T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:14- Finding
Unused High-Value Credentials Violate Least-Privilege Requirements
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14-22
Vulnerability Type: Excessive credential exposure
Risk Level: MediumVulnerable Code
yaml credentials: [GREENHELIX_API_KEY, AGENT_SIGNING_KEY, STRIPE_API_KEY] metadata: openclaw: requires: env: - GREENHELIX_API_KEY - AGENT_SIGNING_KEY - STRIPE_API_KEY primaryEnv: GREENHELIX_API_KEYTechnical Analysis
The Skill declares
AGENT_SIGNING_KEYandSTRIPE_API_KEYas required environment credentials even though the reviewed examples do not read or use either variable. The demonstrated network client only readsGREENHELIX_API_KEY.Requiring unrelated signing and payment credentials violates the principle of least privilege. If the hosting platform exposes every declared variable to the agent or Skill execution context, sensitive credentials become accessible despite not being necessary for the documented functionality.
This issue is especially significant because a signing key can authorize actions under an agent identity, while a Stripe API key may permit payment operations according to its account-level scope. The unnecessary exposure increases the consequences of prompt injection, compromised tools, accidental logging, debugging output, or another flaw in the surrounding agent environment.
Attack Path
- A user installs or loads the Skill.
- The hosting platform processes the metadata and requests or injects all three declared credentials.
AGENT_SIGNING_KEYandSTRIPE_API_KEYenter the Skill or agent environment even though the examples do not require them.- A compromised agent, unsafe tool, malicious prompt, debugging facility, or unrelated integration reads the unnecessary environment variables.
- The exposed credentials are used outside the intended GreenHelix guide workflow.
Impact Assessment
Successful exploitation could disclose an agent signing k ...[truncated 415 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
AGENT_SIGNING_KEYandSTRIPE_API_KEYfrom the top-levelcredentialsandrequires.envdeclarations unless a concrete example actually consumes them. - Declare credentials separately for each optional workflow instead of exposing every secret whenever the Skill is loaded.
- Request
GREENHELIX_API_KEYonly when a user explicitly chooses to run a GreenHelix example. - Use narrowly scoped, revocable credentials restricted to the minimum required API operations.
- Keep production credentials out of educational and sandbox workflows; use dedicated sandbox credentials and fake funds for tests.
- Document the exact permission scope required for each optional integration.
- Ensure the host does not automatically make all declared secrets available to model context, logs, unrelated tools, or subprocesses.
- Add automated metadata validation that rejects declared credentials not referenced by any corresponding implementation.
- Remove
