T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:12- Finding
Unnecessary Declaration of Sensitive Credential Requirements
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-20
Vulnerability Type: Excessive credential access violating least privilege
Risk Level: MediumThe skill declares four sensitive environment values as requirements even though it is marked as non-executable, has no installation procedure, and contains only metadata and a catalog of tutorials.
yaml credentials: [GREENHELIX_API_KEY, AGENT_SIGNING_KEY, STRIPE_API_KEY, WALLET_ADDRESS] metadata: openclaw: requires: env: - GREENHELIX_API_KEY - AGENT_SIGNING_KEY - STRIPE_API_KEY - WALLET_ADDRESSTechnical Analysis
The declared requirements include a GreenHelix API key, an agent signing key, a Stripe API key, and a wallet address. The submitted artifact contains no executable code, API examples, or other functionality that uses these values. Requiring them therefore exceeds the demonstrated operational needs of the skill and violates the principle of least privilege.
AGENT_SIGNING_KEYandSTRIPE_API_KEYare especially sensitive. Depending on their external scopes, unauthorized access could permit cryptographic impersonation or Stripe API operations. The current artifact does not contain code that reads or transmits these values, so active credential theft is not established. The risk arises because a compatible skill loader may make declared environment variables available to the skill context or to components added in a future version.Attack Path
- A user installs or loads the skill in an OpenClaw-compatible environment.
- The platform processes the
metadata.openclaw.requires.envdeclarations. - The user or platform supplies the requested API and signing credentials.
- Those sensitive values become available within the skill's operational context, despite no demonstrated need for them.
- A subsequently modified release, an unreviewed included component, or any process with ...[truncated 1045 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all credential declarations from this non-executable bundle unless the packaged content directly and demonstrably requires them.
- Require credentials only in the specific executable tutorial or component that consumes them, rather than at bundle scope.
- Request credentials at execution time with explicit user consent and a clear explanation of the intended operation.
- Use narrowly scoped, revocable, non-production credentials for tutorials and examples.
- Never expose a raw long-lived signing key when a scoped signing service, hardware-backed key, or delegated short-lived token can be used.
- Restrict Stripe credentials to the minimum required API permissions and prefer restricted test-mode keys.
- Ensure the host does not automatically inject sensitive environment variables solely because they appear in package metadata.
- Add automated manifest validation that rejects credential requirements when a package is declared
executable: falseand provides no component that consumes them.
