T09 · Insecure Skill Coding Practices
- Location
scripts/gmail_auto_draft.py:40- Finding
Gateway Credential and Email Disclosure Through an Unrestricted Model Endpoint
- Content
View full analysis
str: cfg_path = Path("~/.openclaw/openclaw.json").expanduser() if not cfg_path.exists(): return "" try: cfg = json.loads(cfg_path.read_text(encoding="utf-8")) except Exception: return "" return cfg.get("gateway", {}).get("auth", {}).get("token", "") ``` ```python user = ( f"Agency profile:\n{agency_profile}\n\n" f"Style rules:\n{style_rules}\n\n" f"Incoming email metadata:\n" f"From Name: {record.from_name or 'Unknown'}\n" f"From Email: {record.from_email or 'Unknown'}\n" f"Subject: {record.subject or '(no subject)'}\n\n" f"Incoming email content:\n{record.body[:12000]}\n\n" "Write a personalized follow-up reply as if replying in the same thread. " "Include a clear next step and keep it under 180 words unless complexity requires more." ) ``` ```python resp = client.chat.completions.create( model=model, messages=[ {"role": "system", "content": system}, {"role": "user", "content": user}, ], temperature=0.4, ) ``` ```python parser.add_argument("--openai-model", default=os.environ.get("OPENAI_MODEL", "openclaw:main")) parser.add_argument("--openai-base-url", default=os.environ.get("OPENAI_BASE_URL", "http://127.0.0.1:18789/v1")) ``` ```python openai_api_key = os.environ.get("OPENAI_API_KEY", "") or load_gateway_token() ``` ```python openai_client = OpenAI(api_key=openai_api_key, base_url=args.openai_base_url) ``` ### Technical Analysis The OpenAI-compatible base URL can be supplied through the `--openai-base-url` argument or the `OPENAI_BASE_URL` environment variable without host validation, transport validation, or an endpoint allowlist. If ...[truncated 1981 chars]- Remediation
View remediation
