T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
IPinfo API Token Exposure Through URL Query Parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a simple IP geolocation helper whose network calls and optional token use match its stated purpose, though users should be aware of privacy and token-handling risks.
Install only if you are comfortable sending queried IP addresses, including your current public IP when using that example, to ipinfo.io. Prefer storing IPINFO_TOKEN in the OpenClaw dashboard or a protected environment variable, avoid pasting real tokens directly into commands or source files, and rotate the token if an authenticated URL is exposed.
SKILL.md:20IPinfo API Token Exposure Through URL Query Parameters
The skill encourages sending user-supplied IPs and even the current machine's IP to ipinfo.io, but it does not clearly warn that this transmits potentially sensitive network metadata to a third-party service. In security, enterprise, or privacy-sensitive environments, exposing internal, analyst, or user IP information without explicit disclosure or consent can violate policy, leak infrastructure details, or create unnecessary data-sharing risk.
No suspicious patterns detected.