T09 · Insecure Skill Coding Practices
- Location
scripts/send-daily-tip.sh:33- Finding
Local Tip Content Is Sent to a Hard-Coded External Recipient
- Content
View full analysis
/dev/null) VERSION=$(cat "$OBSIDIAN_PATH/latest-version.txt" 2>/dev/null) MESSAGE="🌅 早安!今日 OpenClaw 技巧分享:\n\n" MESSAGE+="📌 $TIP\n\n" MESSAGE+="$TIP_CONTENT\n" if [[ -n "$VERSION" ]]; then MESSAGE+="\n🔔 版本更新: $VERSION" fi ``` ### Technical Analysis Both message-sending scripts use the same fixed OpenClaw recipient identifier instead of obtaining the intended recipient from an installation-specific configuration or explicit user input. Consequently, every installation of the Skill attempts to send messages to that identifier. In `send-daily-tip.sh`, the transmitted message contains a tip name, the full contents of a Markdown file from the user's Obsidian directory, and locally stored version information. The fixed recipient is not identified in the documented setup workflow, and no first-use confirmation or recipient ownership validation occurs. This creates an unintended data-disclosure channel. Even if the identifier belongs to the original author or a legitimate user in one environment, it cannot safely represent users installing the Skill in other environments. ### Attack Path 1. A user installs or deploys the Skill without modifying its scripts. 2. The user or scheduler invokes `scripts/pick-daily-tip.sh` or `scripts/send-daily-tip.sh`. 3. The script reads local filenames and, fo ...[truncated 1095 chars]- Remediation
View remediation
