T09 · Insecure Skill Coding Practices
- Location
SKILL.md:29- Finding
Plaintext API Key Exposure Through Mandatory Preflight Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 29-33
Vulnerability Type: Credential exposure through tool output
Risk Level: HighThe skill requires the agent to execute the following command before every API request:
powershell Get-Content "$env:USERPROFILE\.openclaw\workspace\skills\OraAgent.key"Technical Analysis
Get-Contentreturns the complete contents of the API-key file rather than only checking whether the file exists and is nonempty. When invoked through an agent execution tool, the plaintext credential can be copied into tool results, model context, conversation transcripts, telemetry, or execution logs.This behavior is unnecessary because
ora-customs-client.jsalready reads the credential internally. It also conflicts with a later instruction inSKILL.mdthat describes separately reading the key as deprecated.Attack Path
- A user or workflow initiates a customs-data query.
- The mandatory startup instructions cause the agent to execute
Get-ContentagainstOraAgent.key. - The command returns the plaintext API key in execution output.
- The key enters the agent context, transcript, logs, or connected monitoring systems.
- Anyone with access to those records can recover the credential and use it independently against the associated service.
Impact Assessment
Successful exploitation exposes the full API credential. An attacker could make unauthorized API requests within the permissions and quota assigned to the key, consume paid resources, access data available to that credential, or cause the legitimate user to experience service disruption or account-level abuse.
This issue does not directly grant operating-system privileges, but its scope includes every remote API capability authorized by the exposed key.
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction that prints the key with
Get-Content. - Allow
ora-customs-client.jsto read the credential internally without returning it to the agent. - If a preflight check is required, check only file existence and nonzero size and return a boolean result.
- Never include credential contents in command output, logs, exceptions, telemetry, or model-visible context.
- Store the key in a dedicated secret manager where available.
- Restrict key-file permissions to the account that runs the skill.
- Revoke and rotate any credential that may already have appeared in execution logs or transcripts.
- Remove contradictory credential-handling instructions from
SKILL.mdand define one secure workflow.
- Remove the instruction that prints the key with
