T09 · Insecure Skill Coding Practices
- Location
index.js:40- Finding
Camera Access Token Stored in a Plaintext Configuration File Without Enforced Restrictive Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed workplace camera-monitoring tool, but it handles sensitive surveillance credentials and employee images with weak scoping and incomplete privacy safeguards.
Install only if you have clear legal authority to monitor the covered workplace, have notified or obtained consent from affected people where required, and can protect camera tokens. Prefer a version that stores tokens in a secret manager, restricts config file permissions, avoids generic exec for capture, documents image retention and external sharing, and scopes alert recipients and camera devices explicitly.
index.js:40Camera Access Token Stored in a Plaintext Configuration File Without Enforced Restrictive Permissions
The declared description presents a complete intelligent inspection system with guided setup, configurable tasks, image capture, AI analysis, and alerting. In contrast, the supplied code is mostly a scaffold: it reads/writes config.json, initializes placeholder settings, generates a timestamp-based fileId, and logs that capture/analysis/alerting will be handled elsewhere. There is no implementation of camera access, no calls to AI services, no alert delivery logic, and no Feishu integration. Because the primary described capabilities are not actually present in this code chunk, the description materially overstates what the code does.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Custom HTTP-based capture endpoints
### Authentication Requirements
- Camera API access tokens or credentials
- Feishu bot permissions (if using Feishu alerts)
### OpenClaw Requirements
The setup flow instructs collection and local storage of access tokens in a workspace JSON file. Storing sensitive camera/API credentials in plaintext under a predictable path can expose them to other local processes, users, backups, or accidental disclosure, potentially enabling unauthorized camera access or further compromise.
### 1. Initial Setup (First Run)
When the skill runs for the first time:
1. Prompt user for camera system type
2. Collect API endpoint, access token, device serial, channel number
3. Ask for default inspection prompt template
4. Confirm alert channel preferences
5. Save configuration to `~/.openclaw/workspace/intelligent-inspection-config.json`
The README explicitly describes camera-based workplace monitoring, snapshot capture, AI analysis, and Feishu alerting, but provides no warning about privacy, consent, retention, or data-sharing implications. In a workplace surveillance context, missing privacy and data-handling disclosures can lead to covert monitoring, unauthorized collection of employee images, and compliance violations, making the skill materially riskier than a generic image-processing tool.
The skill is designed for employee surveillance, image capture, AI analysis, and alerting, but it lacks an explicit warning about monitoring, consent, and regulatory obligations. In this context, omission of clear notice increases the risk of misuse, noncompliant workplace surveillance, and unauthorized collection or sharing of employee images.
The privacy section states there is no data retention beyond immediate execution, but earlier sections explicitly say the skill saves configuration, including camera access tokens and device details, to ~/.openclaw/workspace/intelligent-inspection-config.json. This is an active contradiction between the documentation's privacy claim and the documented behavior of persistent local storage.
Documenting use of a generic exec tool for camera capture expands the skill's effective power beyond narrowly scoped image acquisition. If implemented without strict command allowlisting and argument validation, this could enable arbitrary command execution, especially because camera endpoints and parameters are user-supplied during setup.
The defaultPrompt is written entirely in Chinese and does not indicate that language selection is optional, user-configurable, or justified by a region-specific requirement. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.
The config contains natural-language instructions and alert messages only in Chinese, including mandated response terms ('离岗'/'在岗'). This forces a specific language/locale behavior without any indication that users can choose another language or that the skill is restricted to a Chinese-language deployment context.
The skill persists its configuration to a local config.json file, and the configuration structure explicitly includes sensitive camera credentials such as an accessToken. Storing such secrets on disk without encryption, permission hardening, or an explicit warning increases the risk of credential disclosure through local file access, backups, logs, or accidental sharing.
The embedded natural-language prompt instructs the model to respond only with the Chinese outputs "离岗" or "在岗". This imposes a specific language/locale in the skill behavior without any user opt-in or documented region-specific justification.
Natural-language policy requires avoiding forced language or locale constraints unless users are given a choice or the limitation is clearly justified. This README is written entirely in Chinese and does not indicate that other languages are supported or that the skill is region-specific.
The default prompt template requires the model to reply with specific Chinese terms ('离岗' or '在岗'), and the examples are also Chinese-only. This imposes a language choice in the skill content without indicating that users can opt into another language or locale.
This JSON manifest/config file includes a natural-language prompt but provides no surrounding constraint or alternative language handling. In a manifest-like file, hard-coding the interaction text without scope clarification can make the intended usage less specific and may contribute to ambiguous behavior in multilingual environments.
No suspicious patterns detected.