T09 · Insecure Skill Coding Practices
- Location
SKILL.md:479- Finding
Reusable Bearer Token Exposed in Console Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 479–483
Vulnerability Type: Plaintext credential exposure through logging
Risk Level: MediumVulnerable Code
python API_KEY = reg.json()["agent"]["api_key"] print(f"API Key (save this): {API_KEY}") # --- All subsequent requests use this header --- headers = {"Authorization": f"Bearer {API_KEY}"}Technical Analysis
The documented Python example prints the complete reusable API bearer token to standard output. The documentation states that this token is shown only once during registration and authorizes all subsequent API requests.
Standard output is not a secure secret-storage mechanism. Depending on the execution environment, the token may be captured in CI/CD logs, terminal transcripts, agent conversation records, telemetry, notebook output, screen recordings, or shared debugging artifacts. Because bearer-token possession is sufficient for authentication, no additional proof of identity is required to misuse an exposed token.
Transmitting the token in the
Authorizationheader to the declared HTTPS API is necessary for the Skill’s functionality. The vulnerability is specifically the unnecessary plaintext console disclosure, which exceeds the minimum exposure required for authentication.Attack Path
- A user or agent follows the complete Python session example.
- The registration endpoint returns a new bearer token.
- Line 480 prints the complete token to standard output.
- The execution environment retains or forwards that output to logs, transcripts, telemetry, or another observer.
- An attacker obtains the token from the retained output.
- The attacker sends requests to
https://clawchemy.xyz/apiwith:http Authorization: Bearer <exposed-token> - The API treats the attacker as the registered clawbot until the credential becomes invalid.
Impact Assessment
An attacker who obtains the token can impersonate the clawbot within the Clawc ...[truncated 741 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the statement that prints the complete bearer token:
python # Do not print API_KEY API_KEY = reg.json()["agent"]["api_key"] -
Store the token in a dedicated secret manager or a protected configuration file with owner-only permissions. For local examples, prefer loading an existing token from an environment variable:
python import os API_KEY = os.environ["CLAWCHEMY_API_KEY"] headers = {"Authorization": f"Bearer {API_KEY}"} -
If confirmation output is necessary, print only a non-sensitive status message. Avoid printing even partial token values unless there is a documented operational need:
python print("Clawchemy registration succeeded; store the returned API key securely.") -
Configure logging and telemetry filters to redact values matching the
claw_credential prefix and redactAuthorizationheaders. -
Ensure exceptions, HTTP debugging, request tracing, and response-body logging do not record the registration response or authenticated headers.
-
Add server-side token revocation and rotation procedures so users can invalidate a token suspected of exposure.
-
Update the documentation to warn that bearer-token possession grants account access and that tokens must not be placed in source control, chat transcripts, notebooks, screenshots, or CI logs.
-
