T09 · Insecure Skill Coding Practices
- Location
scripts/openclaw-openai-accounts.py:681- Finding
OAuth Access Token Disclosure Through an Unrestricted Usage API Endpoint
- Content
View full analysis
tuple[dict[str, Any], dict[str, Any]]: token = profile.get('access') account_id = profile.get('accountId') or current_identity(profile).get('accountId') if not token: return {}, {'status': 'auth-invalid', 'reason': 'missing-access-token'} headers = { 'Authorization': f'Bearer {token}', 'User-Agent': 'CodexBar', 'Accept': 'application/json', } if account_id: headers['ChatGPT-Account-Id'] = str(account_id) req = urllib.request.Request(CODEX_USAGE_URL, headers=headers, method='GET') try: with urllib.request.urlopen(req, timeout=timeout_sec) as resp: raw = resp.read().decode('utf-8', errors='ignore') ``` ### Technical Analysis The quota-probing function sends an OpenAI OAuth bearer access token in the `Authorization` header. It may also send the associated ChatGPT account ID. While the default endpoint is an expected `chatgpt.com` endpoint, the destination can be replaced without validation through the `OPENCLAW_CODEX_USAGE_URL` environment variable. The implementation does not: - Require HTTPS. - Restrict the hostname to an approved OpenAI domain. - Validate the destination path or origin. - Separate production credential-bearing requests from test endpoint overrides. - Explicitly prevent credential-bearing requests from following redirects to another origin. Consequently, any party capable of influencing the script's inherited environment can redirect quota probes to a server under tha ...[truncated 2112 chars]- Remediation
View remediation
