Back to skill

Security audit

secret-drop

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real secret-transfer tool, but it can read local secrets and upload them to a third-party one-time-link service when asked.

Install only in environments where chat users are trusted operators or where you can enforce who may request outbound shares. Prefer self-hosted or organization-approved providers, restrict which files or secret names agents may export, and avoid using the outbound share feature for production credentials unless there is a separate approval process.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (35)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

│ │ │ (silent CLI ingest) ▼ ▼ [Link Burned] ~/.openclaw/.env (atomic mode 0600)

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · examples/agent-requests.md (reported line 50)May include surrounding context.

│ │ │ (silent CLI ingest) ▼ ▼ [Link Burned] ~/.openclaw/.env (atomic mode 0600)

text

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documentation permits writing secrets to files, modifying configuration/state, and optionally restarting the gateway, yet frames itself mainly as one-time link handling. Those side effects materially increase operational and security impact because a misused or compromised skill could persist secrets locally and alter runtime state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documentation permits writing secrets to files, modifying configuration/state, and optionally restarting the gateway, yet frames itself mainly as one-time link handling. Those side effects materially increase operational and security impact because a misused or compromised skill could persist secrets locally and alter runtime state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill documentation permits writing secrets to files, modifying configuration/state, and optionally restarting the gateway, yet frames itself mainly as one-time link handling. Those side effects materially increase operational and security impact because a misused or compromised skill could persist secrets locally and alter runtime state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill documentation permits writing secrets to files, modifying configuration/state, and optionally restarting the gateway, yet frames itself mainly as one-time link handling. Those side effects materially increase operational and security impact because a misused or compromised skill could persist secrets locally and alter runtime state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documentation permits writing secrets to files, modifying configuration/state, and optionally restarting the gateway, yet frames itself mainly as one-time link handling. Those side effects materially increase operational and security impact because a misused or compromised skill could persist secrets locally and alter runtime state.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The outbound procedure explicitly supports reading named secrets from ~/.openclaw/.env and returning a one-time URL. Even if plaintext is not echoed, this is credential access capability, and if invoked by an unauthorized requester or without strong access checks it enables exfiltration of stored secrets.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

Use only the local source authorized by the request:

bash
# ~/.openclaw/.env
python3 <skill-directory>/scripts/secret-drop share \
  --from openclaw-env \
  --name "VARIABLE_NAME" \

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill allows reading secrets from arbitrary project dotenv paths and exporting them via a one-time link. This is sensitive because project .env files commonly contain production credentials, and path-based access broadens exposure to many local secrets if the skill is misused.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
# Project dotenv
python3 <skill-directory>/scripts/secret-drop share \
  --from dotenv \
  --path "/path/to/.env" \
  --name "VARIABLE_NAME" \
  --json

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

This example shows reading a database credential from /srv/acme/.env and sharing it outward, which is a direct credential disclosure workflow. The skill context makes this more dangerous because it normalizes secret extraction from local storage and transmission to a requester without any visible access-control, redaction, or out-of-band approval step.

Content

Scanner excerpt · examples/agent-requests.md (reported line 64)May include surrounding context.

bash
python3 <skill-directory>/scripts/secret-drop share \
  --from dotenv \
  --path /srv/acme/.env \
  --name DATABASE_URL \
  --json

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 151)May include surrounding context.

md
def default_openclaw_env_path() -> Path:
    state_dir = os.environ.get("OPENCLAW_STATE_DIR") or str(Path.home() / ".openclaw")
    return Path(state_dir).expanduser() / ".env"


def format_assignment(name: str, value: str) -> str:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · secret_drop/dotenv_file.py (reported line 27)May include surrounding context.

python
def default_openclaw_env_path() -> Path:
    state_dir = os.environ.get("OPENCLAW_STATE_DIR") or str(Path.home() / ".openclaw")
    return Path(state_dir).expanduser() / ".env"


def format_assignment(name: str, value: str) -> str:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_secret_drop.py (reported line 116)May include surrounding context.

python
def default_openclaw_env_path() -> Path:
    state_dir = os.environ.get("OPENCLAW_STATE_DIR") or str(Path.home() / ".openclaw")
    return Path(state_dir).expanduser() / ".env"


def format_assignment(name: str, value: str) -> str:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_secret_drop.py (reported line 195)May include surrounding context.

python
def default_openclaw_env_path() -> Path:
    state_dir = os.environ.get("OPENCLAW_STATE_DIR") or str(Path.home() / ".openclaw")
    return Path(state_dir).expanduser() / ".env"


def format_assignment(name: str, value: str) -> str:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_secret_drop.py (reported line 451)May include surrounding context.

python
def default_openclaw_env_path() -> Path:
    state_dir = os.environ.get("OPENCLAW_STATE_DIR") or str(Path.home() / ".openclaw")
    return Path(state_dir).expanduser() / ".env"


def format_assignment(name: str, value: str) -> str:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_secret_drop.py (reported line 486)May include surrounding context.

python
def default_openclaw_env_path() -> Path:
    state_dir = os.environ.get("OPENCLAW_STATE_DIR") or str(Path.home() / ".openclaw")
    return Path(state_dir).expanduser() / ".env"


def format_assignment(name: str, value: str) -> str:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · secret_drop/redact.py (reported line 44)May include surrounding context.

python
netloc = parts.hostname or ""
        if parts.port:
            netloc = f"{netloc}:{parts.port}"
        # Query values can carry passphrases or access tokens. Error messages do not
        # need them, so drop the whole query instead of trying to classify every key.
        return urlunsplit((parts.scheme, netloc, _sanitize_path(parts.path), "", ""))
    except Exception:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_secret_drop.py (reported line 208)May include surrounding context.

python
)

    def test_rejects_symlink_secret_source(self) -> None:
        target = self.root / "secret.txt"
        target.write_text("hidden-secret", encoding="utf-8")
        link = self.root / "secret-link.txt"
        link.symlink_to(target)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_secret_drop.py (reported line 216)May include surrounding context.

python
)

    def test_rejects_symlink_secret_source(self) -> None:
        target = self.root / "secret.txt"
        target.write_text("hidden-secret", encoding="utf-8")
        link = self.root / "secret-link.txt"
        link.symlink_to(target)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_secret_drop.py (reported line 432)May include surrounding context.

python
)

    def test_rejects_symlink_secret_source(self) -> None:
        target = self.root / "secret.txt"
        target.write_text("hidden-secret", encoding="utf-8")
        link = self.root / "secret-link.txt"
        link.symlink_to(target)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CHANGELOG.md (reported line 9)May include surrounding context.

md
## [0.2.0] - 2026-09-19

- Add `secret-drop share` command to create short-lived Password Pusher links from local `.env`, `~/.openclaw/.env`, or raw secret files without exposing plaintext.
- Rewrite `SKILL.md` into a concise decision matrix for AI agents covering inbound drops, chat masking recovery, and outbound sharing.
- Require Password Pusher retrieval-step handovers to preserve the API-returned
  `html_url` ending in `/r`; bare `/p/<token>` links can be consumed by messenger

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The workflow intentionally creates retrievable secret-bearing links and sends them through chat platforms, which introduces a persistence and interception surface outside the host even if links are single-use and expiring. Link previews, message retention, compromised chat accounts, provider-side logging, or race conditions on retrieval could allow unauthorized access before the intended agent consumes the secret.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

(atomic mode 0600)

text

1. You create an expiring single-use link on an established secret sharing service.
2. You send only the retrieval-step link to your agent in chat: `"Set OPENROUTER_API_KEY from https://eu.pwpush.com/p/abc12345/r"`.
3. The agent invokes `secret-drop`.
4. The CLI fetches the secret in-process and writes it atomically to the desired target (`~/.openclaw/.env`, local `.env`, or OpenClaw SQLite secret store). A provider configured for one retrieval consumes or expires the drop.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 100)May include surrounding context.

git clone https://github.com/sprintberlin/openclaw-secret-drop.git cd openclaw-secret-drop pip install -r requirements.txt sudo ln -s $(pwd)/scripts/secret-drop /usr/local/bin/secret-drop

text

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly documents a feature to share secrets outbound through third-party services, but it does not prominently warn that this transmits plaintext secrets off-host to external infrastructure and may place them under another party's control. Even if the service is designed for one-time secret exchange, users may underestimate the trust, retention, logging, jurisdiction, and compromise risks of using external secret-sharing providers.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 176)May include surrounding context.

md
## Security Guarantees

- **No Output Leakage:** The CLI strictly suppresses secrets on `stdout`, `stderr`, and exit codes.
- **Atomic File Writes:** Writes use temporary files in the target directory, `fchmod 0600`, `fsync`, and atomic `os.replace`. The destination is checked again with `lstat` immediately before replacement to reject a late symlink swap.
- **SSRF Guardrails:** The HTTP client requires HTTPS, rejects URL userinfo, validates every redirect, and rejects the request if any resolved A/AAAA result is private, loopback, link-local, multicast, reserved, unspecified, or scoped. Self-hosted private instances require explicit `--allow-private-host`. This is defense in depth, not a replacement for host network policy.
- **URL Redaction:** Provider identifiers in `/p/<token>` and `/g/<id>` paths, query strings, and fragments are masked in status and error output.
- **No false erase promise:** Python cannot guarantee erasure of immutable strings or SSD/journal history. The design minimizes copies and never emits plaintext; use a protected OpenClaw store or external secret manager when stronger storage isolation is required.

Static analysis

No suspicious patterns detected.