Back to skill

Security audit

Credential Hygiene Validator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent credential-audit helper, but its documented scans can print full secrets into the agent session or logs.

Review this skill before installing if your OpenClaw directory may contain live tokens. Use it only in a context where command output is not logged or shared, prefer redacted/manual checks, and rotate any credential that has already appeared in an agent transcript or terminal log.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:48
Finding

Credential Scans Expose Complete Secret Values in Command Output

Content
View full analysis
/dev/null ``` ```bash # 5. Log file leaks (full token68 charset) grep -rnP '[Bb]earer\s+[\w\-\.+/=~]{16,}|[a-f0-9]{32,}' \ ~/.openclaw/logs/ --include="*.log" 2>/dev/null ``` ### Technical Analysis The prescribed recursive `grep` commands print every matching line without redacting the matched credential. If a JSON configuration or log entry contains a token, API key, Bearer credential, or long hexadecimal secret, the complete line—and potentially the complete credential—is written to standard output. When this Skill is executed through an AI agent, terminal recorder, CI job, or other automation system, that output may enter model context, conversation history, execution logs, telemetry, or other records. The validation process therefore creates an additional plaintext copy of the sensitive data it is intended to protect. Redirecting standard error to `/dev/null` does not mitigate this issue because successful matches are emitted through standard output. ### Attack Path 1. A token or API credential is present in `~/.openclaw/*.json` or `~/.openclaw/logs/*.log`. 2. A user invokes the credential-hygiene Skill. 3. The agent runs one of the documented recursive `grep` commands. 4. `grep` prints the complete matching line, including the credential. 5. The command output is captured in an agent transcript, terminal log, CI artifact, telemetry system, or other downstream record. 6. A party with access to that record can recover and use the exposed credential until it is revoked or expires. ### Impact Assessment An attacker does not directly gain operating-system privileges ...[truncated 424 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:48
Finding

Overbroad Recursive Access to Credential-Bearing Configuration and Log Files

Content
View full analysis
/dev/null ``` ```bash # 5. Log file leaks (full token68 charset) grep -rnP '[Bb]earer\s+[\w\-\.+/=~]{16,}|[a-f0-9]{32,}' \ ~/.openclaw/logs/ --include="*.log" 2>/dev/null ``` ### Technical Analysis The Skill directs the agent to recursively inspect all JSON files under `~/.openclaw/` and all log files under `~/.openclaw/logs/`. This may read unrelated credentials and sensitive log content beyond the specific resource the user intended to audit. The access is disclosed, read-only, and limited to files readable by the invoking account. No privilege-escalation mechanism, permission bypass, network exfiltration, or persistence was identified. Nevertheless, the design does not apply data minimization or least-privilege principles: it exposes the agent to credential values when metadata-only or narrowly scoped checks would often be sufficient. ### Attack Path 1. The OpenClaw directory contains multiple JSON or log files, including files unrelated to the credential selected for review. 2. The user requests a credential-hygiene check. 3. The documented recursive searches inspect every matching file beneath the designated directories. 4. Sensitive values from unrelated files enter the tool-output and agent-processing boundary. 5. If the agent session, output consumer, or downstream logging system is compromised or insufficiently protected, those unrelated credentials may be disclosed. ### Impact Assessment The commands cannot read files that the invoking user is not already authorized to access, so they do not independently elevate local privileges. The affected scope is the set of readabl ...[truncated 348 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
## What it checks

1. **File permissions** -- config files should be 600 or 700, not world-readable
2. **Plaintext tokens** -- scans for hex tokens, JWTs (base64url with dots), Bearer strings, and API keys
3. **Git repo contamination** -- whether the config directory sits inside a git working tree
4. **Gitignore coverage** -- whether .gitignore excludes credential paths

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
4. **Gitignore coverage** -- whether .gitignore excludes credential paths
5. **Log file leaks** -- tokens appearing in log output (checks all formats: hex, JWT, Bearer per RFC 6750)
6. **Token age** -- warns if tokens have not been rotated recently
7. **Atomic write safety** -- checks if config backup exists (indicator of safe write patterns)

## When to use it

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

find ~/.openclaw/openclaw.json -mtime +90 -print 2>/dev/null

If output: token has not been rotated in 90+ days

7. Backup file exists (atomic write indicator)

ls ~/.openclaw/openclaw.json.bak 2>/dev/null && echo "backup present" || echo "no backup"

text

Static analysis

No suspicious patterns detected.