Back to skill

Security audit

GreenHelix API Mastery Bundle: 22 Hands-On Tutorials

Security checks for vulnerabilities and agentic risk

Overview

The package is only a tutorial catalog, but it asks for sensitive API, signing, and payment credentials without showing a necessary use.

Review this package before installing and do not provide production GreenHelix, signing, Stripe, or wallet-linked credentials unless a specific tutorial or component clearly needs them and you can scope them narrowly. The artifact does not show active theft or execution, but the credential request is broader than the visible content justifies.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:12
Finding

Unnecessary Declaration of Sensitive Credential Requirements

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-20
Vulnerability Type: Excessive credential access violating least privilege
Risk Level: Medium

The skill declares four sensitive environment values as requirements even though it is marked as non-executable, has no installation procedure, and contains only metadata and a catalog of tutorials.

yaml
credentials: [GREENHELIX_API_KEY, AGENT_SIGNING_KEY, STRIPE_API_KEY, WALLET_ADDRESS]
metadata:
  openclaw:
    requires:
      env:
        - GREENHELIX_API_KEY
        - AGENT_SIGNING_KEY
        - STRIPE_API_KEY
        - WALLET_ADDRESS

Technical Analysis

The declared requirements include a GreenHelix API key, an agent signing key, a Stripe API key, and a wallet address. The submitted artifact contains no executable code, API examples, or other functionality that uses these values. Requiring them therefore exceeds the demonstrated operational needs of the skill and violates the principle of least privilege.

AGENT_SIGNING_KEY and STRIPE_API_KEY are especially sensitive. Depending on their external scopes, unauthorized access could permit cryptographic impersonation or Stripe API operations. The current artifact does not contain code that reads or transmits these values, so active credential theft is not established. The risk arises because a compatible skill loader may make declared environment variables available to the skill context or to components added in a future version.

Attack Path

  1. A user installs or loads the skill in an OpenClaw-compatible environment.
  2. The platform processes the metadata.openclaw.requires.env declarations.
  3. The user or platform supplies the requested API and signing credentials.
  4. Those sensitive values become available within the skill's operational context, despite no demonstrated need for them.
  5. A subsequently modified release, an unreviewed included component, or any process with ...[truncated 1045 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all credential declarations from this non-executable bundle unless the packaged content directly and demonstrably requires them.
  2. Require credentials only in the specific executable tutorial or component that consumes them, rather than at bundle scope.
  3. Request credentials at execution time with explicit user consent and a clear explanation of the intended operation.
  4. Use narrowly scoped, revocable, non-production credentials for tutorials and examples.
  5. Never expose a raw long-lived signing key when a scoped signing service, hardware-backed key, or delegated short-lived token can be used.
  6. Restrict Stripe credentials to the minimum required API permissions and prefer restricted test-mode keys.
  7. Ensure the host does not automatically inject sensitive environment variables solely because they appear in package metadata.
  8. Add automated manifest validation that rejects credential requirements when a package is declared executable: false and provides no component that consumes them.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.