T09 · Insecure Skill Coding Practices
- Location
scripts/_lib.mjs:9- Finding
OAuth Token Cache and Profile Files Are Created Without Explicit Restrictive Permissions
- Content
View full analysis
{ if (ctx.cacheHasChanged) { cache = ctx.tokenCache.serialize(); fs.writeFileSync(cachePath, cache, 'utf8'); } }, ``` `scripts/setup.mjs:96-100`: ```js afterCacheAccess: async (ctx) => { if (ctx.cacheHasChanged) { cache = ctx.tokenCache.serialize(); fs.writeFileSync(cachePath, cache, 'utf8'); } }, ``` ### Technical Analysis The Skill stores its MSAL token cache under `~/.openclaw/secrets/m365-mailbox/`. The cache can contain access tokens, refresh-token material, account identifiers, and other authentication state. The directory is created without an explicit `0700` mode, while profile and token-cache files are written without an explicit `0600` mode. Their effective permissions therefore depend on the runtime environment's umask and any permissions already present on the directory or files. A permissive umask or pre-existing broadly accessible file can leave mailbox credentials readable by other local users. The implementation also rewrites existing token-cache files without verifying or correcting their permissions. Merely placing credentials in a directory named `secrets` does not enf ...[truncated 1500 chars]- Remediation
View remediation
