T09 · Insecure Skill Coding Practices
- Location
references/auth-login.ts:167- Finding
Anthropic access token is exposed in the browser-facing RPC response
- Content
View full analysis
Vulnerability Details
File Location:
references/auth-login.ts, lines 167-171
Vulnerability Type: Sensitive credential exposure through an RPC response
Risk Level: HighVulnerable Code:
ts const result = await storeAnthropicSetupToken(accessToken, profileName ?? "claude-cli"); if (!result.ok) { return result; } return { ok: true, profileId: result.profileId, token: accessToken };Technical Analysis
The
autoDetectAnthropicTokenfunction reads an Anthropic OAuth bearer token from the local~/.claude/.credentials.jsonfile. After storing the credential, it unnecessarily includes the complete token in its return value.The
auth.login.anthropic-autogateway handler sends this object back through the RPC response. Although the UI controller declares a narrower TypeScript response type that omitstoken, TypeScript types do not remove properties from runtime objects. The raw credential therefore still reaches the browser.Returning a stored bearer credential violates secret-minimization principles. It exposes the token to browser memory, gateway or RPC instrumentation, debugging tools, browser extensions, client-side compromises, and any logging layer that records RPC responses.
Attack Path
- The user has previously authenticated with the Claude CLI, causing an Anthropic token to be stored in
~/.claude/.credentials.json. - The user or an authorized Control UI client invokes
auth.login.anthropic-auto. - The gateway reads
claudeAiOauth.accessTokenfrom the local credential file. - The gateway stores the token in the OpenClaw authentication profile.
- The function returns the same raw token as the
tokenproperty of its result. - The RPC handler serializes that result and transmits it to the browser.
- A compromised browser context, extension, RPC interceptor, developer tool, or response-logging component captures the bearer token.
- The captured token can be ...[truncated 636 chars]
- The user has previously authenticated with the Claude CLI, causing an Anthropic token to be stored in
- Remediation
View remediation
Remediation Suggestions
-
Remove the token from the success response and return only non-sensitive metadata:
ts return { ok: true, profileId: result.profileId }; -
Change the function's declared return type so it does not contain an optional
tokenfield. -
Ensure gateway handlers never serialize access tokens, API keys, authorization codes, refresh tokens, or other bearer credentials.
-
Review RPC logging and telemetry to confirm that previous responses containing this field were not retained.
-
Add automated tests asserting that successful and failed authentication RPC responses contain no credential values or credential-shaped properties.
-
Consider explicitly constructing response objects at the RPC boundary rather than forwarding internal service-layer objects.
-
If exposure may already have occurred, revoke or rotate the affected Anthropic credential.
-
