T09 · Insecure Skill Coding Practices
- Location
SKILL.md:49- Finding
Plaintext ClawHub Token Exposed in Skill Documentation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 49
Vulnerability Type: Hardcoded credential / plaintext sensitive data
Risk Level: HighVulnerable Code Snippet
markdown - 需要 ClawHub token:`clh_dfYBmWi76_VPBJhUkwRoK8BWpQ4m1IV47bAHieANjVA`Technical Analysis
The skill documentation embeds a credential-shaped ClawHub token directly in plaintext. Any person or process that can access the skill package can extract and attempt to use this token. The repository provides no evidence that the value is an inert placeholder; therefore, it must be treated as potentially valid and compromised.
Storing credentials in documentation bypasses normal secret-management controls and can expose the token through source distribution, repository clones, archives, logs, caches, indexing systems, and repository history.
Attack Path
- An attacker obtains read access to the skill package or a copy of its repository.
- The attacker opens
SKILL.mdand extracts the token from line 49. - The attacker submits the token to applicable ClawHub endpoints or tooling.
- If the token remains valid, the attacker performs actions allowed by its assigned scope until it expires or is revoked.
No evidence in the audited project establishes that the token is valid or identifies its exact scopes, so successful exploitation and specific downstream permissions cannot be confirmed.
Impact Assessment
If valid, the exposed token may enable unauthorized ClawHub access, impersonation of the token owner, consumption of service quotas, or access to resources authorized for that credential. The precise impact is bounded by the token's server-side scopes, account permissions, expiration policy, and any additional access controls.
The only project artifact reviewed was the 56-line
SKILL.mdfile. No executable code, remote payload retrieval, persistence mechanism, dependency installation, tool spoofing, or instruction hijacking was identified.- Remediation
View remediation
Remediation Suggestions
- Revoke the exposed token immediately and issue a replacement only if it is still required.
- Remove the token from the current file and purge it from repository history, release archives, caches, and generated documentation where feasible.
- Replace the literal value with a non-secret placeholder such as
${CLAWHUB_TOKEN}. - Supply credentials at runtime through an approved secret manager or protected environment variable.
- Apply least-privilege scopes, short expiration periods, and regular rotation to replacement credentials.
- Review ClawHub access logs for activity involving the exposed token and investigate any unrecognized use.
- Add automated secret scanning to pre-commit hooks and CI pipelines to prevent recurrence.
- Avoid printing credentials in logs, examples, errors, or generated output.
