T09 · Insecure Skill Coding Practices
- Location
SKILL.md:28- Finding
API Key Disclosure Through a Secret-Printing Prerequisite Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its purpose, but it handles an API key and changes OpenClaw behavior while using unsafe secret-check instructions, a persistent watcher, and an unpinned remote installer.
Install only if you are comfortable with it editing your OpenClaw model configuration and using your OpenRouter API key. Do not run the documented echo command for the key; use a non-printing presence check instead. Avoid the nohup watcher unless you deliberately want continuous background health checks and automatic config rotation, and prefer a pinned installer version over @latest.
SKILL.md:28API Key Disclosure Through a Secret-Printing Prerequisite Command
skill.json:46Mutable Remote Package Is Downloaded and Executed During Installation
main.py:349Optional Authentication-Profile Write Exceeds the Declared Configuration Boundary
The published description frames the skill as a simple model configuration helper, but the documented behavior includes a persistent watcher/daemon, health probing, rotation logic, and state/history persistence. This mismatch is dangerous because users and orchestration layers may grant or invoke the skill under the assumption of one-shot config edits, while it can establish ongoing autonomous behavior with continued network and file activity.
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
def _atomic_write(path: Path, content: str):
"""Write atomically via tmp + rename so a crash mid-write can't corrupt state."""
path.parent.mkdir(parents=True, exist_ok=True)
tmp = path.with_suffix(path.suffix + ".tmp")
tmp.write_text(content)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
### Stop paying for AI. Start riding free.
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
### Stop paying for AI. Start riding free.
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
### Stop paying for AI. Start riding free.
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
### Stop paying for AI. Start riding free.
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
[](https://clawhub.ai/skills/free-ride)
The README promotes a one-command setup that automatically edits ~/.openclaw/openclaw.json and reconfigures model/fallback behavior, but the up-front messaging emphasizes convenience rather than clearly warning that a persistent user configuration file will be modified. This can lead users to run the command without understanding that local agent behavior and routing policy are being changed.
The installation command uses npx clawhub@latest, which fetches and executes the latest package version at install time without pinning to a reviewed release. This creates a supply-chain execution risk: if the package, dependency chain, or publishing account is compromised, users may run attacker-controlled code immediately during setup.
The watcher instructions encourage users to run a persistent background daemon that probes remote models every minute and automatically rotates config, but do not foreground the privacy, resource, and operational implications of continuous network activity and ongoing config mutation. Users may unknowingly leave a long-running process active across logouts that makes repeated outbound requests and changes model selection over time.
The README explicitly instructs users to start freeride-watcher under nohup so it persists after logout, creating a background process that continues making network probes and rotating configuration outside the user's active session. Persistence itself is not inherently malicious here, but without strong warnings and lifecycle guidance it increases the chance of unnoticed ongoing activity, stale processes, and unintended behavior changes.
freeride-watcher
# Background, persistent across logout
nohup freeride-watcher > ~/.openclaw/freeride-watcher.log 2>&1 &
# One-off check (no loop)
freeride-watcher --once
The skill declares sensitive capabilities (environment secret access, network access, and file writes) but does not define an explicit tool/permission scope. That makes its effective authority broader and less auditable, increasing the chance an agent invokes it with more privileges than intended or that future changes expand behavior without a corresponding policy review.
The invocation guidance uses broad trigger phrases like 'free AI', 'model switching', 'rate limits', and 'reduce AI costs', which can overlap with many ordinary support requests. Over-broad routing can cause the skill to be invoked unexpectedly, exposing API-key-dependent network operations and config mutations in situations where the user may only be asking for advice rather than requesting changes.
The skill explicitly recommends launching a persistent background process via nohup, which creates session persistence outside the immediate user interaction. Persistent daemons increase risk because they continue making network probes and configuration changes after the original task ends, and they may be forgotten, harder to audit, or abused if their behavior changes.
freeride-watcher
# Persistent background
nohup freeride-watcher > ~/.openclaw/freeride-watcher.log 2>&1 &
# One-shot check (no loop)
freeride-watcher --once
This code persistently modifies the user's OpenClaw configuration by calling save_openclaw_config(config) after changing primary and fallback models. Although some status messages are printed, there is no confirmation prompt or explicit warning before the write occurs, and the operation changes application behavior in a user-impacting way.
The install command invokes npx clawhub@latest, which fetches and executes remote package code at install time without pinning to an exact trusted version. This creates a supply-chain execution path where a compromised upstream release or dependency could run arbitrary code on the user's machine during installation, and the risk is amplified because this skill also handles API secrets and edits local configuration.
The skill writes a cache file under ~/.openclaw/.freeride-cache.json, which is a file-system side effect. The function itself has only an internal docstring and no user-facing disclosure at the point of write, so users invoking commands indirectly triggering caching may not be warned that local files are being created or updated.
The dependency is specified as requests>=2.31.0, which allows any future version and does not guarantee a tested or reviewed release. This weakens supply-chain control and reproducibility, and can unintentionally introduce vulnerable or incompatible versions during installation.
requests>=2.31.0
Because requests is not pinned, it is not possible to determine from this manifest whether the installed version is affected by known advisories. In a skill that may make network calls to OpenRouter or related services, using an unknown requests version can expose the agent to client-side request handling issues, credential leakage, or TLS/redirect-related vulnerabilities if a vulnerable release is resolved.
This is a manifest file, so vague-trigger review applies. The description says the skill provides "Unlimited free AI access for OpenClaw via OpenRouter's free models with automatic fallback switching," but it does not specify concrete activation conditions, command scope, or exclusion cases, which can make invocation overly broad in systems that use manifest text for discovery or routing.
No suspicious patterns detected.