T09 · Insecure Skill Coding Practices
- Location
src/notify/openclaw-push.ts:323- Finding
Gateway Authentication Token Exposed Through Child Process Arguments
- Content
View full analysis
= 1000 ? parsedTimeout : DEFAULT_WEBCHAT_INJECT_TIMEOUT_MS; const args = ["gateway", "call", "chat.inject", "--params", injectParams, "--json", "--timeout", String(timeoutMs)]; const token = process.env.OPENCLAW_GATEWAY_TOKEN?.trim(); if (token) args.push("--token", token); const r = spawnSync(bin, args, { encoding: "utf8", maxBuffer: 16 * 1024 * 1024, env: { ...process.env }, }); ``` ### Technical Analysis The implementation reads `OPENCLAW_GATEWAY_TOKEN` from the environment and appends it to the command-line argument vector using `--token`. Command-line arguments can be exposed through operating-system process inspection interfaces, process-monitoring software, audit logs, diagnostic tooling, or crash reports. On systems where processes belonging to the same user can inspect one another, another local process may observe the token while the `openclaw gateway call chat.inject` subprocess is running. Although the token already exists in the parent environment, converting it into a command-line argument unnecessarily increases its exposure surface. The token is authentication material and should not appear in argv. ### Attack Path 1. The farm worker performs an automatic WebChat notification. 2. `pushWebchatViaGatewayInject` reads `OPENCLAW_GATEWAY_TOKEN`. 3. The function starts an `openclaw` subprocess with the token included after `--token`. 4. A local attacker, monitoring agent, or compromised process with sufficient process-inspection access captures the subprocess arguments. 5. The attacker ex ...[truncated 539 chars]- Remediation
View remediation
