T09 · Insecure Skill Coding Practices
- Location
harden.py:31- Finding
Sensitive credential files are created without restrictive permissions
- Content
View full analysis
Vulnerability Details
File Location:
harden.py:31-52andharden.py:97-119
Vulnerability Type: Insecure plaintext credential storage
Risk Level: MediumVulnerable Code
python def backup_config(self) -> Optional[Path]: """Create backup of current configuration""" if not self.config_file.exists(): print("[ERROR] openclaw.json not found") return None if self.dry_run: print(f"[DRY-RUN] Would create backup in: {self.backup_dir}") return None self.backup_dir.mkdir(exist_ok=True) timestamp = datetime.now().strftime('%Y%m%d_%H%M%S') backup_path = self.backup_dir / f"openclaw.json.backup.{timestamp}" try: with open(self.config_file, 'r', encoding='utf-8') as f: config = f.read() with open(backup_path, 'w', encoding='utf-8') as f: f.write(config) print(f"[BACKUP] Configuration backed up to: {backup_path}") return backup_pathpython env_file = self.openclaw_path / ".env" env_example = self.openclaw_path / ".env.example" if self.dry_run: print(f"[DRY-RUN] Would create: {env_file}") print(f"[DRY-RUN] Would create: {env_example}") return None # Generate .env file (actual credentials) lines = [ "# OpenClaw Environment Variables", f"# Generated: {datetime.now().isoformat()}", "# WARNING: Keep this file secure! Never commit to version control.", "", ] for key, value in credentials.items(): lines.append(f"{key}={value}") try: with open(env_file, 'w', encoding='utf-8') as f: f.write('\n'.join(lines)) print(f"[ENV] Created: {env_file}")Technical Analysis
The hardening process creates two additional plaintext copies of credentials:
- A complete backup of the original
openclaw.json, including all credentials it contained. - A
.envfile containing extracted Feishu cr ...[truncated 2010 chars]
- A complete backup of the original
- Remediation
View remediation
Remediation Suggestions
- Create sensitive files atomically with owner-only permissions. On POSIX systems, use
os.openwithO_CREAT | O_EXCL | O_WRONLYand mode0o600. - Create
security-backupswith mode0o700and verify the effective mode after creation. - If
.envor backup files already exist, verify ownership and permissions before overwriting them. - Apply platform-appropriate access control lists on Windows so only the current user can read the files.
- Avoid retaining plaintext backups by default. Require explicit consent or encrypt backups using a user-managed key.
- Implement a documented retention policy and provide a safe mechanism for deleting obsolete plaintext backups.
- Write files to a protected temporary file, flush and synchronize the content, then atomically rename the file into place.
- Update the documentation and permission metadata to disclose all credential-bearing files created by hardening.
- Create sensitive files atomically with owner-only permissions. On POSIX systems, use
