T09 · Insecure Skill Coding Practices
- Location
SKILL.md:28- Finding
Gateway Token Disclosed Through Terminal Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 28–34
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: HighVulnerable Code:
bash cat /data/.openclaw/openclaw.json | grep -A 2 '"token"'Token is under:
json "gateway": { "auth": { "token": "YOUR_TOKEN_HERE" } }Technical Analysis
The documented command reads the OpenClaw configuration and prints the gateway authentication token in plaintext. The secret can consequently remain in terminal scrollback, session recordings, centralized terminal logs, support transcripts, or AI agent tool output.
The broad
grep -A 2 '"token"'expression is not restricted to the exactgateway.auth.tokenproperty. If the configuration contains multiple matching properties, it may disclose additional tokens or return the wrong credential.Attack Path
- An operator follows the Skill and runs the documented command.
- The gateway token appears in plaintext in terminal or agent output.
- The output is retained in scrollback, a recording, a transcript, or diagnostic logs.
- An attacker or unauthorized user obtains access to that retained output.
- The attacker submits the exposed token to a reachable OpenClaw gateway.
- The attacker gains the gateway access authorized by that token.
Impact Assessment
Disclosure allows an attacker to impersonate a gateway-authenticated client. The exact accessible operations depend on the gateway's authorization model and network exposure, but may include access to gateway functionality, connected channels, status information, and device-management operations. The compromise persists until the exposed token is revoked or rotated.
- Remediation
View remediation
Remediation Suggestions
- Do not print the gateway token to standard output or include it in agent transcripts.
- Use a trusted local credential handoff, protected secret manager, or UI integration that transfers the token without exposing it to terminal output.
- If programmatic retrieval is unavoidable, use a structured JSON parser to select only the exact
gateway.auth.tokenpath and pass it directly to the intended consumer. - Disable command tracing and redact secrets from terminal recordings, diagnostic logs, and support bundles.
- Restrict
/data/.openclaw/openclaw.jsonto the minimum required account and permissions. - Rotate the gateway token if the documented command has been used in a logged or shared environment.
- Ensure authentication failures and debugging output never echo the supplied token.
