T09 · Insecure Skill Coding Practices
- Location
SKILL.md:5- Finding
Unnecessary Plaintext Password Configuration Requirement
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Google Sheets skill mostly does what it says, but it unnecessarily requires users to store a password-like secret in configuration before the skill can load.
Review this skill before installing. It appears purpose-aligned and does not contain executable payloads, but users should avoid putting real passwords or reusable secrets into ordinary OpenClaw config. Prefer removing the password requirement, using OAuth-only setup, and storing any needed secrets in a proper secret manager or environment reference with clear warnings.
SKILL.md:5Unnecessary Plaintext Password Configuration Requirement
This markdown file includes authentication commands that use a local OAuth client secret file and add an account, but it does not warn users that these steps involve sensitive credentials and account authorization. For markdown files, omission of privacy or security warnings around credential-related behavior is in scope for missing user warnings.
Detected: suspicious.exposed_secret_literal