T09 · Insecure Skill Coding Practices
- Location
scripts/client.py:13- Finding
API credentials and user content are transmitted over cleartext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly fits its media-generation purpose, but it handles credentials, background watchers, and session data in ways that need careful review before installation.
Install only if you trust the easyclaw.bar relay and are comfortable with the skill uploading prompts/media, using OpenClaw credentials, creating cron watchers, and writing completion messages into sessions. Prefer waiting for a version that enforces HTTPS, avoids secrets in commands and URLs, scopes notifications to an explicit current-session token, and avoids direct transcript mutation.
scripts/client.py:13API credentials and user content are transmitted over cleartext HTTP
scripts/schedule_task_watch.py:267Platform and messaging credentials are persisted and printed in cron commands
scripts/schedule_task_watch.py:294Watcher setup reads global channel credentials and enumerates session stores across agents
scripts/cron_watch_task.py:200Watcher directly injects assistant messages into persistent conversation state
scripts/cron_watch_task.py:119Messaging device tokens are exposed in URL query strings
scripts/generate_video.py:296Reference images are transmitted twice in VEO multipart requests
The request target and credentials are derived from local configuration/environment and sent over the network without strong validation of the destination. An attacker who can influence server_url or related config can redirect device_id/device_token traffic to an attacker-controlled endpoint, causing credential exfiltration and unauthorized message access.
)
request = urllib.request.Request(f"{url}?{query}", method="GET")
try:
with urllib.request.urlopen(request) as response:
payload = _parse_json_response(response)
except urllib.error.HTTPError:
return []
声明描述的是一个面向图片/视频生成的多模型素材生产技能,但提供的代码片段仅是底层客户端组件。它负责配置 base URL、读取凭证、发送 JSON/multipart 请求、解析响应,以及对一个 veo2 自定义视频任务进行轮询获取状态。虽然其中出现 veo2 相关路径,可能是某类视频生成任务的配套接口,但该代码本身没有展示生成图片/视频的具体调用,也没有体现 banana、sora 等模型支持。因此,代码实际行为与声明的核心能力存在明显不一致:声明强调多模型媒体生成,代码体现的是平台通信和任务查询基础设施。
The declared description emphasizes media generation using image/video models. This code chunk does not generate images or videos directly. Its primary function is operational orchestration after a task has been submitted: checking task completion status, constructing completion/failure messages, storing notification state on disk, resolving inbound event IDs, replying through EasyClaw/ClawX bridge APIs, appending notifications to session files, and removing scheduled watcher jobs. While it is related to VEO-generated content workflows, the actual behavior is a background task monitor/notification component, which is a materially different capability than the declared media-generation purpose.
The description claims the skill can invoke Banana, Sora, and Veo models to generate image/video assets. However, the supplied code does not perform generation at all; it only retrieves the result of an already-created task, and the endpoint shown is specifically for Veo video fetches. This is a materially different primary purpose from media generation, so the description does not accurately represent the code chunk.
声明描述的核心能力是“调用多种模型生成图片/视频内容”。但代码中没有任何图片或视频生成模型调用逻辑,也没有 banana、sora、veo 推理请求或媒体生产处理。相反,代码的主要用途是调度一个后台 watcher:构造 OpenClaw cron create/add/edit/remove 命令,周期性检查异步 VEO relay task,并根据本地 session/config 和远程事件信息,将结果通知到会话文件、ClawX IM 或 easyclaw。其访问的资源包括本地会话状态、OpenClaw 配置、系统可执行文件定位、以及消息桥接 HTTP 接口,这些都与“生成图片视频素材”的声明不一致。因此这是明显的描述与行为不匹配。
The multipart upload routine reads arbitrary local files from paths supplied to the client and sends their full contents to a remote server, with no safety checks, consent gate, destination validation, or restriction to trusted paths. In this skill context, which is designed for image/video generation and asset production, file upload is expected functionality, but the combination with a hard-coded default remote host over plain HTTP makes unintended exfiltration of sensitive local files significantly more dangerous.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
prompt = str(args.prompt or "").strip()
if not prompt:
raise ValueError("Prompt is required in builder mode. Use --prompt or switch to raw payload mode.")
return prompt
def validate_file_paths(paths):
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
last_result: subprocess.CompletedProcess[str] | None = None
for base_command, extra_env in _openclaw_command_candidates():
command = [*base_command, *args]
env = os.environ.copy()
env.update(extra_env)
try:
result = subprocess.run(
The code reads session stores, session history files, and channel credentials/device tokens to infer reply targets and messaging context. For a media-generation skill, this is unnecessary access to sensitive local data and can enable surveillance of conversations, credential misuse, and covert message delivery.
This file implements cron job creation, editing, and removal plus notification routing, which is materially unrelated to the declared image/video generation purpose. Capability mismatch is dangerous because it hides persistence and background execution inside an apparently benign media skill, increasing the chance users authorize behavior they did not intend.
Without declared permissions the skill's intent is opaque and cannot be validated.
The file hard-codes Chinese for the display name and short description while using English for the default prompt, with no indication that users can choose their preferred language or locale. This can violate language/locale policy expectations when a skill imposes a specific language presentation without explicit opt-in.
The documentation explicitly states that relay logs record user identity, request parameters, response parameters, task IDs, success status, points cost, and timestamps, but provides no user-facing notice, minimization guidance, or retention limits. In an image/video generation skill, prompts and outputs may contain sensitive personal, commercial, or copyrighted material, so undocumented broad logging increases privacy and compliance risk.
The client sends API tokens or key/secret headers in outbound HTTP requests via request_json, but there is no confirmation prompt or user-facing warning that credentials and payload data will be transmitted to a remote platform. For code files, outbound network transmission of user or system data should have some visible disclosure unless clearly warned elsewhere or obviously implied by the skill purpose, which is not established in this file alone.
These functions query inbound bridge events and post text replies back to external messaging endpoints using device credentials. Messaging-bridge interaction is not an obvious requirement for a skill described only as generating image/video assets, so it represents an additional capability unrelated to the declared purpose.
The script transmits device credentials and generated message content to a configurable server_url without enforcing HTTPS or validating destination trust. If a misconfigured or attacker-controlled URL is supplied, credentials and notification contents could be exposed in transit or sent to an unauthorized endpoint.
fetch_easyclaw_events places device_id and device_token into the URL query string, which can be logged by proxies, servers, browser/history tooling, and process monitors. This is especially risky because the destination is configurable and the code does not enforce HTTPS, making credential leakage more likely.
append_session_notification writes to file paths supplied via command-line arguments with no restriction that they stay within an approved session directory. An attacker who can influence these arguments could overwrite or append to arbitrary user-accessible files, corrupt session data, or tamper with local state outside the skill's intended scope.
This function appends assistant messages to a session transcript file and rewrites the session store metadata, but there is no confirmation, print/log statement, or explanatory comment/docstring notifying users that local conversation files will be changed. File writes affecting session history fall under the missing-warning checks for code files when they occur without visible disclosure.
The manifest describes a skill for generating images and videos with models like banana, sora, and veo. This script primarily polls a task endpoint, persists watcher state, removes scheduled jobs, sends IM replies to external bridge APIs, and appends assistant messages into session transcript files, which is materially broader than direct media generation behavior.
The script reads local files, base64-encodes their contents, and includes them in outbound API requests, but it does not give the user an explicit warning at submission time that full file contents will be transmitted off-host. This creates a real privacy and data-handling risk because users may assume local files are only referenced locally rather than uploaded to a remote service.
The submission paths send prompts, image/video URLs, and optionally attached file contents to a remote relay API without an explicit runtime disclosure or consent prompt. In a content-generation skill, this matters because users may provide sensitive creative assets or internal material, and the script silently forwards them to an external service.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
env = os.environ.copy()
env.update(extra_env)
try:
result = subprocess.run(
command,
capture_output=True,
text=True,
The code collects platform base URLs and API credentials from environment variables for background watcher authentication with no visible user notice or runtime confirmation. In a skill presented as media generation, undisclosed background credential use is risky because it expands trust boundaries and may surprise users or administrators.
The HTTP request transmits device_id and device_token as URL query parameters. Query-string secrets are more likely to be logged by servers, proxies, browser histories, and monitoring systems, increasing the chance of credential leakage and subsequent account or device impersonation.
No suspicious patterns detected.