T09 · Insecure Skill Coding Practices
- Location
scripts/send_daily_report.sh:3- Finding
Overbroad Workspace Secret Loading and Hardcoded External Email Recipient
- Content
View full analysis
/tmp/gptsportswriter-report.txt source /home/pi/.openclaw/workspace/.venv-agentmail/bin/activate python /home/pi/.openclaw/workspace/skills/agentmail/scripts/send_email.py \ --inbox 'njm.openclaw@agentmail.to' \ --to 'normandmickey@gmail.com' \ --subject 'GPTSportswriter daily betting report' \ --text "$(cat /tmp/gptsportswriter-report.txt)" ``` ### Technical Analysis The script sources a workspace-wide `.env` file while `set -a` is enabled. Consequently, every variable defined by that file is exported to all subsequently launched processes, including the report generator and external AgentMail script. This exceeds least privilege because report generation and email delivery should receive only the individual credentials they require. The script also sends the generated report to a hardcoded personal Gmail address. Although email delivery is documented functionality, the recipient is neither supplied nor confirmed by the invoking user. This creates a fixed, external disclosure channel. The reviewed code does not directly place `.env` values in the message body, so direct credential exfiltration is not established; the confirmed weaknesses are excessive secret exposure to child processes and an unsafe fixed destination. ### Attack Path 1. A user follows the documented instruction and executes `scripts/send_daily_report.sh`. 2. The script sources `/home/pi/.openclaw/workspace/.env` and exports all values. 3. The report generator and AgentMail sender inherit the complete exported environment. 4. The generated betting report is sent automatically to `normand ...[truncated 838 chars]- Remediation
View remediation
