T09 · Insecure Skill Coding Practices
- Location
references/api-reference.md:51- Finding
Cloud Access Credentials Embedded in Tracked Documentation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This billing skill mostly does what it claims, but it ships credential-looking cloud keys and gives weak credential-storage guidance for sensitive account access.
Review this skill carefully before installing. Do not use the included credential examples, rotate any matching or reused keys, and only provide read-only billing credentials stored outside source control with strict local permissions. Treat Base64 as reversible encoding, not secret protection.
references/api-reference.md:51Cloud Access Credentials Embedded in Tracked Documentation
SKILL.md:52Base64 Encoding Is Incorrectly Presented as Credential Protection
scripts/query_volc_billing.py:96Outbound API Requests Have No Explicit Timeouts
The skill claims broad multi-platform billing features while apparently accessing a local sensitive credential file and implementing only a narrower subset. This kind of overclaiming can conceal the real security boundary of the skill, causing users to authorize or run a credential-reading workflow they did not accurately understand.
The skill claims broad multi-platform billing features while apparently accessing a local sensitive credential file and implementing only a narrower subset. This kind of overclaiming can conceal the real security boundary of the skill, causing users to authorize or run a credential-reading workflow they did not accurately understand.
The skill claims broad multi-platform billing features while apparently accessing a local sensitive credential file and implementing only a narrower subset. This kind of overclaiming can conceal the real security boundary of the skill, causing users to authorize or run a credential-reading workflow they did not accurately understand.
The skill claims broad multi-platform billing features while apparently accessing a local sensitive credential file and implementing only a narrower subset. This kind of overclaiming can conceal the real security boundary of the skill, causing users to authorize or run a credential-reading workflow they did not accurately understand.
The reference document includes what appear to be concrete access key values and secrets rather than obvious placeholders. Even if they are sample values, publishing credential-shaped strings in a billing/account skill is dangerous because users may reuse them, scanners may treat them as live secrets, and real credentials could grant access to account balance, billing history, or broader cloud resources.
The skill documentation declares access to local credential files and use of networked billing queries, but it does not define any explicit tool scope or permissions boundary. In agent environments, undeclared file-read and network capabilities increase the risk of overbroad access to sensitive secrets in ~/.openclaw/workspace and make review and containment harder.
The document instructs use of Bearer tokens and access keys for multiple billing providers without warning users that these credentials are sensitive or that billing data is financial/account information. In a skill specifically designed to query balances and bills, this omission increases the chance that users paste secrets insecurely, store them in prompts, logs, or source files, and expose account data.
The file’s docstrings and all user-facing console messages are written in Chinese, which imposes a specific language on users. There is no opt-in, locale selection, or indication that this is a region-specific tool, so this appears to violate the language/locale policy criterion.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""查询 DeepSeek 账户余额"""
api_key = load_credentials()
url = "https://api.deepseek.com/user/balance"
headers = {
"Authorization": f"Bearer {api_key}"
}
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""查询 DeepSeek 账户余额"""
api_key = load_credentials()
url = "https://api.deepseek.com/user/balance"
headers = {
"Authorization": f"Bearer {api_key}"
}
The file's user-facing docstring, usage text, and warnings are presented exclusively in Chinese. Under the policy rule for language/locale, this is a natural-language constraint that does not provide user opt-in or justify why the skill is region- or language-specific.
A language/locale policy issue can arise when a skill or reference forces a specific language without offering choice or documenting a justified locale restriction. This file presents all instructions and labels in Chinese only, with no note that the content is region-specific or optional.
This shell script's natural-language comments and all echoed user-facing messages are written only in Chinese, which imposes a specific language choice on users. The file does not offer any language selection, fallback, or documentation that the skill is intentionally limited to a Chinese-speaking or region-specific audience.
The docstring and all user-facing messages in this script are written only in Chinese, which imposes a specific language on users. The file does not provide an opt-in, fallback language, or justification that the skill is intended exclusively for a Chinese-speaking or region-specific audience.
The top-level documentation states that credentials come from a Base64-encoded .volc_ak_sk.env file. However, load_credentials() simply reads VOLC_ACCESS_KEY_ID and VOLC_SECRET_KEY as raw strings, and the only related comment says the secret key is used directly without decoding. This is an active documentation/code contradiction.
No suspicious patterns detected.