T09 · Insecure Skill Coding Practices
- Location
scripts/backup-openclaw.sh:9- Finding
Unencrypted Sensitive Backup Written to a Predictable Temporary Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This backup skill is coherent, but it handles broad private OpenClaw data and a full Quark session cookie with weak scoping and unsafe setup details.
Review carefully before installing. Use only if you are comfortable uploading the full OpenClaw state to Quark Drive, and avoid enabling cron until the kuake binary source is pinned and verified, the cookie is stored with strict permissions or a secret manager, and the backup archive is narrowed or encrypted.
scripts/backup-openclaw.sh:9Unencrypted Sensitive Backup Written to a Predictable Temporary Path
scripts/backup-openclaw.sh:24Credential Configuration File Is Executed as Shell Code
references/kuake-setup.md:5Unpinned and Unverifiable External Upload Component
The skill instructs users to extract a full Quark session cookie from the browser and place it into a local environment file for automated use. Even though the archive exclusion mentions tools/kuake/.env, the skill still normalizes storing long-lived authentication material in plaintext on disk and using it for unattended cloud access, which creates credential theft and account compromise risk if the host, logs, backups, or file permissions are weak.
├── bin/kuake # kuake CLI 二进制 ├── use-kuake.sh # 包装脚本(设置 Cookie 环境变量) ├── backup-openclaw-full.sh # 主备份脚本 └── .env # 不存在则跳过(Cookie 由上一步提供)
### 打包排除项
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
--exclude='.openclaw/agents/*/workspace/.openclaw/cdp-profile' \
--exclude='.openclaw/agents/*/workspace/.openclaw/cdp-profile/*' \
--exclude='.openclaw/agents/*/workspace/.openclaw/cdp-profile-*' \
--exclude='workspace/tools/kuake/.env' \
-czf "$ARCHIVE" \
-C "$(dirname "$OPENCLAW_HOME")" "$(basename "$OPENCLAW_HOME")"
The skill explicitly automates packaging and remote upload of the entire .openclaw directory, including workspace, memory, sessions, and configuration, but does not present a clear user-facing warning about the privacy and security consequences of exporting this data to a third-party cloud service. Because these paths can contain conversation history, session artifacts, tokens, and other sensitive material, users may trigger or schedule exfiltration-like behavior without informed consent.
The script conditionally sources a local secret file and exports its contents into the environment, which is access to sensitive credentials. Although the variable check on L28 enforces presence of the cookie, there is no user-facing warning at the point of credential loading beyond Chinese error text for missing configuration.
The activation description enumerates only Chinese trigger phrases such as "备份" and "上传夸克". This creates a language-specific activation policy without stating that the skill is China-region-specific or offering alternative language handling.
The script emits operational and error messages in Chinese, and the same pattern continues throughout the file. This enforces a specific language for user interaction without opt-in or an explicit justification that the skill is intended only for a Chinese-speaking environment.
No suspicious patterns detected.