T09 · Insecure Skill Coding Practices
- Location
SKILL.md:53- Finding
Hardcoded Shared Password for Client Workbooks
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 53–55
Vulnerability Type: Hardcoded credential and insecure password reuse
Risk Level: MediumVulnerable Code Snippet:
markdown ## Step 5: Deliver - Save to `/Users/synapsefirm/.openclaw/workspace/excel-projects/[filename].xlsx` - For client delivery: create a password-protected version with `Formly2026!` as default passwordTechnical Analysis
The skill embeds a static password directly in its instructions and directs the agent to reuse it for client-delivery workbooks. The password is visible to anyone who can inspect the skill and is identical across generated files. Consequently, workbook protection does not provide a meaningful confidentiality boundary against anyone familiar with this convention.
Reusing the password also expands the scope of a disclosure: knowledge of the credential for one workbook can provide access to every workbook generated according to the same instruction. The project does not include the referenced generator script, so the precise protection mechanism—including whether it provides encryption or only workbook/worksheet editing protection—could not be verified.
Attack Path
- The skill generates a client workbook and protects it using the documented default password.
- An attacker obtains the workbook through unauthorized file access, accidental disclosure, email forwarding, shared storage, or another distribution channel.
- The attacker reads the password from
SKILL.mdor learns the shared convention from a previously delivered workbook. - The attacker supplies
Formly2026!when prompted to open or modify the workbook. - If the implementation applies actual file encryption, the attacker decrypts and reads the workbook. If it applies only workbook or worksheet protection, the attacker bypasses the intended editing restrictions.
- The attacker repeats the same process against other workbooks pro ...[truncated 787 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the hardcoded default password from
SKILL.md. - Generate a unique password for every protected workbook using a cryptographically secure random-number generator.
- Use a sufficiently long random value, such as at least 16 characters containing multiple character classes, or an equivalently strong generated passphrase.
- Do not write generated passwords to source files, logs, workbook metadata, command histories, or predictable output files.
- Deliver the password through a secure channel separate from the workbook.
- Confirm that the selected Excel library and workflow provide authenticated file encryption rather than only worksheet, workbook-structure, or editing protection.
- Allow users to supply credentials through a secure secret-input mechanism when organizational password-management requirements apply.
- Rotate the exposed shared password immediately and re-protect previously delivered sensitive workbooks with unique credentials where feasible.
- Add automated checks that reject known default passwords and prevent password reuse across generated client files.
- Remove the hardcoded default password from
