T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:14- Finding
Excessive Declaration of Sensitive Credentials Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14–23
Vulnerability Type: Excessive credential access and least-privilege violation
Risk Level: MediumVulnerable Code
yaml credentials: [GREENHELIX_API_KEY, WALLET_ADDRESS, AGENT_SIGNING_KEY, STRIPE_API_KEY] metadata: openclaw: requires: env: - GREENHELIX_API_KEY - WALLET_ADDRESS - AGENT_SIGNING_KEY - STRIPE_API_KEY primaryEnv: GREENHELIX_API_KEYTechnical Analysis
The Skill globally declares four credentials as environment requirements, including the sensitive
AGENT_SIGNING_KEYandSTRIPE_API_KEY. However, the reviewed examples only retrieve and useGREENHELIX_API_KEY:python API_KEY = os.environ["GREENHELIX_API_KEY"]No reviewed example reads or otherwise requires
AGENT_SIGNING_KEYorSTRIPE_API_KEY. Declaring these secrets globally can cause a compatible host to expose high-value signing and payment credentials to the Skill context even when they are unnecessary for the documented functionality.This exceeds the minimum privileges required by the guide and conflicts with the Skill's own recommendation at
SKILL.md:457that private keys should be stored in a secrets manager rather than environment variables.The static pre-scan also flagged Base64 encoding at
SKILL.md:258–272. That behavior was reviewed and is not a covert exfiltration channel: the example encodes only a newly generated Ed25519 public key for API registration. It does not encode, return, or transmit the private key.Attack Path
- A user installs or loads the Skill in a host that resolves the
metadata.openclaw.requires.envdeclarations. - The host makes
AGENT_SIGNING_KEYandSTRIPE_API_KEYavailable to the Skill execution context despite their not being required by the reviewed examples. - A separate compromised component, prompt-injected workflow, or subsequent ...[truncated 1465 chars]
- A user installs or loads the Skill in a host that resolves the
- Remediation
View remediation
Remediation Suggestions
-
Remove unused sensitive credentials from the global Skill metadata:
yaml credentials: [GREENHELIX_API_KEY, WALLET_ADDRESS] metadata: openclaw: requires: env: - GREENHELIX_API_KEY - WALLET_ADDRESS primaryEnv: GREENHELIX_API_KEY -
If later examples genuinely require Stripe access, request a restricted Stripe key only for that specific workflow rather than exposing it to the entire Skill context.
-
Do not inject private signing keys into general-purpose environment variables. Use a secrets manager, hardware-backed signer, or isolated signing service that performs signing operations without releasing private key material.
-
Apply narrowly scoped API permissions, transaction limits, expiration, and environment separation to all payment and platform credentials.
-
Require explicit user approval before making production payment, settlement, webhook, or identity operations.
-
Keep sandbox credentials separate from production credentials and default all educational examples to
https://sandbox.greenhelix.net. -
Add automated checks that compare declared credentials against actual references in the Skill and reject unused high-value secrets.
-
Rotate and revoke any signing or Stripe credentials that may already have been unnecessarily exposed to a shared Skill context.
-
