T09 · Insecure Skill Coding Practices
- Location
references/mcp.md:8- Finding
Purchase-Capable API Key Embedded in MCP URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Bitrefill skill is not clearly malicious, but it needs review because it can spend real money and includes risky credential and recurring-purchase guidance.
Install only with a dedicated low-balance Bitrefill account. Prefer OAuth or bearer-token headers, do not place API keys in MCP URLs, keep buy-products out of auto-approve settings, and avoid recurring cron purchases unless they have explicit caps, expiration, recipient/SKU locks, and a way to list and cancel them.
references/mcp.md:8Purchase-Capable API Key Embedded in MCP URL
references/host-openclaw.md:91Persistent Unattended Purchases Bypass the Skill's Transaction Approval Boundary
references/cli.md:57OpenClaw Bootstrap Stores a Purchase Credential Without a Documented Permission Guarantee
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
1. **`--api-key <key>`** — global flag; can appear before any subcommand.
2. **`BITREFILL_API_KEY`** — environment variable.
3. **`~/.config/bitrefill-cli/credentials.json`** — written by `bitrefill init` (mode `0600`). Overwrite or remove to change the key.
4. **OAuth** — only when no key is available **and** the session is interactive (TTY, not `CI=true`). Browser flow; state under `~/.config/bitrefill-cli/<host>.json` (e.g. `api.bitrefill.com.json`). Clear with `bitrefill logout` (OAuth only; no-op when using API key only).
Generate keys at <https://www.bitrefill.com/account/developers>.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
1. **`--api-key <key>`** — global flag; can appear before any subcommand.
2. **`BITREFILL_API_KEY`** — environment variable.
3. **`~/.config/bitrefill-cli/credentials.json`** — written by `bitrefill init` (mode `0600`). Overwrite or remove to change the key.
4. **OAuth** — only when no key is available **and** the session is interactive (TTY, not `CI=true`). Browser flow; state under `~/.config/bitrefill-cli/<host>.json` (e.g. `api.bitrefill.com.json`). Clear with `bitrefill logout` (OAuth only; no-op when using API key only).
Generate keys at <https://www.bitrefill.com/account/developers>.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
1. **`--api-key <key>`** — global flag; can appear before any subcommand.
2. **`BITREFILL_API_KEY`** — environment variable.
3. **`~/.config/bitrefill-cli/credentials.json`** — written by `bitrefill init` (mode `0600`). Overwrite or remove to change the key.
4. **OAuth** — only when no key is available **and** the session is interactive (TTY, not `CI=true`). Browser flow; state under `~/.config/bitrefill-cli/<host>.json` (e.g. `api.bitrefill.com.json`). Clear with `bitrefill logout` (OAuth only; no-op when using API key only).
Generate keys at <https://www.bitrefill.com/account/developers>.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
OAuth: codex mcp login bitrefill.
~/.gemini/settings.json (or project .gemini/settings.json){
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
codex --sandbox workspace-write --ask-for-approval on-request
Put `BITREFILL_API_KEY` in a profile (`~/.codex/config.toml` `[profiles.bitrefill]`), not in committed config.
### Claude Code
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
codex --sandbox workspace-write --ask-for-approval on-request
Put `BITREFILL_API_KEY` in a profile (`~/.codex/config.toml` `[profiles.bitrefill]`), not in committed config.
### Claude Code
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
In ~/.claude/settings.json (or project .claude/settings.json):
{
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
{
"sandbox": {
"filesystem": {
"denyRead": ["~/.ssh", ".env", "*.pem", "**/.bitrefill_token"],
"denyWrite": ["~/.ssh", ".env"]
},
"network": {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
{
"sandbox": {
"filesystem": {
"denyRead": ["~/.ssh", ".env", "*.pem", "**/.bitrefill_token"],
"denyWrite": ["~/.ssh", ".env"]
},
"network": {
The trigger description is broad enough to activate on generic payment- or crypto-related requests that may not actually be about Bitrefill. Over-broad activation can route unrelated user intents into a real-money purchase skill, increasing the chance of unintended transaction flows or unnecessary credential handling.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- **Use a dedicated, low-balance account.** Never give the agent access to high-balance accounts or crypto wallet seeds. This skill is **not a wallet**.
- **Log every purchase.** `invoice_id`, product, amount, payment method.
Full safeguards + per-host hardening (OpenClaw exec-approvals, Cursor auto-approve, Codex sandbox, Claude Code allowlist) → [safeguards.md](references/safeguards.md).
## References
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Use when: outbound HTTP available but no MCP and no shell. Last resort — verbose, no typed validation. Examples below use `curl` but any HTTP client works.
Base URL: `https://api.bitrefill.com/v2`
## Three tiers
No suspicious patterns detected.