T09 · Insecure Skill Coding Practices
- Location
mcp/docparse.py:305- Finding
Document Contents and API Credentials May Be Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real remote document parser, but it needs Review because it can upload readable local documents over HTTP and stores service credentials in local configuration.
Install only if you trust the remote parsing service and its network path. Treat every parsed file as uploaded to that service, avoid sensitive documents unless HTTPS and retention policies are clear, restrict the service to approved document directories, and avoid putting real API keys in command lines, dry-run logs, .env files, or broadly readable OpenClaw config.
mcp/docparse.py:305Document Contents and API Credentials May Be Transmitted over Plaintext HTTP
mcp/docparse.py:174Unrestricted Readable File Paths Can Be Uploaded to the Remote Parsing Service
setup.py:91Installer Persists API Credentials in Plaintext and Exposes Them in Dry-Run Output
requirements.txt:1Unpinned Dependencies Are Installed without Artifact Integrity Verification
The skill is presented as simple document parsing, but its instructions extend into package installation, config discovery, environment inspection, and modification of local/OpenClaw configuration. That mismatch can cause users or orchestrators to grant broader trust than warranted, enabling stealthy persistence, secret collection, or system reconfiguration beyond OCR functionality.
The skill sends user document contents to a remote parsing service but does not present a clear user-facing warning at the trigger/description level. This is dangerous because documents often contain confidential data, and users may assume local processing unless remote transfer is prominently disclosed before use.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Returns a dict of key=value pairs, ignoring comments and blank lines.
"""
skill_dir = _SCRIPT_DIR.parent # mcp/ to docparse/
env_path = skill_dir / ".env"
env_vars = {}
if env_path.is_file():
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Returns a dict of key=value pairs, ignoring comments and blank lines.
"""
skill_dir = _SCRIPT_DIR.parent # mcp/ to docparse/
env_path = skill_dir / ".env"
env_vars = {}
if env_path.is_file():
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
功能:
1. 自动识别 OpenClaw 安装路径与 workspace 位置
2. 安装 Python 依赖(fastmcp, mcp)
3. 创建 .env 配置文件(如不存在)
4. 将 MCP Server 配置注入 openclaw.json
5. 检测并修复 docparse.py 中硬编码的路径,使其自适应
The skill declares no explicit tool scope or permissions despite instructing use of environment variables, filesystem access, network connectivity, shell commands, and file writes. In an agent setting this over-privileges the skill, making unintended config changes, secret access, or remote exfiltration of document data more likely if the skill is invoked broadly or misused.
The trigger terms include common verbs like 'read' and 'extract text,' which can cause accidental activation in unrelated conversations. Because this skill sends documents to a remote service and may perform setup actions, over-broad invocation increases the chance of unintended data handling or execution of privileged actions.
The natural-language instructions, examples, and user-facing outputs are entirely in Chinese, including mandated response text such as error and success messages. There is no indication that users may choose another language or that the locale restriction is required for a region-specific compliance purpose.
The activation guidance lacks crisp boundaries for when not to run, beyond a limited unsupported-format note. In an agent environment, ambiguous routing can cause the skill to process sensitive files or initiate remote parsing when the user only asked for summarization, viewing, or local-only handling.
No suspicious patterns detected.