T09 · Insecure Skill Coding Practices
- Location
scripts/index.js:137- Finding
Webhook Signature Verification Can Be Bypassed When Authentication Parameters Are Missing
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent WeChat Work to OpenClaw purpose, but its webhook security and secret/message handling are under-scoped for an internet-reachable enterprise messaging bridge.
Review before installing. Use only in a controlled test environment unless the webhook is fixed to require signatures, reject stale or replayed requests, bind to loopback by default, restrict logs and .env permissions, and use pinned dependencies. Treat the adapter as handling sensitive enterprise chat content and credentials.
scripts/index.js:137Webhook Signature Verification Can Be Bypassed When Authentication Parameters Are Missing
scripts/index.js:121Authenticated Webhook Messages Can Be Replayed Without Deduplication or Freshness Enforcement
scripts/deploy.sh:34Deployment Creates a Multi-Secret Environment File Without Enforcing Restrictive Permissions
scripts/index.js:158Sensitive User Messages and Model Responses Are Persisted in Plaintext Logs
scripts/index.js:299Adapter Listens on All Network Interfaces Despite Localhost-Only Security Claims
scripts/deploy.sh:13Deployment Installs Non-Reproducible Dependency Versions Without a Reviewed Lockfile
The documented behavior diverges from the described purpose in several security-relevant ways: undeclared local logging of message content, permissive CORS, an extra HTTP endpoint, and confusing secret usage for cryptography. This is dangerous because operators may deploy the skill under false assumptions, exposing message data, widening network attack surface, and misconfiguring cryptographic verification.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 1. Deploy
bash <skill_dir>/scripts/deploy.sh
# 2. Edit .env with your WeChat Work credentials
nano ~/wecom-adapter/.env
# 3. Start
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 1. Deploy
bash <skill_dir>/scripts/deploy.sh
# 2. Edit .env with your WeChat Work credentials
nano ~/wecom-adapter/.env
# 3. Start
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 1. Deploy
bash <skill_dir>/scripts/deploy.sh
# 2. Edit .env with your WeChat Work credentials
nano ~/wecom-adapter/.env
# 3. Start
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 1. Deploy
bash <skill_dir>/scripts/deploy.sh
# 2. Edit .env with your WeChat Work credentials
nano ~/wecom-adapter/.env
# 3. Start
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 1. Deploy
bash <skill_dir>/scripts/deploy.sh
# 2. Edit .env with your WeChat Work credentials
nano ~/wecom-adapter/.env
# 3. Start
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 1. Deploy
bash <skill_dir>/scripts/deploy.sh
# 2. Edit .env with your WeChat Work credentials
nano ~/wecom-adapter/.env
# 3. Start
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 1. Deploy
bash <skill_dir>/scripts/deploy.sh
# 2. Edit .env with your WeChat Work credentials
nano ~/wecom-adapter/.env
# 3. Start
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### Token Caching
Access tokens cached with 5-minute safety margin to minimize API calls.
## Recommended Hardening
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
fi
# Create .env template if not exists
if [ ! -f "$TARGET_DIR/.env" ]; then
cat > "$TARGET_DIR/.env" << 'EOF'
# === WeChat Work Credentials ===
CORP_ID=your_corp_id
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
fi
# Create .env template if not exists
if [ ! -f "$TARGET_DIR/.env" ]; then
cat > "$TARGET_DIR/.env" << 'EOF'
# === WeChat Work Credentials ===
CORP_ID=your_corp_id
The skill declares no explicit tool scope or permissions despite clearly requiring access to environment variables for sensitive credentials. In an agent ecosystem, missing scope declarations weaken reviewability and allow broader-than-expected secret access, increasing the chance of accidental credential exposure or unsafe execution assumptions.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
## Environment Security
- Store `.env` with `chmod 600`
- Never commit `.env` to version control
- Rotate WEBHOOK_TOKEN periodically
- Monitor `logs/wecom-adapter.log` for anomalies
The guide instructs users to expose a local webhook over a temporary public Cloudflare tunnel but does not explicitly warn that this creates an Internet-reachable endpoint handling sensitive enterprise messages. Even with token/signature checks, public exposure increases attack surface, can leak metadata, and may invite unsolicited probing or misconfiguration during setup.
This shell script creates directories and copies or generates files in a user-supplied target path, which are safety-relevant filesystem modifications. Although it logs that deployment is happening, it does not give the user any chance to confirm or cancel before performing the writes.
Running npm install performs network access and may execute package lifecycle scripts, which can affect system state beyond simple file copying. The script does not disclose this specific action before executing it, aside from generic deployment messaging.
The code persistently writes detailed request metadata and operational events to a local log file, including webhook parameters and downstream processing details. In a messaging bridge, these logs can expose sensitive identifiers, message data, and authentication-related values to local users, backups, or log collectors, expanding data retention beyond the stated integration purpose.
The webhook flow logs decrypted challenge data, CorpID, and later user message content, which directly captures confidential payloads after decryption. Because this service handles enterprise chat traffic, such logging increases the risk of privacy leakage, credential-adjacent data exposure, and unintended retention of regulated or internal business information.
The skill forwards inbound WeCom message content to an external OpenClaw service for AI processing without any in-code notice, consent mechanism, or filtering. In an enterprise messaging context, this can transmit sensitive employee or business data to another system, creating confidentiality, compliance, and data-governance risk if users or administrators are unaware of the data flow.
User-visible strings, logs, and fallback responses are written exclusively in Chinese, including generated fallback text such as 抱歉,我还没学会回答这个。 and 服务暂时不可用,请稍后重试。. There is no indication that users can opt into another language or that the locale restriction is intentionally documented as region-specific.
Detected: suspicious.env_credential_access