安全决策报告

nano-banana-pro

OpenClaw workspace configuration with extensive hardcoded credentials and sensitive tokens exposed in plaintext across multiple files

安装决策优先 来源: 手动上传 扫描时间: 2026/4/4
文件 614
IOC 256
越权项 0
发现 9
最直接的威胁证据
严重 凭证窃取
Hardcoded DASHSCOPE_API_KEY in _meta.json

API key 'sk-1f3847debc3e492e81f64115b20c6d82' hardcoded in _meta.json env section. This is a production credential exposure.

_meta.json:13

为什么得出这个结论

2/4 个维度触发
通过
声明与实际能力

声明资源与推断能力基本一致。

阻止
隐藏执行与外联

提取到 9 个高危 IOC 或外联信号。

阻止
攻击链与高危发现

报告包含 4 步攻击链,另有 8 项高危或严重发现。

复核
依赖与供应链卫生

没有完整依赖信息,供应链判断需要保留弹性。

攻击链

01
Attacker discovers workspace repository or file leak

reconnaissance · N/A

02
Attacker extracts hardcoded API keys from _meta.json

凭证访问 · _meta.json:13

03
Attacker uses extracted keys for unauthorized API access

最终危害 · N/A

04
Attacker compromises Feishu integration using exposed credentials

最终危害 · _meta.json:175

风险分是怎么被拉高的

Multiple production API keys hardcoded in plaintext +35

_meta.json, scripts/vectorize-and-store.py, search_knowledge.py, and backup files contain plaintext API keys for DashScope, Xiaomi, GLM

Feishu integration credentials exposed +20

appId, appSecret, verificationToken exposed in _meta.json

Gateway authentication token exposed +10

Gateway auth token '82a4d393848d5ad8cd3d9831b10ef1292074a58b400cb2ff' in _meta.json

API keys in backup/prose files +7

2026-3-10afu的js备份.txt contains hardcoded keys

最关键的证据

严重 凭证窃取

Hardcoded DASHSCOPE_API_KEY in _meta.json

API key 'sk-1f3847debc3e492e81f64115b20c6d82' hardcoded in _meta.json env section. This is a production credential exposure.

_meta.json:13
Move to environment variable. Never commit API keys to configuration files.
严重 凭证窃取

Hardcoded Xiaomi API key in _meta.json

API key 'sk-JPxFOBXYC8ieSrEN9OgCjYJ4V06XqkykhVtma4gw8ONxNuwE' hardcoded in xiaomi provider config.

_meta.json:66
Rotate immediately. Use environment variable.
严重 凭证窃取

Hardcoded GLM API key in _meta.json

API key 'd846dcff984f435ebeb2e67d81138dd9.r4hj85ftxqpD1Nrj' hardcoded.

_meta.json:80
Rotate immediately.
严重 凭证窃取

Hardcoded API key in scripts/vectorize-and-store.py

DASHSCOPE_API_KEY directly assigned in Python file.

scripts/vectorize-and-store.py:19
Use os.getenv('DASHSCOPE_API_KEY') instead.
严重 凭证窃取

Hardcoded API key in search_knowledge.py

API key directly in source file.

search_knowledge.py:22
Use environment variable.
严重 凭证窃取

Feishu app credentials exposed

appId, appSecret, and verificationToken for Feishu integration exposed in _meta.json.

_meta.json:175
Rotate Feishu credentials immediately.
高危 凭证窃取

Gateway authentication token exposed

Gateway auth token hardcoded in configuration.

_meta.json:193
Rotate gateway token.
高危 凭证窃取

API keys in backup file

Backup file contains hardcoded API keys.

2026-3-10afu的js备份.txt:9
Delete backup file containing credentials.

还有 1 项发现未展开显示

声明能力 vs 实际能力

文件系统 通过
声明 NONE
推断 READ
SKILL.md describes script execution only
网络访问 通过
声明 READ
推断 READ
Script makes API calls to Gemini image generation API
环境变量 通过
声明 READ
推断 READ
GEMINI_API_KEY environment variable check in SKILL.md

可疑产物与外联

严重 API 密钥
sk-1f3847debc3e492e81f64115b20c6d82

2026-3-10afu的js备份.txt:9

严重 API 密钥
sk-JPxFOBXYC8ieSrEN9OgCjYJ4V06XqkykhVtma4gw8ONxNuwE

2026-3-10afu的js备份.txt:55

严重 危险命令
rm -rf /

skills/skill-vetting/references/patterns.md:20

高危 IP 地址
120.0.0.0

expert-review-2026-03-09-browser-stealth-explained.md:47

高危 API 密钥
accessToken = "your_access_token"

feishu-calendar-integration.md:20

高危 API 密钥
api_key='sk-1f3847debc3e492e81f64115b20c6d82'

memory/2026-03-14.md:55

高危 API 密钥
API_KEY = "sk-1f3847debc3e492e81f64115b20c6d82"

scripts/vectorize-and-store.py:19

高危 API 密钥
API_KEY = 'sk-1f3847debc3e492e81f64115b20c6d82'

search_knowledge.py:22

高危 API 密钥
apiKey = "sk-1f3847debc3e492e81f64115b20c6d82"

skills/tts-automation/SKILL.md:96

中危 外部 URL
http://127.0.0.1:11434/v1

2026-3-10afu的js备份.txt:31

中危 外部 URL
https://api.xiaomimimo.com/anthropic

2026-3-10afu的js备份.txt:54

中危 外部 URL
https://open.bigmodel.cn/api/paas/v4

2026-3-10afu的js备份.txt:77

依赖与供应链

没有结构化依赖告警。

文件构成

614 个文件 · 140626 行
Markdown 320 个文件 · 79463 行HTML 86 个文件 · 34309 行Python 73 个文件 · 9689 行JSON 38 个文件 · 7212 行Text 73 个文件 · 6690 行JavaScript 16 个文件 · 2313 行
需关注文件 · 7
agents/config.json JSON · 50 行
skills/feishu-multi-agent-manager/package-lock.json JSON · 5324 行
https://opencollective.com/babel · https://opencollective.com/eslint · https://opencollective.com/typescript-eslint · https://opencollective.com/browserslist · https://tidelift.com/funding/github/npm/browserslist · https://tidelift.com/funding/github/npm/caniuse-lite · https://eslint.org/version-support · https://opencollective.com/fast-check · https://www.patreon.com/feross · https://feross.org/support · [email protected]
memory/2026-03-08.md Markdown · 2415 行
https://feishu.cn/docx/U9PIdZ5SooMa9TxTXabcv8TGnhb · https://feishu.cn/docx/AafbdknDaoglGpx3RAvcluyUnAM · https://feishu.cn/docx/Mc5td0zf5oKY4bxHNRMc4E6Inyc · https://feishu.cn/docx/B52uds8WLo02Swx5SGdcfClxnSh · https://feishu.cn/docx/BiwWdBiUyoV8XzxrzL6cItginTh · https://feishu.cn/docx/NyVtdMB1NomyooxHnoTcHKw5nRh · https://feishu.cn/docx/NyVtdMB1NomyooxHnoTcHKw5nRh(V1.2,31 · https://feishu.cn/docx/AaC9dkA8QoAmAKx3hQqcLqFznRf(分块写入 · https://feishu.cn/docx/I49YdfIQ8omBxBxtW3Mc3PAWnBc · https://feishu.cn/docx/NTWmdppaWoxzpwxIjpQcZPiFn9f · https://feishu.cn/docx/CEoRdPxG2oiwlzxg9i9c9M1sngf · https://feishu.cn/docx/TNIVdysYHoJ0tex1wTMc5yE8nAc · https://feishu.cn/docx/AaC9dkA8QoAmAKx3hQqcLqFznRf(108 · https://feishu.cn/docx/AaC9dkA8QoAmAKx3hQqcLqFznRf(V1.1,追加 · https://feishu.cn/docx/AaC9dkA8QoAmAKx3hQqcLqFznRf(V1.2,追加 · https://weda.tencentcloudapi.com · https://tcb.cloud.tencent.com/dev · https://cloud.tencent.com/document/product/876 · https://servicewechat.com/wxa-dev-logic/download_redirect?type=win32_x64&from=mpwiki&download_version=2012510280&version_type=1 · https://mp.weixin.qq.com/ · https://mermaid.live/edit#pako:Sy9KLMhQ8AniUgACx+iMktwc3dSKgtSiEt2i1LLM1HKFMCM9g1gFXV07BafoZw1zn+...
memory/triple-line-sync-log.md Markdown · 1963 行
https://scns3ak4jrto.feishu.cn/docx/GeG0dywMxof8dLx1tcUckSFNndh##
worklog.txt Text · 1784 行
https://mermaid.live/edit#pako:Sy9KLMhQ8AniUgACx+iMktwc3dSKgtSiEt2i1LLM1HKFMCM9g1gFXV07BafoZw1zn+/e8nT9nqez9ynkZual5CYWxEK0glU4A1Xsfr578rOupU8ndj3tmv+ieS9E3iW6oCg/KzW5RLe4NDc3sagSaHxBflEJkvGu0U92dD7d2PRs3rZn8 · https://scns3ak4jrto.feishu.cn/docx/KaBld2wpyoKL5yxLYuPcSCPOne4 · https://scns3ak4jrto.feishu.cn/docx/GQsbd042WoNdbHxaBbscO9D8nW6 · https://scns3ak4jrto.feishu.cn/base/bascnZQh8v5K6d2m4E7p9Lr1tYw · https://feishu.cn/docx/NQCBdAXzeoBoi0xLJX7cPBHDnm3 · https://feishu.cn/docx/CvCBd5N2co0n02xXPZscQPEsnOL
memory/2026-03-07.md Markdown · 1386 行
https://scns3ak4jrto.feishu.cn/docx/GeG0dywMxof8dLx1tcUckSFNndh
backups/html-expert-review-v2.0/SKILL.md Markdown · 1046 行
https://mermaid.live/edit#pako:... · https://mermaid.live/edit · https://mermaid.live/edit#pako: · https://mermaid.live/edit#pako:$base64 · http://www.w3.org/2000/svg
其他文件 · index.js · people.txt · bom-物料管理规则 - 专家评点-v9-pyramid.html · SKILL.md · expert-review-2026-03-08-voice-redpacket-journey.html

安全亮点

The nano-banana-pro SKILL.md describes legitimate image generation functionality
Skill-vetting skill contains good security practices and documentation
No malicious code execution patterns (eval/exec) detected in main skill files
No base64-encoded malicious payloads detected
No network exfiltration detected - all network calls are to documented APIs