T09 · Insecure Skill Coding Practices
- Location
SKILL.md:299- Finding
GitHub PAT Disclosure Through Unquoted Curl URL Expansion
- Content
View full analysis
- Remediation
View remediation
&2 return 1 ;; esac } validate_repo_component "$OWNER" || exit 1 validate_repo_component "$REPO" || exit 1 ``` 3. Pass the destination explicitly and terminate curl option parsing: ```bash curl -s -X POST --url "$URL" \ -H "Authorization: Bearer ${GH_TOKEN}" ``` Where compatible with the command structure, also use `--` before positional URL arguments. 4. Enforce an endpoint allowlist before attaching credentials. Confirm that the parsed scheme is HTTPS and the exact hostname is `api.github.com`; do not rely only on a string prefix check. 5. Use fine-grained, repository-specific, short-lived PATs. Separate read-only and write-capable credentials where practical, and avoid classic tokens with the broad `repo` scope. 6. Add negative tests using repository values containing spaces, leading dashes, additional URLs, tabs, and control characters. Verify that malformed values are rejected before curl executes. 7. Avoid printing the credential during setup verification. Replace the documented `cat ~/.config/openclaw/github_token` check with an existence and permissions check such as: ```bash test -r ~/.config/openclaw/github_token && stat ~/.config/openclaw/github_token ``` ]]>
