T09 · Insecure Skill Coding Practices
- Location
openclaw.json:102- Finding
Hardcoded Operational Credentials and Access Tokens
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill's voice-chat purpose is understandable, but it ships overly broad unauthenticated services, root persistence instructions, unsafe file handling, and hardcoded credentials that need review before use.
Review this skill carefully before installing. Replace and rotate all embedded credentials, bind services to 127.0.0.1, add authentication and request limits, run under a dedicated unprivileged account, avoid the root systemd units as written, use only trusted voice clone files, and require consent for any voice cloning or automatic voice-message processing.
openclaw.json:102Hardcoded Operational Credentials and Access Tokens
openclaw.json:53Shell Command Injection Through Unescaped Media Path Interpolation
scripts/server/whisper-server.py:40Unauthenticated Network-Wide ASR Service Reads Attacker-Selected Local Files
scripts/server/tts-base-server.py:36Unauthenticated TTS Endpoint Allows Arbitrary Filesystem Writes
scripts/server/tts-base-server-openai.py:91Unauthenticated Model Inference Services Permit Resource Exhaustion
SKILL.md:454Persistent Root Services Exceed the Skill's Minimum Privilege Requirements
scripts/tools/tts-base.py:80Remote Mode Uploads Voice Biometrics and Transcripts to Arbitrary Plaintext Endpoints
scripts/server/tts-base-server-openai.py:423Unsafe Deserialization of Voice Clone Files with torch.load
setup.sh:64Unpinned Dependencies and Model Revisions Create Supply-Chain Risk
The configuration embeds multiple live secrets directly in the file, including Feishu app secrets, a gateway auth token, skill API keys, and a Tavily API key. Storing credentials in a skill/config file creates immediate secret exposure risk through source control leaks, backups, logs, local file disclosure, or unintended sharing, and these values could be used to impersonate services or access connected systems.
os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.
# Always use venv if available and not already active
if not os.environ.get("QWEN_TTS_VENV_ACTIVE") and VENV_PYTHON.exists():
os.environ["QWEN_TTS_VENV_ACTIVE"] = "1"
os.execv(str(VENV_PYTHON), [str(VENV_PYTHON)] + sys.argv)
# Check for remote mode
REMOTE_URL = os.environ.get("QWEN_TTS_REMOTE")
The skill is documented to automatically transcribe incoming Feishu voice messages, locally download/process them, and synthesize replies, but it provides no privacy notice or user-consent guidance. This is risky because users may not realize their audio is being stored and transformed, creating privacy, compliance, and surveillance concerns even if processing is local.
The README promotes cloning arbitrary voices and custom voice embeddings without any consent, impersonation, or abuse warning. In a voice-chat skill, this materially increases misuse risk because operators may deploy impersonation-capable features without guardrails, policy checks, or user disclosure.
The documentation advertises the skill as 'completely offline' and '无需任何云端 API', but the setup explicitly requires downloading models from Hugging Face and even allows repo IDs that can trigger automatic remote downloads at runtime. This is misleading security documentation: operators may deploy it under the false assumption that no network access or supply-chain exposure exists, reducing scrutiny of outbound access and model provenance.
The skill promotes arbitrary voice cloning without any warning about consent, impersonation, or misuse risks. In a messaging/voice-reply context, this can facilitate deceptive impersonation, privacy abuse, or unauthorized use of another person's voice, especially if users are encouraged to clone '任意人声'.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
source venv/bin/activate
# 启动 Whisper ASR 服务(端口 8001)
nohup python scripts/server/whisper-server.py --port 8001 > /tmp/whisper-server.log 2>&1 &
# 启动 Qwen3-TTS 服务(端口 8000,使用 OpenAI 兼容 API)
nohup python scripts/server/tts-base-server-openai.py --port 8000 --clone voice_embedings/huopo_kexin.pt > /tmp/tts-server.log 2>&1 &
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 检查 Whisper 服务
curl http://localhost:8001/
# 检查 TTS 服务
curl http://localhost:8000/
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 检查 Whisper 服务
curl http://localhost:8001/
# 检查 TTS 服务
curl http://localhost:8000/
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sudo systemctl daemon-reload
sudo systemctl enable openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl start openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
sudo systemctl status openclaw-feishu-voice-free-whisper openclaw-feishu-voice-free-tts
No suspicious patterns detected.