T09 · Insecure Skill Coding Practices
- Location
scripts/status_uploader.py:57- Finding
Authentication Token Can Be Redirected to an Arbitrary or Plaintext Endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This status-monitoring skill appears legitimate, but it needs review because it asks users to paste a reusable token into chat, stores it locally, and can run a background uploader to a configurable endpoint.
Review before installing. Use it only if you are comfortable sending your OpenClaw agent IDs to the hosted dashboard and running a periodic/background uploader. Do not paste reusable tokens into chat if avoidable; prefer an environment variable or a protected local secret file, restrict file permissions, and avoid setting OPENCLAW_MONITOR_URL or monitorUrl to untrusted endpoints.
scripts/status_uploader.py:57Authentication Token Can Be Redirected to an Arbitrary or Plaintext Endpoint
SKILL.md:81Setup Instructions Require Users to Disclose a Reusable Token Through Chat
scripts/status_uploader.py:89Credentials File Is Written Without Enforcing Restrictive Permissions
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
python3 ~/.openclaw/skills/openclaw-status-monitor/scripts/status_uploader.py stop
# 删除技能目录
rm -rf ~/.openclaw/skills/openclaw-status-monitor
# 删除配置文件(可选)
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
python3 ~/.openclaw/skills/openclaw-status-monitor/scripts/status_uploader.py stop
# 删除技能目录
rm -rf ~/.openclaw/skills/openclaw-status-monitor
# 删除配置文件(可选)
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
python3 ~/.openclaw/skills/openclaw-status-monitor/scripts/status_uploader.py stop
# 删除技能目录
rm -rf ~/.openclaw/skills/openclaw-status-monitor
# 删除配置文件(可选)
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
python3 ~/.openclaw/skills/openclaw-status-monitor/scripts/status_uploader.py stop
# 删除技能目录
rm -rf ~/.openclaw/skills/openclaw-status-monitor
# 删除配置文件(可选)
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/skills/openclaw-status-monitor
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json rm -rf ~/.openclaw/logs/status_uploader*
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/credentials/openclaw-status-monitor.json rm -rf ~/.openclaw/logs/status_uploader*
The skill instructs the agent to solicit a secret token from the user via chat and then persist it on disk. This is dangerous because secrets entered into chat are commonly retained in conversation history, logs, analytics, or debugging systems, turning a monitoring token into a potentially recoverable credential for unauthorized uploads or account misuse.
The setup flow explicitly instructs the user to send the monitoring token to the agent in chat, then store it locally, without a strong warning that the token is a secret credential. Collecting secrets through conversational channels increases the risk of exposure through logs, transcripts, prompt history, or unintended downstream processing.
The guide instructs users to generate a token and send it to the agent, but it does not warn that this token is a sensitive credential that could authorize uploads or account actions if exposed. Encouraging users to paste credentials into an agent workflow without clear handling guidance increases the risk of accidental leakage through logs, prompts, chat history, or other integrations.
The installation guide documents periodic uploads to a cloud monitoring platform, but it does not present this background network behavior as a prominent privacy/security warning at the point where users enable the service. Users may install or activate the skill without fully understanding that it runs continuously and transmits agent identifiers off-host, which weakens informed consent and can expose operational metadata.
The README prominently advertises automatic syncing of agent status and IDs to a cloud dashboard, but it does not clearly warn users about ongoing external data transmission, retention, or privacy implications before enablement. Even if only agent IDs are sent, this still exposes operational metadata and creates a risk of unintended disclosure because users may enable the feature without informed consent.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Every. Single. Time.
Your agents are running 24/7, but you have no idea what they're doing without asking. That's friction.
## The Solution
The README clearly promotes automatic syncing of agent status and IDs to a cloud dashboard, but it does not prominently warn users that operational metadata is being transmitted off-host to a third-party service. Even if only agent IDs are uploaded, this can disclose fleet membership, activity patterns, and presence information, creating privacy and security exposure through documentation-driven misconfiguration or uninformed consent.
The quick-start flow instructs users to enable monitoring and visit a hosted dashboard, but omits a clear disclosure that doing so shares agent status data remotely. This is especially risky because users may enable it with a simple command, causing external data exposure without understanding that agent identifiers and heartbeat/activity metadata are leaving their environment.
The skill describes capabilities to read environment variables, read and write local files, and communicate with a remote monitoring platform, but it does not declare any explicit tool scope or permissions. This creates an authorization transparency gap: users and the host platform cannot clearly constrain or review what the skill is allowed to access before it handles credentials and performs background sync.
The top-level description says the skill syncs status to a cloud monitoring platform, but it does not clearly warn that agent identifiers/status will be uploaded and that stored credentials may be used for ongoing background synchronization. This weakens informed consent, especially because the skill can run on a schedule or as a daemon.
The trigger set includes broad phrases like 'sync status', 'start daemon', 'run in background', and similar variants that could plausibly appear in normal conversation. Because those triggers can start background processes, change intervals, or perform uploads, accidental invocation could cause unintended network transmission or persistent service execution without clear user intent.
The skill persists a user-provided monitoring token under ~/.openclaw/credentials for ongoing reuse, enabling session/credential persistence beyond the immediate interaction. In context, this is more dangerous because the token is first collected via chat and then stored for a background service, extending the blast radius if the local machine, logs, or agent environment are compromised.
2. **Wait for user to reply with token**
3. **Save the token**:
- Create directory `~/.openclaw/credentials/`
- Save to `~/.openclaw/credentials/openclaw-status-monitor.json`:
```json
{
Including a realistic plaintext token value in documentation encourages insecure handling and may cause operators to copy the pattern directly into files without considering protection. Even if the sample token is not real, documenting secrets in plaintext next to the storage path normalizes weak secret hygiene.
The example conversation repeatedly normalizes the user providing the token directly in chat, reinforcing an unsafe operational pattern. Repetition increases the chance that users will treat secret-sharing in conversation as expected and acceptable across deployments and future skills.
This Python file includes its primary description in Chinese and continues using Chinese-only user-facing messages throughout the script, which imposes a specific language/locale without any opt-in or alternative. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific.
The document repeatedly hardcodes English and Chinese phrases and conversation patterns, but it does not state that users may choose their preferred language or locale. This can conflict with a language-choice policy when locale behavior is prescribed without user opt-in.
Detected: suspicious.destructive_delete_command