sensitive data and modify server state without clear safeguards.
Review this carefully before installing. Treat the exposed API key and SSH password as compromised, rotate them if they are real, and do not use the skill until it requires explicit secrets, removes password-based SSH or tightly scopes it, validates inputs, redacts sensitive fields, and adds confirmation for write operations.
scripts/api_client.sh:18Remote Command Injection Through Unsafe SSH Command Construction
scripts/api_client.sh:8Hardcoded API and SSH Credentials
references/response-format.md:55Overbroad Raw Access to Sensitive API Data and State-Changing Operations
The skill is presented as a simple API client, but its documented behavior includes password-based SSH access, hardcoded credentials, and state-changing operations against an internal service. This mismatch is dangerous because users and policy systems may permit it under a lower-risk assumption while it actually enables authenticated remote access and modification of server state.
The skill exposes a path to local secret storage and includes a concrete secret value in the example, indicating credential material is embedded in documentation. This is a direct credential-access risk because it teaches where secrets live and appears to disclose an actual API key that can be used against the service.
OpenClaw 自动加载 ~/.openclaw/.env 文件中的环境变量:
# ~/.openclaw/.env
HOPE_API_KEY=hope-openclaw-apikey-2026-0411
HOPE_HOST=hope05
HOPE_PORT=8088
The documentation claims configuration is sourced from environment variables, but the quick-call implementation bypasses them with hardcoded values. This is dangerous because it defeats secret-management expectations, encourages credential sprawl, and can silently direct traffic to a fixed internal host regardless of user configuration.
The helper function hardcodes an SSH password, host, username, and API key, then executes a remote curl command. This directly enables credential reuse and unauthorized access to an internal system by anyone who can read or copy the skill, turning documentation into an operational access mechanism.
The skill demonstrates shell-based capabilities through curl/ssh/sshpass examples and helper functions, yet it declares no tool scope or allowed-tools restrictions. This increases the chance that an agent can invoke broader shell behavior than users expect, especially given the presence of authenticated network and remote-access commands.
The markdown publishes a concrete API key value in a sample .env block, which is effectively credential disclosure if the value is real or reused. Exposed secrets can be copied and used to authenticate to the service, especially in an internal environment with limited additional controls.
The examples show secrets being carried in HTTP headers and SSH commands to reach an internal service, but they provide no warning about protecting credentials, shell history exposure, or internal-network sensitivity. In this context, the omission materially increases the chance of unsafe handling of live secrets and broadening access to internal infrastructure.
The documentation instructs use of sshpass and SSH to run remote commands on an internal host, which exceeds the stated role of an API client. Embedding remote-execution guidance normalizes privileged lateral access and can expose internal services and secrets if the skill is adopted as written.
The file is presented as common query examples, but it includes a bulk state-changing command that marks items as cleaned. In an agent skill, users or downstream automation may treat examples as safe read-only operations, so undocumented write actions increase the chance of accidental destructive or workflow-altering use.
The bulk operation example performs state changes without any warning about operational impact, scope, or reversibility. In the context of an API client skill, such examples can be copied directly into automation or interactive sessions, causing unintended bulk data/status modification.
The script reads and uses an SSH password, and even provides a default password value, which is a hardcoded credential and an unnecessary privilege for a nominal API client. This can lead to credential disclosure, unauthorized host access, and lateral movement if the script or environment is exposed.
The script is presented as an API client, but it actually performs remote command execution over SSH and runs curl on the remote host. This expands its privilege and attack surface beyond a normal HTTP client, enabling access to localhost-only services on the remote machine and creating command-injection risk if endpoint, params, method, or data are attacker-controlled.
The script transmits an API key to a remote host and forwards requests to a localhost-bound service through SSH, meaning sensitive data and privileged API access are being relayed off-process and potentially off-machine. In this skill context, that is more dangerous because the declared purpose is a simple API client, yet it covertly brokers access to an internal service using additional credentials and transport layers.
if [[ "$method" == "GET" ]]; then
sshpass -p "$SSH_PASS" ssh "$HOPE_HOST" \
"curl -s -H 'X-OpenClaw-Key: $HOPE_KEY' \
'http://127.0.0.1:$HOPE_PORT${endpoint}?${params}'"
else
sshpass -p "$SSH_PASS" ssh "$HOPE_HOST" \
This function triggers a channel cookie refresh via POST, which is a state-changing administrative action. The script includes no confirmation, prompt, or explicit warning near the function or in the help text that this operation modifies remote system state.
The function performs a PUT request to update download-instance cleanup state, which is a state-changing operation that could affect system/task handling. There is no confirmation prompt, visible user-facing warning, or inline disclosure indicating that this action modifies server state.
The manifest description forces a specific language presentation, and the rest of the skill documentation is also Chinese-only. The policy for this audit flags language or locale constraints when they are imposed without user opt-in or justification.
The document title and structure imply it only contains query examples, yet it also documents a batch write operation. This mismatch can mislead operators and agents into executing a mutating command under the assumption that it is informational only, creating a documentation-driven safety issue.
This markdown file presents all headings, descriptions, and examples in Chinese only. The policy requires flagging language or locale constraints when a skill forces a specific language without offering a user choice or documenting the constraint.
User-facing comments, warnings, and help text are written in Chinese throughout the script, with no option to choose another language. This creates a language/locale constraint in the skill's natural-language interface without documented opt-in or justification.
No suspicious patterns detected.