T08 · Insecure Dependencies
- Location
references/setup-checklist.md:7- Finding
Unpinned Third-Party Dependency Receives Access to Publishing Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent content automation tool, but it asks for broad posting authority, persistent scheduled jobs, and sensitive credentials with weak scoping and secret-handling guidance.
Review this carefully before installing. Use separate scoped credentials per service and per brand, lock down or avoid ~/.openclaw/.env, do not store customer newsletter API keys as plain database text, verify the Larry dependency source and version, and keep all crons in test mode until you have reviewed exactly what each channel will publish.
references/setup-checklist.md:7Unpinned Third-Party Dependency Receives Access to Publishing Credentials
SKILL.md:119Centralized Plaintext Secret File Is Read with Excessive Credential Scope
references/supabase-schema.md:8Customer Newsletter API Keys Are Modeled as Plaintext Database Fields
The skill description emphasizes convenience and self-hosting but does not prominently warn that it can schedule recurring automated posts, send newsletters, publish blog content, and message Telegram using the user's linked accounts. That missing disclosure increases the risk that a user invokes the skill without understanding it will create persistent, externally visible automation with reputational and operational consequences.
The access secret is a companion credential that can enable authenticated API use when paired with the token/key material. Because this skill orchestrates social posting at scale, leakage increases the blast radius from a single host compromise or accidental commit to full misuse of the posting integration.
## 2. Twitter/X API (direct posting — optional if using Postiz only)
1. Apply at developer.twitter.com
2. Basic tier required for posting ($100/mo) — OR use Postiz OAuth only (free, no direct API needed)
3. If using direct API: save API key, secret, access token, access secret to ~/.openclaw/.env
## 3. MailerLite (newsletter)
1. Create account at mailerlite.com (free up to 1,000 subscribers)
The access secret is a companion credential that can enable authenticated API use when paired with the token/key material. Because this skill orchestrates social posting at scale, leakage increases the blast radius from a single host compromise or accidental commit to full misuse of the posting integration.
## 2. Twitter/X API (direct posting — optional if using Postiz only)
1. Apply at developer.twitter.com
2. Basic tier required for posting ($100/mo) — OR use Postiz OAuth only (free, no direct API needed)
3. If using direct API: save API key, secret, access token, access secret to ~/.openclaw/.env
## 3. MailerLite (newsletter)
1. Create account at mailerlite.com (free up to 1,000 subscribers)
The access secret is a companion credential that can enable authenticated API use when paired with the token/key material. Because this skill orchestrates social posting at scale, leakage increases the blast radius from a single host compromise or accidental commit to full misuse of the posting integration.
## 2. Twitter/X API (direct posting — optional if using Postiz only)
1. Apply at developer.twitter.com
2. Basic tier required for posting ($100/mo) — OR use Postiz OAuth only (free, no direct API needed)
3. If using direct API: save API key, secret, access token, access secret to ~/.openclaw/.env
## 3. MailerLite (newsletter)
1. Create account at mailerlite.com (free up to 1,000 subscribers)
The checklist instructs users to store the Telegram bot token and chat ID in ~/.openclaw/.env without warning about sensitivity. A leaked bot token allows others to send messages as the bot, read/update bot interactions depending on configuration, and abuse the automation channel used for briefings.
1. Message @BotFather on Telegram → /newbot → follow prompts
2. Save the bot token
3. Get your chat ID: message your bot, then fetch https://api.telegram.org/bot{TOKEN}/getUpdates
4. Save TELEGRAM_BOT_TOKEN + TELEGRAM_CHAT_ID to ~/.openclaw/.env
## 5. OpenAI API (image generation for TikTok slides)
1. Get API key at platform.openai.com
The OpenAI API key is directed into a plaintext .env file with no handling guidance. Exposure would let an attacker consume the account's quota, incur charges, and potentially access or generate content through the user's automation workflow.
## 5. OpenAI API (image generation for TikTok slides)
1. Get API key at platform.openai.com
2. Save OPENAI_API_KEY to ~/.openclaw/.env
3. Note: gpt-image-1.5 costs ~$0.04/image. ~30 images/month = ~$1.20/month per pipeline
## 6. Supabase + Netlify (blog publishing)
This instruction stores a Supabase service-role key and Netlify deploy hook in ~/.openclaw/.env. A Supabase service-role key is highly privileged and can bypass normal client restrictions, while a leaked Netlify deploy hook can trigger unauthorized site deployments; together they create a strong path to database abuse and malicious content publication.
2. Create blog_articles table — schema at references/blog-schema.md
3. Get service role key: Supabase → Settings → API → service_role key
4. Create Netlify site (or connect existing) and get deploy hook URL
5. Save SUPABASE_URL + SUPABASE_SERVICE_KEY + NETLIFY_DEPLOY_HOOK to ~/.openclaw/.env
6. Note: Blog publishing requires your site to be connected to Supabase — see references/blog-schema.md
## 7. Verify everything
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## 7. Verify everything
Run: `node scripts/verify-setup.js` (coming soon — manual check for now)
Confirm each credential is in ~/.openclaw/.env or the relevant config file.
---
The manifest advertises very broad trigger phrases such as 'run my content engine', 'start posting for [product]', and 'go live [slug]', which can overlap with ordinary user requests and cause the skill to activate in situations where the user did not intend to authorize automated publishing. In this skill's context, accidental invocation is especially dangerous because downstream actions include provisioning cron jobs and eventually publishing to external social, newsletter, blog, and Telegram accounts.
Creating a new system folder from a template establishes persistent infrastructure for future automated operations, not just a transient response to the current request. That persistence becomes more dangerous here because the created directory is later used for cron-driven posting and publication workflows, amplifying the effect of any mistaken setup or abusive invocation.
slug = productName.toLowerCase().replace(/[^a-z0-9]/g, '-').replace(/-+/g, '-')
Example: "Echo Reviews" → "echo-reviews"
LARRY_ROOT = ~/[workspace]/99-External-Systems/skills/larry
SYSTEMS_DIR = {LARRY_ROOT}/tiktok-marketing/systems
The skill persists user-provided brand data by writing config files and updating systems.json, creating durable state that can continue influencing future automated behavior beyond the current session. In this context, persistence is security-relevant because it is coupled to recurring automation and can silently survive later user context changes or misunderstandings.
- Copy template: `cp -r {TEMPLATE_DIR} {NEW_DIR}`
- Write `{NEW_DIR}/config.json` using answers from Step 1. See `references/config-schema.md`.
- Write `{NEW_DIR}/voice.md` from brand voice + product description. See `references/voice-guide-template.md`.
- Add entry to `{LARRY_ROOT}/tiktok-marketing/systems.json`
### Step 3b — Generate Twitter config
Write `{LARRY_ROOT}/social/twitter/config.json` using the buyer's brand details.
The instructions direct the agent to read sensitive secrets from ~/.openclaw/.env, including API keys and messaging tokens, but provide no privacy/security warning or minimization guidance. Even if the intended use is legitimate, instructing a skill to access a consolidated secret store raises the chance of over-collection, accidental disclosure, or use of credentials without fully informed consent.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
create table blog_articles (
id uuid default gen_random_uuid() primary key,
created_at timestamptz default now(),
title text not null,
The documentation tells users to place a Supabase service-role key in a local .env file but does not clearly warn that this credential is highly privileged and bypasses normal row-level security controls. In a self-serve automation skill that provisions publishing infrastructure, this increases the chance users mishandle the secret, commit it, expose it to logs, or reuse it in unsafe contexts, leading to full database compromise.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SUPABASE_URL=https://your-project.supabase.co
SUPABASE_SERVICE_KEY=your-service-role-key
NETLIFY_DEPLOY_HOOK=https://api.netlify.com/build_hooks/your-hook-id
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
---
## 1. Postiz (TikTok + Twitter scheduling)
1. Create account at postiz.com (free plan works for 1 channel, paid for multiple)
2. Connect your TikTok account: Postiz dashboard → Channels → Add Channel → TikTok
3. Connect your Twitter/X account: Postiz dashboard → Channels → Add Channel → Twitter
4. Get your API key: Postiz dashboard → Settings → API → Copy API key
The checklist instructs users to place multiple sensitive credentials, including service-role and deploy-hook secrets, into local config files without any warning about least privilege, filesystem protections, git exclusion, or rotation. In a skill whose purpose is to automate posting and publishing across several services, compromise of these secrets could enable account takeover of automation channels and unauthorized publishing.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## 4. Telegram (briefings)
1. Message @BotFather on Telegram → /newbot → follow prompts
2. Save the bot token
3. Get your chat ID: message your bot, then fetch https://api.telegram.org/bot{TOKEN}/getUpdates
4. Save TELEGRAM_BOT_TOKEN + TELEGRAM_CHAT_ID to ~/.openclaw/.env
## 5. OpenAI API (image generation for TikTok slides)
This documentation explicitly instructs operators to use a Supabase service role key and indicates storage of customer-provided newsletter API keys in the same system. A service role key bypasses RLS and provides broad database access, so weak handling, unclear storage protections, or operator misuse could expose all client records and downstream third-party credentials; in a content automation skill that provisions posting infrastructure, those credentials are especially sensitive because they can be used to send mail or act on customer accounts.
This markdown file describes generating example tweets that will 'seed the Twitter autoposter,' which implies downstream automated publishing behavior. The template and instructions do not include any warning about review, approval, or the risks of unintended public posting, which is a user-impacting behavior covered by missing-warning criteria for markdown files.
The documentation states that publishing will POST to a Netlify deploy hook and trigger a rebuild, but it does not clearly frame this as an externally triggered side effect users should explicitly expect before enabling automation. In an automated content pipeline, unexpected rebuilds can cause unplanned deployments, cost, or availability disruption if the hook is triggered too often or misused.
No suspicious patterns detected.