T09 · Insecure Skill Coding Practices
- Location
SKILL.md:9- Finding
Credential-Bearing MCP URL Creates a Bearer Secret Exposure Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:9-12, 20, 24, 35-38
Vulnerability Type: Credential exposure through URL-based authentication
Risk Level: HighVulnerable Code
yaml metadata: openclaw: emoji: "📣" homepage: https://adagent.10xboost.org requires: config: - MCP Connector link from adagent.10xboost.org (contains embedded auth token)markdown - **MCP link is a credential**: Your MCP Server URL (`https://adagent.10xboost.org/api/mcp/fb-ads/{user_id}/mcp`) contains your user ID for credential lookup. Treat it like a password — do not share it publicly.markdown - **No local credentials**: No local API keys, environment variables, or secrets are needed. All auth is embedded in the MCP link.markdown 3. **Get your MCP link**: Copy your Facebook Ads MCP Server URL from the dashboard 4. **Add to Claude**: Paste the MCP link as a Connector — no install, no API key neededTechnical Analysis
The skill explicitly states that authentication is embedded in the MCP URL and that the URL must be treated as a password. URL-based bearer credentials are vulnerable to incidental disclosure because complete URLs may be retained in browser history, connector configuration, application telemetry, HTTP access logs, reverse-proxy logs, diagnostic exports, screenshots, or support records.
The documentation is also ambiguous about the credential mechanism. The metadata says that the link contains an embedded authentication token, while the security section says that it contains a user ID used for credential lookup. If the user ID or opaque path is sufficient to authorize requests, possession of the URL effectively grants bearer access. No secondary authentication, expiration, client binding, or request-level authorization control is documented.
The endpoint exposes financially consequential operations, including campaign creation, budget management, and advertisement activation. Consequentl ...[truncated 1552 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace URL-embedded credentials with short-lived access tokens transmitted in an
Authorizationheader. - Ensure that the URL itself is non-secret and cannot independently authorize access.
- Make tokens narrowly scoped, time-limited, revocable, and bound to the intended user or connector client where practical.
- Redact authentication material from application, proxy, telemetry, and diagnostic logs.
- Provide users with an immediate mechanism to revoke and rotate MCP credentials.
- Require explicit user confirmation for operations that activate advertisements, modify budgets, or otherwise incur spending.
- Add configurable spending limits and transaction thresholds.
- Clearly document whether the URL contains a user identifier, an authentication token, or both.
- Do not allow a predictable user identifier to function as authorization.
- Monitor for anomalous clients, locations, and financially consequential operations, and notify users when sensitive actions occur.
- Replace URL-embedded credentials with short-lived access tokens transmitted in an
