T09 · Insecure Skill Coding Practices
- Location
publish_skill.py:11- Finding
Hardcoded ClawHub bearer token is exposed and included in publication artifacts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a PaperMC server-management tool, but it needs Review because it ships an exposed ClawHub token, broad publishing upload scripts, unverified executable downloads, and restart code that can kill processes.
Install only after the publisher removes and revokes the exposed ClawHub token, removes publishing utilities from the runtime package, restricts executable downloads to trusted verified sources, and changes restart logic to use a clearly configured service with explicit operator confirmation. If used despite Review status, run it under a dedicated unprivileged server account and review every downloaded JAR and restart action manually.
publish_skill.py:11Hardcoded ClawHub bearer token is exposed and included in publication artifacts
plugin_manager.py:61Unverified remote JAR files are installed into executable server locations
plugin_upgrade_framework.py:668Automatic restart bypasses the declared safety interface and can forcibly terminate a matching process
The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.
The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.
The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.
The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.
The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.
The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.
The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.
The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.
The skill repeatedly claims 'safe, controlled interfaces' and a backup-first policy, yet the documented update flows accept arbitrary URLs for plugin and PaperMC JAR downloads. Allowing URL-based retrieval and replacement of executable server components without clear origin restrictions, signature/hash verification, or enforced backups creates a supply-chain and integrity risk.
Referenced artifact was not completely inspected
- `plugin_upgrade_framework.py` - Intelligent plugin upgrade framework
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
# Clean old backups (keep last 10)
echo "[backup] cleaning old backups, keep latest 10 ..."
cd "${BACKUP_DIR}"
ls -t world-backup-*.tar.gz 2>/dev/null | tail -n +11 | xargs -r rm -f
echo "[backup] done"
The skill can automatically restart the server when auto_restart is enabled, leading into a flow that may terminate and later kill the active PaperMC process without an immediate confirmation barrier. In this server-management context, unexpected restart behavior can cause player disruption, unsaved state loss, and possible corruption of live server data.
The script recursively enumerates local text-like files and later prepares them for upload to an external API, creating a broad exfiltration path for source code, documentation, configs, and other sensitive plaintext artifacts. In the context of a PaperMC server-management skill, this publishing behavior is outside the operational scope and increases the risk of accidentally disclosing secrets or proprietary data present in the working tree.
The script uploads all discovered text files to a remote service without interactive confirmation or a clear warning about the transmission scope, so a user may unintentionally send sensitive local data. This is especially risky because recursive collection and remote publication happen in one flow, with no review gate before exfiltration.
The code performs an external POST to ClawHub to publish the collected files, which is a data-transfer capability unrelated to managing a Minecraft server. Because the upload is automatic and broad in scope, misuse or accidental execution can leak internal project contents to a third party.
File contents flow to a network sink. This may indicate data exfiltration of sensitive files.
try:
print("正在上传技能...")
response = requests.post(
f"{API_BASE}/skills/{SKILL_SLUG}",
headers=headers,
data=payload,
The manifest describes a skill for managing PaperMC Minecraft servers, including lifecycle management, backups, plugin operations, and health monitoring. This file instead implements an AI usage/cost logging utility under ~/.openclaw/cost_logs, with no PaperMC/server-management functionality at all.
The manifest describes a skill for managing PaperMC Minecraft servers, backups, plugin operations, and health monitoring. This file instead implements a generic local accounting tool for tracking DeepSeek and Kimi model token usage and generating spending reports, with no PaperMC or server-management functionality.
The script contains a hardcoded bearer credential and uses it to upload local repository files to an external service. Embedding live secrets in a distributable skill is dangerous because anyone with access to the file can reuse the token for unauthorized API actions, and the outbound publishing behavior is unrelated to the stated PaperMC server-management purpose, increasing supply-chain and data-exfiltration risk.
The README asserts a 'controlled interfaces only' safety model, but later documents update and plugin installation flows that accept arbitrary URLs for downloading server jars or plugins. Even though these actions are wrapped in helper scripts, URL-based fetch-and-install is still a direct supply-chain risk because an agent could be induced to retrieve and deploy untrusted code while believing it is operating within approved safety boundaries.
The skill advertises and documents capabilities that imply shell, filesystem, environment, and network access, but it does not declare any explicit tool scope or permission boundaries in the manifest. In an agent setting, missing scope declarations increases the chance that a consumer or runner grants broader privileges than intended, especially for scripts that download artifacts and modify server files.
The documentation instructs users to install plugins and update PaperMC from remote URLs, but it does not prominently warn that these artifacts are executable code with integrity, authenticity, and privacy risks. In a server-management skill, users may interpret the examples as endorsed-safe workflows and fetch malicious or tampered JARs.
标题和全文内容均以中文呈现,未说明这是面向特定中文用户群的区域性文档,也未提供多语言或用户选择。根据语言/区域政策,这属于未经用户选择而强制特定语言的自然语言策略问题。
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_command(cmd: list[str], check: bool = True) -> int:
"""Execute command in server directory"""
print(f"[cmd] {' '.join(cmd)}")
result = subprocess.run(cmd, cwd=SERVER_DIR)
if check and result.returncode != 0:
raise SystemExit(result.returncode)
return result.returncode
The code runs a privileged subprocess using sudo to restart a system service, which changes system state and may interrupt availability. While the command itself is printed, there is no explicit warning, confirmation, or explanatory disclosure that this action requires elevated privileges and will restart the server service.
Detected: suspicious.exposed_secret_literal, suspicious.install_untrusted_source