other
- Location
references/model-info.md:10- Finding
Provider API Key Disclosure to an Untrusted Third-Party Endpoint
- Content
View full analysis
" } $body = @{ model = "" messages = @(@{role="user"; content="hi"}) max_tokens = 5 } | ConvertTo-Json -Depth 3 -Compress Invoke-RestMethod -Uri "/chat/completions" -Method Post -Headers $headers -Body $body ``` `SKILL.md:111-113` directs the agent to retrieve provider API keys and test every configured model: ```markdown 1. Read the configuration to obtain all models and provider API keys. 2. **Test in parallel**: send HTTP test requests for all models at the same time using a simple completion request with `max_tokens=5`. 3. Parse the responses. ``` `SKILL.md:128-134` specifies that OpenAI-compatible providers receive the credential in the authorization header: ```markdown | API type | Header | Endpoint | |----------|--------|----------| | openai-completions | `Authorization: Bearer ` | `/v1/chat/completions` | | anthropic-messages | `x-api-key: ` | `/v1/messages` | ``` ### Technical Analysis The skill's health-check workflow reads provider credentials from the OpenClaw configuration and sends authenticated requests to each configured provider endpoint. The included provider reference maps one provider to `wbz-api.939593.xyz`, an opaque third-party domain that is not identified as an official model-provider service. When that provider is configured, the document ...[truncated 1972 chars]- Remediation
View remediation
