T09 · Insecure Skill Coding Practices
- Location
commands/post.js:19- Finding
Facebook Access Tokens Are Disclosed in Debug Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real Facebook Page management skill, but it needs Review because it exposes Page tokens and can change live Facebook content with weak safeguards.
Install only if you are comfortable giving this skill a Facebook Page token that can publish, schedule, hide, or delete content. Use a test Page first, avoid pasting tokens into command lines or chats, rotate any token used with this version, and do not run the test or cron examples against a production Page without manual review.
commands/post.js:19Facebook Access Tokens Are Disclosed in Debug Output
commands/fb-post-setup.js:27Setup Commands Expose Access Tokens Through Process Arguments and Console Output
commands/fb-post-setup.js:108Facebook Access Tokens Are Stored in Plaintext Without Explicit Restrictive Permissions
commands/fb-post-setup.js:70Bearer Tokens Are Transmitted in Graph API URL Query Strings
commands/fb-post-test.js:126Connection Test Creates a Real Post and Can Leave It Published After Cleanup Failure
The command prints part of the Facebook access token and reveals its total length to standard output. Even partial credential disclosure is sensitive because terminal output may be captured in logs, shell history workflows, screenshots, CI output, or shared support sessions, increasing the risk of token compromise or aiding reconstruction/identification of the secret.
if (config.page_name) {
console.log(`📄 Page Name: ${config.page_name}`);
}
console.log(`🔑 Access Token: ${config.access_token.substring(0, 15)}...${config.access_token.length} chars`);
console.log(`📅 Created: ${new Date(config.created_at).toLocaleString()}`);
console.log('\n💡 Commands:');
console.log(' fb-post "<message>" - Post text');
The user access token is embedded directly in the request URL query string when requesting the page token. Putting credentials in URLs is risky because query strings are more likely to be captured in logs, proxies, monitoring systems, browser/history equivalents, or error messages, causing unintended token disclosure.
console.log('🔄 Fetching Page Access Token...');
try {
// Step 1: Get Page Access Token using User Token
const pageTokenResponse = await makeHttpsRequest(
'GET',
`/${page_id}?fields=access_token&access_token=${userToken}`,
The script prints part of the access token to stdout, exposing a credential fragment in terminal scrollback, logs, CI output, or session recordings. Even partial token disclosure is unnecessary and increases the chance of credential leakage, especially when combined with other metadata or if token formats are predictable.
console.log('Configuration:');
console.log(` Page ID: ${pageId}`);
console.log(` Access Token: ${accessToken.substring(0, 15)}...${accessToken.substring(accessToken.length - 5)}`);
console.log(` Page Name: ${pageName || '(will fetch from API)'}`);
console.log('');
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
💡 Tips:
--------
- Access tokens may expire. Re-run setup if you get authentication errors.
- Use fb-post-test to verify your credentials before posting.
- Scheduled posts use server time (UTC).
The code places the user access token directly into the URL query string when calling the Facebook Graph API. Tokens in URLs are dangerous because they can be captured in logs, proxies, browser/history equivalents, monitoring systems, error traces, or upstream infrastructure, resulting in credential disclosure and unauthorized Page actions.
console.log('🔄 Fetching Page Access Token...');
try {
// Step 1: Get Page Access Token using User Token
const pageTokenResponse = await makeHttpsRequest(
'GET',
`/${page_id}?fields=access_token&access_token=${userToken}`,
The code sends the Facebook access token in the URL query string and explicitly requests the page's access_token field. Query-string credentials are more likely to be exposed through logs, error messages, proxies, browser/history capture, or downstream monitoring, and requesting token material when it is not needed increases credential exposure. In a CLI skill that stores and uses persistent page tokens, this raises the risk of token leakage and subsequent unauthorized access to the Facebook page.
}
try {
// Test 1: Verify access token and page access
const pageInfo = await makeHttpsRequest(
'GET',
`/${page_id}?fields=id,name,access_token&access_token=${access_token}`,
The code logs part of the page access token in the request path preview. Even partial credential disclosure is risky because logs are often broadly accessible, retained long-term, and aggregated externally; combined with other leaked context, this can aid token compromise and confirms the presence of a live secret.
const pageAccessToken = pageTokenResponse.access_token;
console.log('✅ Page Access Token retrieved successfully.');
// Step 2: Post using the Page Access Token
console.log(`📝 Posting message: "${message}"`);
console.log(`🔗 Request path: /${page_id}/feed?access_token=${pageAccessToken.substring(0, 20)}...`);
console.log(`📦 Request body: { message: "${message}" }`);
The manifest states that configuration is stored in a file containing page_id, access_token, and page_name, implying persistent storage of a sensitive access token. Storing long-lived API tokens in a local config file can lead to credential exposure through weak file permissions, backups, shell history during setup, or accidental sharing.
"description": "Configuration file containing page_id, access_token, and page_name"
},
"security_notes": [
"Never share your access token",
"Page tokens last 60 days",
"Regenerate if compromised",
"Use Page tokens, not User tokens"
The package defines a postinstall hook that automatically launches PowerShell with ExecutionPolicy Bypass on Windows, causing code to run during installation without explicit user review. Even though this file does not itself show a network download, install-time script execution materially increases risk because it can execute arbitrary local bootstrap logic and is especially dangerous in an agent-skill/package ecosystem where installation may be automated.
{
"name": "facebook-advanced",
"version": "1.0.0",
"description": "Facebook Page management CLI for OpenClaw",
"main": "bin/facebook-advanced",
"dependencies": {
"commander": "^12.0.0",
"node-fetch": "^2.7.0"
},
"scripts": {
"test": "echo \"Error: no test specified\" && exit 1",
"postinstall": "if (process.platform === 'win32') { powershell.exe -ExecutionPolicy Bypass -File ./bin/setup.ps1 }"
},
"bin": {
"facebook-advanced": "./bin/facebook-advanced"
},
"keywords": [
"facebook",
"graph-api",
"pages",
"posts",
"comments",
"openclaw"
],
"author": "",
"license": "MIT"
}
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Quick Start
### 1. Configure your access token
**Option A: Using facebook-config.json (Recommended)**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Quick Start
### 1. Configure your access token
**Option A: Using facebook-config.json (Recommended)**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Quick Start
### 1. Configure your access token
**Option A: Using facebook-config.json (Recommended)**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Quick Start
### 1. Configure your access token
**Option A: Using facebook-config.json (Recommended)**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Quick Start
### 1. Configure your access token
**Option A: Using facebook-config.json (Recommended)**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Quick Start
### 1. Configure your access token
**Option A: Using facebook-config.json (Recommended)**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Quick Start
### 1. Configure your access token
**Option A: Using facebook-config.json (Recommended)**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This skill is installed as an npm package. After cloning or installing:
```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"
# Make the script executable (if needed)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This skill is installed as an npm package. After cloning or installing:
```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"
# Make the script executable (if needed)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This skill is installed as an npm package. After cloning or installing:
```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"
# Make the script executable (if needed)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This skill is installed as an npm package. After cloning or installing:
```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"
# Make the script executable (if needed)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This skill is installed as an npm package. After cloning or installing:
```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"
# Make the script executable (if needed)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This skill is installed as an npm package. After cloning or installing:
```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"
# Make the script executable (if needed)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This skill is installed as an npm package. After cloning or installing:
```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"
# Make the script executable (if needed)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This skill is installed as an npm package. After cloning or installing:
```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"
# Make the script executable (if needed)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
This skill is installed as an npm package. After cloning or installing:
```bash
# Set your Facebook Page Access Token
$env:FB_PAGE_ACCESS_TOKEN = "your_page_access_token_here"
# Make the script executable (if needed)
Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal