T09 · Insecure Skill Coding Practices
- Location
send_weixin.sh:11- Finding
Webhook Secret Exposed Through Process Arguments and Persistent Scheduled-Task Configuration
- Content
View full analysis
[mentioned_list] [mentioned_mobile_list]" echo "示例: $0 'key' 'text' '消息内容' 'user1,user2' '13800001111,@all'" exit 1 fi # 定义变量 WEBHOOK_KEY="$1" MSGTYPE="$2" CONTENT="$3" MENTIONED_LIST="$4" MENTIONED_MOBILE_LIST="$5" ``` `SKILL.md:48-75` documents embedding the webhook key directly in persistent task messages: ```bash openclaw cron add \ --cron "0 14 * * *" \ --agent main \ --message "执行:~/.openclaw/workspace/skills/weixin-webhook/send_weixin.sh 'your_key' 'text' '【健康提醒】请做提肛运动!' 'liujie'" \ --name "daily_kegel" \ --description "每日提肛提醒" \ --no-deliver openclaw cron add \ --cron "0 9 * * *" \ --agent main \ --message "执行:~/.openclaw/workspace/skills/weixin-webhook/send_weixin.sh 'your_key' 'text' '晨会即将开始,请准时参加' '@all'" \ --name "morning_meeting" \ --description "晨会通知" \ --no-deliver openclaw cron add \ --cron "0 17 * * *" \ --agent main \ --message "执行:~/.openclaw/workspace/skills/weixin-webhook/send_weixin.sh 'your_key' 'markdown' '【日报提醒】请在18:00前提交日报。1. 今日完成2. 遇到问题3. 明日计划'" \ --name "daily_report" \ --description "日报提醒" \ --no-deliver ``` ### Technical Analysis The WeCom webhook key is a bearer credential: knowledge of the key is sufficient to submit messages to the associated group webhook. The script requires this credential as its first positional command-line argument. Command-line arguments can be exposed through process-inspection interfaces while the script and `curl` are running. Manual invocations can also remain in shell history. ...[truncated 1628 chars]- Remediation
View remediation
