T09 · Insecure Skill Coding Practices
- Location
SKILL.md:31- Finding
Shared Plaintext Storage of an Unnecessary Authentication Cookie
- Content
View full analysis
" # Sam's Club membership account SAM_PHONE="" ``` ### Technical Analysis Authentication cookies are bearer credentials: any party that obtains a valid cookie may be able to impersonate the authenticated user without knowing the account password. Storing such a credential as plaintext in `~/.openclaw/workspace/.env` creates unnecessary exposure to other local processes, Skills, workspace readers, backups, diagnostic tools, or accidental source-control inclusion. The implemented script does not use the cookie to authenticate, query prices, track orders, or place orders. It only reads the named environment variables and reports whether they are present: ```python cookie = os.environ.get("XIANYU_COOKIE", "") sam_phone = os.environ.get("SAM_PHONE", "") ``` Consequently, requesting and retaining `XIANYU_COOKIE` exceeds the minimum privileges required by the current manual-ordering and configuration-check functionality. Although the script does not print the secret value or directly read the `.env` file, the documentation encourages users to create the sensitive plaintext storage condition. ### Attack Path 1. A user follows `SKILL.md` and places a valid Xianyu session cookie in `~/.openclaw/workspace/.env`. 2. The file is left accessible to another local user, process, Skill, backup service, diagnostic utility, or workspace synchronization mechanism. 3. That party reads or otherwise captures `XIANYU_COOK ...[truncated 924 chars]- Remediation
View remediation
