T09 · Insecure Skill Coding Practices
- Location
references/setup.md:28- Finding
Privy application secret stored in plaintext and exposed through command-line arguments
- Content
View full analysis
Vulnerability Details
File Location:
references/setup.md:28-64
Vulnerability Type: Plaintext credential storage and unsafe command-line secret handling
Risk Level: MediumVulnerable Code
json { "gateway": { "env": { "PRIVY_APP_ID": "your-app-id", "PRIVY_APP_SECRET": "your-app-secret" } } }bash export PRIVY_APP_ID="your-app-id" export PRIVY_APP_SECRET="your-app-secret"bash curl -X GET "https://api.privy.io/v1/wallets" \ --user "$PRIVY_APP_ID:$PRIVY_APP_SECRET" \ -H "privy-app-id: $PRIVY_APP_ID" \ -H "Content-Type: application/json"Equivalent patterns also appear in
README.md:57-62,README.md:113-123,SKILL.md:111-115,SKILL.md:149-153, andSKILL.md:168-172.Technical Analysis
The setup instructions recommend storing
PRIVY_APP_SECRETdirectly in a plaintext OpenClaw configuration file or persistent shell profile. Anyone with read access to these files, their backups, diagnostic bundles, or editor history may recover the credential.The secret is then expanded into the argument supplied to
curl --user. Depending on the operating system and execution environment, expanded command-line arguments may be observable through process inspection, audit tooling, shell tracing, crash diagnostics, or command-capture systems.This is especially sensitive because
references/security.mdstates that the Privy application secret can create wallets, sign transactions, and potentially drain wallets associated with the application.Attack Path
- A local attacker, compromised plugin, backup reader, or process with sufficient local visibility reads
~/.openclaw/openclaw.json, a shell profile, or captured process arguments. - The attacker extracts
PRIVY_APP_IDandPRIVY_APP_SECRET. - The attacker authenticates directly to the Privy API using HTTP Basic authentication.
- The attacker enumerates wallets o ...[truncated 690 chars]
- A local attacker, compromised plugin, backup reader, or process with sufficient local visibility reads
- Remediation
View remediation
Remediation Suggestions
- Store the secret in an operating-system credential vault, managed secret service, or equivalent protected runtime secret provider.
- Do not place long-lived secrets in shell profiles, source-controlled files, general OpenClaw configuration, command history, or diagnostic output.
- Avoid expanding secrets into process arguments. Use an authentication mechanism that reads protected credential material without exposing it in the process list.
- Disable shell tracing before handling credentials and ensure commands are not written to history or operational telemetry.
- If file-based storage is unavoidable, create a dedicated credential file with owner-only permissions, such as mode
0600, and exclude it from source control and backups where possible. - Use separately scoped credentials for development and production, applying the minimum Privy permissions required.
- Configure restrictive, server-enforced wallet policies and authorization-key quorums so compromise of one credential cannot authorize unrestricted transactions.
- Rotate the application secret immediately if it may have appeared in logs, process captures, shell history, or shared configuration.
