T09 · Insecure Skill Coding Practices
- Location
main.py:47- Finding
Automatic publication of the project root may expose credentials and generated data
- Content
View full analysis
Vulnerability Details
File Location:
main.py:47-53
Related Location:SKILL.md:24-26
Vulnerability Type: Sensitive data exposure through overbroad publication scope
Risk Level: HighVulnerable Code
main.py:47-53:python def publish_skill_to_clawhub(): print("Publishing workflow as ClawHub skill...") result = subprocess.run([ "clawhub", "publish", ".", "--slug", "gog-sales-analytics", "--name", "GOG Weekly Sales Analytics", "--version", "1.2.3",The documented setup in
SKILL.md:24-26places credentials in the project root:bash cp .env.example .env # Fill in API keys in .env pip install -r requirements.txtTechnical Analysis
The workflow instructs users to create a credential-bearing
.envfile in the project root and later invokesclawhub publish ., passing that entire root directory as the publication source. No publication allowlist or ignore file exists in the audited project.The same directory also receives runtime-generated files under
data/, including scraped JSON and Gemini-generated Markdown reports. Consequently, publication safety depends on undocumented behavior of the externalclawhubexecutable rather than an explicit security boundary enforced by this project.Although publishing the reusable Skill is declared functionality, publishing the complete mutable working directory exceeds the minimum scope needed. Only static Skill source and configuration files need to be distributed.
Attack Path
- A user follows the documentation and creates
.envin the project root. - The user stores
GEMINI_API_KEY,FEISHU_APP_ID,FEISHU_APP_SECRET,FEISHU_DRIVE_FOLDER_ID, and potentiallyCLAWHUB_API_TOKENin that file. main.pygenerates scraped data and an analysis report beneath the same project directory.- The workflow invokes
clawhub publish .. - If the publisher does n ...[truncated 1065 chars]
- A user follows the documentation and creates
- Remediation
View remediation
Remediation Suggestions
- Create a clean staging directory containing only explicitly approved static files, then publish that directory instead of
".". - Add
.env,.env.*,data/, generated reports, caches, logs, virtual environments, and credential files to the publisher's verified exclusion mechanism. - Generate and inspect a publication manifest before upload. Abort if it contains secret-bearing or generated files.
- Add automated secret scanning before publication, checking both filenames and content patterns.
- Store credentials outside the publishable project tree where practical.
- Separate Skill publication from the recurring data-analysis workflow and require explicit confirmation before publishing.
- Rotate any credentials if they may already have been included in a published artifact.
- Create a clean staging directory containing only explicitly approved static files, then publish that directory instead of
