T09 · Insecure Skill Coding Practices
- Location
scripts/identity/identity.json:2- Finding
Bundled Ed25519 Private Key Enables Agent Identity Impersonation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/identity/identity.json:2-5
Vulnerability Type: Hardcoded cryptographic private key
Risk Level: MediumVulnerable Code
json { "name": "本机OpenClaw", "pubkey": "302a300506032b6570032100a607131a7e3f8b0eda8acb291dffa1d5bdaefcabf6136f93a4408193d0a7ec12", "privkey": "302e020100300506032b657004220420726920ac095c693d58c4d42918b7ca80f263585b165ef394e615af3961de3196", "created": "2026-09-17T11:38:39.809Z" }The exposed key is loaded by
scripts/identity.js:14-17:javascript if (fs.existsSync(ID_FILE)) { const saved = JSON.parse(fs.readFileSync(ID_FILE, 'utf8')); const priv = crypto.createPrivateKey({ key: Buffer.from(saved.privkey, 'hex'), format: 'der', type: 'pkcs8' }); return { name: saved.name, priv, privHex: saved.privkey, pubHex: saved.pubkey, agentId: saved.agentId }; }It is then used to authenticate messages in
scripts/post.js:13-19:javascript const id = loadOrCreateIdentity('本机OpenClaw'); const agentId = id.pubHex.toLowerCase(); const data = JSON.stringify({ room, kind: reply ? 'comment' : 'post', body: text, reply_to: reply ? Number(reply) : null, ts: Date.now() }); const r = await fetch(BASE + '/messages', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ agent_id: agentId, data, signature: sign(id.priv, data) }), });Technical Analysis
The package distributes a complete Ed25519 private key in plaintext. The identity loader prefers an existing
identity.jsonover generating a new key, so installations containing this file reuse the same package-distributed identity.The community protocol treats possession of this private key as proof of control over the corresponding agent identity. Because every person with access to the package can recover the key, the identity is not private or host-specific. The restrictive mode applied when creating ...[truncated 1192 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
scripts/identity/identity.jsonfrom source control and all distributed packages. - Revoke or invalidate the exposed community identity because the private key must be considered compromised.
- Generate a new Ed25519 key locally on each installation's first use.
- Add
scripts/identity/or the specific identity file to version-control ignore and package-exclusion rules. - Store generated keys in a user-specific application data directory rather than inside the installed Skill directory.
- Preserve restrictive owner-only permissions and verify them after file creation where the operating system supports such checks.
- Add release checks that reject artifacts containing private-key fields or PKCS#8 private-key material.
- Remove
