T09 · Insecure Skill Coding Practices
- Location
security_news_aggregator_simple.py:121- Finding
GLM API Credential Can Be Sent to an Arbitrary Configured Endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill matches its security-news automation purpose, but it can automatically publish and archive Notion/Tistory content while using sensitive credentials and weak transport safeguards.
Review this before installing if it will have write access to real Notion databases or a logged-in Tistory browser profile. Use least-privilege Notion databases, keep Tistory disabled unless needed, avoid broad shared .env files, pin dependencies, remove TLS-verification bypasses, and add a manual review/dry-run step before publishing or archiving content.
security_news_aggregator_simple.py:121GLM API Credential Can Be Sent to an Arbitrary Configured Endpoint
modules/crawlers/skshieldus.py:34TLS Certificate Verification Is Disabled in Multiple Crawlers
requirements.txt:2Most Third-Party Dependencies Are Unpinned
security_news_aggregator_simple.py:140Untrusted Crawled Content Is Directly Embedded in LLM Instructions and Automatically Published
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### Tistory API (선택)
1. https://www.tistory.com/guide/api/register 접속
2. 앱 등록
3. Access Token 발급
## 라이선스
The script accesses a local .env file to obtain a Notion API key, which is credential access behavior. In an agent skill context, reading local secrets is high risk because it expands trust boundaries: a seemingly simple utility can harvest privileged tokens and immediately use them against external services.
database_id = "fe8277a4484243db8b3b2f1a15399d40"
# Notion 토큰 로드
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
notion_token = None
with open(env_file, 'r') as f:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv
# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv
# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv
# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv
# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv
# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path
The code explicitly targets a local .env secrets file under the user's workspace, which is a credential access pattern. In context, this appears intended to supply API and publishing credentials for the pipeline rather than steal them, but it still meaningfully increases risk because any compromise of this script or its imported modules exposes all loaded secrets.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
# 크롤러 임포트
Referencing and loading a .env file from a user workspace is consistent with credential access behavior because .env files commonly contain API keys, tokens, and service credentials. In the context of an integration test, this is more dangerous because test code often runs in developer environments with broad access and weaker operational controls, so secrets may be consumed unnecessarily and exposed indirectly.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
# 크롤러 임포트
The code archives Notion pages automatically with no confirmation, dry-run, rollback, or safety guard. Because the archival decision is based on a derived top-keyword set rather than explicit user intent, any logic error, partial dataset, or cache inconsistency can remove active pages from normal view and disrupt downstream workflows.
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
\`\`\`markdown
\`\`\`bash
# 패치 적용
sudo apt update && sudo apt upgrade
\`\`\`
\`\`\`
Referencing and loading a workspace .env file constitutes credential/config access because it imports whatever secrets are stored there into the process environment before executing multiple external-facing crawlers. In this context, the danger is elevated because imported crawler modules may consume or leak those variables through logs, subprocesses, HTTP requests, or downstream integrations, even though this script itself does not visibly exfiltrate them.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
# 작동하는 크롤러 임포트
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
No suspicious patterns detected.