Back to skill

Security audit

Local File Sender

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to upload local files, but it needs Review because it accepts arbitrary local paths, uses undeclared shell checks, and shares files through public cloud links without strong scoping or confirmation.

Install only in a trusted local deployment where users understand that selected files leave the machine and may be accessible to anyone with the link. Before use, require explicit confirmation of the exact file and link visibility, restrict uploads to approved sharing folders, avoid secrets and credential files, and replace shell-based path checks with a safe filesystem API.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:78
Finding

Command Injection Through User-Controlled File Paths

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 78-88
Vulnerability Type: OS command injection caused by unsafe shell interpolation
Risk Level: High

Vulnerable Code

powershell
Test-Path "E:\校对\报告.xlsx"
Get-Item "E:\校对\报告.xlsx" | Select-Object Name, Length, LastWriteTime
bash
ls -la "/home/user/report.xlsx"

Technical Analysis

The Skill instructs the Agent to extract a file path from an untrusted natural-language request and insert that path into a PowerShell or POSIX shell command executed through exec.

Merely surrounding the path with double quotation marks does not make this safe. PowerShell and POSIX shells perform expansions inside double-quoted strings. For example, PowerShell subexpressions and POSIX command substitutions can execute commands embedded in what appears to be a file path. A malicious value may also contain quotation marks and command separators that terminate the intended argument and introduce additional commands.

The preceding path normalization recommendations do not provide command escaping or establish that the path is safe for shell evaluation. Functions such as normpath and abspath canonicalize path syntax but are not defenses against shell metacharacters or command substitution.

Attack Path

  1. An attacker submits a file-send request containing a crafted path with shell syntax, such as a command substitution or a closing quotation mark followed by a command separator.
  2. The Agent extracts the attacker-controlled string as the requested file path.
  3. Path normalization is applied but does not safely encode the value for the target shell.
  4. Following the Skill instructions, the Agent interpolates the resulting value into Test-Path, Get-Item, or ls.
  5. The Agent invokes exec.
  6. The shell evaluates the injected syntax and executes the attacker's command with the privileges of the local Agent process.

Impact Assessment

...[truncated 638 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not use exec or a command shell to test file existence or retrieve metadata. Use a dedicated filesystem tool or a language API such as os.path.isfile, pathlib.Path.is_file, and Path.stat.
  2. If an external process is unavoidable, invoke it without a shell and supply the path as a discrete argument. For example, use an argument array with shell=False rather than building a command string.
  3. Reject null bytes, control characters, newlines, shell metacharacters, and other values that cannot be represented safely as a local path.
  4. Resolve symbolic links and canonicalize the path before access.
  5. Restrict eligible files to explicitly configured user-owned directories. Reject paths outside those roots after canonicalization.
  6. Require the target to be a regular file and reject directories, devices, named pipes, sockets, and other special files.
  7. Run the Agent under a dedicated least-privileged operating-system account with narrowly scoped filesystem access.
  8. Add tests covering quotation marks, semicolons, pipes, command substitutions, newlines, traversal sequences, symbolic links, and platform-specific shell syntax.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:93
Finding

Unrestricted Disclosure of Local Files Through Public Download Links

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 93-103
Vulnerability Type: Sensitive data exposure through public cloud uploads
Risk Level: Medium

Vulnerable Code

json
{
  "paths": ["E:\\校对\\报告.xlsx"]
}

The documented behavior uploads the selected local file through lightclaw_upload_file and states that the service returns a public download link.

Technical Analysis

The Skill permits any user-specified, readable local path to be uploaded to unspecified cloud storage. It does not define an allowed directory boundary, sensitive-path restrictions, recipient authentication, access controls, retention limits, deletion behavior, or a mandatory confirmation step.

The generated link is explicitly described as public. Consequently, access is based on possession of the link rather than an authenticated recipient identity. The Skill also does not require the Agent to verify that the requester is authorized to disclose the selected local file or that the destination is appropriate for its contents.

This creates a data-exfiltration boundary: content available only on the local filesystem is copied to an external service and made accessible through a shareable URL. Although uploading files is the declared purpose of the Skill, the absence of authorization and disclosure safeguards makes sensitive-file exposure possible.

Attack Path

  1. An attacker or unauthorized conversation participant requests that the Agent send a sensitive path accessible to the local Agent account.
  2. The Skill directs the Agent to resolve and inspect that path without checking whether it lies in an approved sharing directory.
  3. The Agent submits the path to lightclaw_upload_file.
  4. The cloud service stores the local file and returns a public download link.
  5. The Agent posts the link into the conversation or connected messaging platform.
  6. The requester—and any other party who obtains the link—can download ...[truncated 705 chars]
Remediation
View remediation

Remediation Suggestions

  1. Restrict uploads to explicitly configured sharing directories. Canonicalize the requested path, resolve symbolic links, and verify that the final target remains within an allowed root.
  2. Introduce a mandatory confirmation step that displays the canonical local path, file name, size, destination service, link visibility, expiration period, and retention policy.
  3. Deny access to sensitive locations and file classes, including credential stores, SSH keys, browser profiles, environment files, operating-system configuration, and application secret files.
  4. Prefer authenticated, recipient-scoped delivery through the destination platform's file-upload API instead of a public bearer link.
  5. If links must be used, generate high-entropy, single-recipient or single-use links with short expiration times and revocation support.
  6. Define automatic deletion and provide a mechanism to revoke the link and remove the uploaded object.
  7. Verify that the requester is authorized to access and disclose the file before uploading it.
  8. Warn users that the file will leave the local machine and identify the external storage provider before obtaining consent.
  9. Avoid recording public links or sensitive paths in persistent logs, telemetry, or Agent memory.
  10. Run the Agent with least-privilege filesystem permissions so that unrelated sensitive directories are not readable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is designed to accept a natural-language local path and upload the referenced file to cloud storage, then publish a download link. This creates a direct exfiltration path for arbitrary local files, with little evidence of access restrictions, sensitive-path blocking, or strong confirmation, making accidental or induced disclosure likely.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The step-by-step workflow instructs the agent to locate, inspect, and upload local files based solely on user language, operationalizing plain-language data exfiltration from the host. In a local deployment context this is especially dangerous because the agent may have real filesystem access, so prompt manipulation or user confusion can lead to exposure of sensitive documents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill declares only the upload tool, but its instructions tell the agent to use an undeclared exec capability to probe the local filesystem. This expands the effective privilege boundary beyond what is advertised and can enable unauthorized local inspection or command execution behavior if the runtime permits it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill uploads local files to cloud storage and returns a public download link, but it does not clearly warn at the decision point that the file will leave the local machine and become externally accessible. Users may believe they are merely sending a file to a chat platform when they are actually publishing sensitive local data via a shareable URL.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

All user-facing instructions, trigger examples, and operational messages in the skill are written only in Chinese, with no indication that users may interact in other languages or that the locale restriction is intentional. Under the policy, a skill should not implicitly force a specific language unless it offers user choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.