T09 · Insecure Skill Coding Practices
- Location
scripts/install-guardian.sh:59- Finding
Alert credentials are embedded in an insufficiently protected launchd plist
- Content
View full analysis
/dev/null | head -1 | cut -d= -f2- | tr -d '"' || true) _tg_chat=$(grep -E '^GUARDIAN_TELEGRAM_CHAT_ID=' "$env_file" 2>/dev/null | head -1 | cut -d= -f2- | tr -d '"' || true) _discord_url=$(grep -E '^GUARDIAN_DISCORD_WEBHOOK_URL=' "$env_file" 2>/dev/null | head -1 | cut -d= -f2- | tr -d '"' || true) fi local extra_env_xml="" [[ -n "$_tg_token" ]] && extra_env_xml+=" GUARDIAN_TELEGRAM_BOT_TOKEN${_tg_token}"$'\n' [[ -n "$_tg_chat" ]] && extra_env_xml+=" GUARDIAN_TELEGRAM_CHAT_ID${_tg_chat}"$'\n' [[ -n "$_discord_url" ]] && extra_env_xml+=" GUARDIAN_DISCORD_WEBHOOK_URL${_discord_url}"$'\n' cat > "$plist_path" <EnvironmentVariables ... ${extra_env_xml} ... PLIST ``` ### Technical Analysis The installer reads reusable Telegram and Discord credentials from `~/.openclaw/guardian.env` and duplicates them directly into `~/Library/LaunchAgents/com.openclaw.guardian.plist`. The script does not establish a restrictive umask or explicitly set the generated plist to mode `0600`. Consequently, its permissions depend on the invoking user's current umask and the accessibility of parent directories. The values are also concatenated directly into XML without XML escaping. Characters such as `&`, `<`, and `>` can make the plist invalid. If an attacker can influence `guardian ...[truncated 1832 chars]- Remediation
View remediation
