T09 · Insecure Skill Coding Practices
- Location
SKILL.md:48- Finding
Credential Scans Expose Complete Secret Values in Command Output
- Content
View full analysis
/dev/null ``` ```bash # 5. Log file leaks (full token68 charset) grep -rnP '[Bb]earer\s+[\w\-\.+/=~]{16,}|[a-f0-9]{32,}' \ ~/.openclaw/logs/ --include="*.log" 2>/dev/null ``` ### Technical Analysis The prescribed recursive `grep` commands print every matching line without redacting the matched credential. If a JSON configuration or log entry contains a token, API key, Bearer credential, or long hexadecimal secret, the complete line—and potentially the complete credential—is written to standard output. When this Skill is executed through an AI agent, terminal recorder, CI job, or other automation system, that output may enter model context, conversation history, execution logs, telemetry, or other records. The validation process therefore creates an additional plaintext copy of the sensitive data it is intended to protect. Redirecting standard error to `/dev/null` does not mitigate this issue because successful matches are emitted through standard output. ### Attack Path 1. A token or API credential is present in `~/.openclaw/*.json` or `~/.openclaw/logs/*.log`. 2. A user invokes the credential-hygiene Skill. 3. The agent runs one of the documented recursive `grep` commands. 4. `grep` prints the complete matching line, including the credential. 5. The command output is captured in an agent transcript, terminal log, CI artifact, telemetry system, or other downstream record. 6. A party with access to that record can recover and use the exposed credential until it is revoked or expires. ### Impact Assessment An attacker does not directly gain operating-system privileges ...[truncated 424 chars]- Remediation
View remediation
