T09 · Insecure Skill Coding Practices
- Location
SKILL.md:38- Finding
Discord Bot Token Stored in Plaintext Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 38-43
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Mediumyaml plugins: entries: - plugin: openclaw-discord config: botToken: "YOUR_BOT_TOKEN" clientId: "YOUR_CLIENT_ID"Technical Analysis
The primary setup procedure directs users to place a Discord bot token directly in the persistent
~/.openclaw/config.yamlfile. A similar inline-token configuration is repeated in the advanced slash-command example.Discord bot tokens are authentication credentials that grant access to the bot account and its authorized Discord resources. Storing the token as a literal configuration value exposes it to local users and processes that can read the file, insecure backups, diagnostic archives, accidental source-control commits, or configuration files shared for technical support.
Although the document later recommends using an environment variable, it does not demonstrate how the plugin should consume that variable. Consequently, the actionable configuration examples continue to promote plaintext credential storage.
Attack Path
- A user follows the documented setup and writes a valid Discord bot token into
~/.openclaw/config.yaml. - The configuration file is exposed through permissive file permissions, local malware, another account with filesystem access, an unprotected backup, a support archive, or an accidental repository commit.
- An attacker extracts the token from the
botTokenfield. - The attacker submits authenticated requests to the Discord Bot API using the stolen token.
- The attacker impersonates the bot and exercises the permissions granted to it until the token is revoked or regenerated.
Impact Assessment
A successful attacker can authenticate as the affected Discord bot. The resulting scope is limited by the bot's configured Discord permissions and the servers ...[truncated 552 chars]
- A user follows the documented setup and writes a valid Discord bot token into
- Remediation
View remediation
Remediation Suggestions
- Replace every inline-token example with an explicit environment-variable or secret-manager reference supported by the OpenClaw plugin.
- Do not use placeholder syntax unless the documentation confirms that OpenClaw expands it. Provide a tested configuration example showing exactly how
DISCORD_BOT_TOKENis consumed. - Store production credentials in an operating-system credential store or dedicated secrets manager where supported.
- Restrict the configuration file to the owning account, such as mode
0600on Unix-like systems, and ensure the parent directory is not broadly accessible. - Exclude local configuration and secret files from source control, backups shared with third parties, diagnostic bundles, and support attachments.
- Apply least privilege to the Discord bot and restrict it to explicitly approved guild IDs.
- Document immediate token regeneration through the Discord Developer Portal after any suspected disclosure.
- Add automated secret scanning to detect Discord bot tokens before files are committed or distributed.
