T05 · Unauthorized Access and Privilege Escalation
- Location
main.py:45- Finding
Cross-Agent OpenRouter Credential Discovery Violates Least Privilege
- Content
View full analysis
Optional[str]: """Get OpenRouter API key from environment or OpenClaw config.""" # Try environment first api_key = os.environ.get("OPENROUTER_API_KEY") if api_key: return api_key # Try OpenClaw config if OPENCLAW_CONFIG_PATH.exists(): try: config = json.loads(OPENCLAW_CONFIG_PATH.read_text()) # Check env section api_key = config.get("env", {}).get("OPENROUTER_API_KEY") if api_key: return api_key except (json.JSONDecodeError, KeyError): pass # Try agent auth-profiles.json (where OpenClaw stores actual API keys) for agent_dir in (Path.home() / ".openclaw" / "agents").glob("*/agent/auth-profiles.json"): if agent_dir.exists(): try: auth = json.loads(agent_dir.read_text()) profile = auth.get("profiles", {}).get("openrouter:default", {}) if profile.get("provider") == "openrouter": key = profile.get("key") if key: return key except (json.JSONDecodeError, KeyError): pass return None ``` ### Technical Analysis The function first checks the expected environment variable and primary OpenClaw configuration, but then enumerates every agent directory under `~/.openclaw/agents/*/agent/auth-profiles.json`. It extracts an OpenRouter API key from the first matching profile without requiring the user to identify or authorize that agent. The Skill's core functionality requires an OpenRouter credential, but it does not require access to credentials belonging to unrelated agents. Explicitly supplied credentials or a profile associated with the current agent would provide sufficient privile ...[truncated 1888 chars]- Remediation
View remediation
