T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:12- Finding
Unnecessary Declaration of Sensitive Credential Requirements
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12–21
Vulnerability Type: Excessive credential access violating least privilege
Risk Level: MediumVulnerable Code
yaml executable: false install: none credentials: [GREENHELIX_API_KEY, AGENT_SIGNING_KEY, WALLET_ADDRESS, STRIPE_API_KEY] metadata: openclaw: requires: env: - GREENHELIX_API_KEY - AGENT_SIGNING_KEY - WALLET_ADDRESS - STRIPE_API_KEY primaryEnv: GREENHELIX_API_KEYTechnical Analysis
The package identifies itself as non-executable and contains only a manifest advertising four compliance guides. No scripts, installation actions, network operations, or other implementation capable of using these credentials are present.
Despite this, the manifest requires a GreenHelix API key, agent signing key, wallet address, and Stripe API key. A compatible host may consequently expose those values to the Skill context even though its documented and implemented behavior does not require them. Requiring signing and payment credentials without a demonstrated operational purpose violates least privilege and unnecessarily expands the secret-exposure boundary.
The reviewed package contains no code that accesses or transmits these values, so active credential theft or exfiltration is not established. The risk arises from unnecessary credential provisioning and possible access by future, external, or host-integrated components operating in that context.
Attack Path
- A user installs or enables the bundle.
- The host reads
metadata.openclaw.requires.env. - To satisfy the manifest, the host makes the listed environment values available to the Skill context.
- That context receives sensitive signing and payment credentials despite having no corresponding executable functionality.
- Any subsequently introduced component, externally resolved included guide, or other process able to inspect that context could attempt to read and m ...[truncated 750 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
credentialsfield and all entries undermetadata.openclaw.requires.envbecause the current package is documentation-only and non-executable. - If future executable features genuinely require authentication, request only the minimum credential necessary for each specific operation and only at the time of use.
- Avoid requesting high-impact credentials such as agent signing keys or payment API keys unless the implementation demonstrably performs an authorized operation requiring them.
- Document each required credential's purpose, destination, required permission scope, retention behavior, and revocation procedure.
- Use narrowly scoped and revocable tokens rather than broad account-level secrets.
- Ensure the host does not expose credentials to included or externally resolved components unless each component has been independently reviewed and explicitly authorized.
- Add automated manifest validation that rejects credential requirements for non-executable packages unless a documented exception is approved.
- Remove the
