T09 · Insecure Skill Coding Practices
- Location
SKILL.md:340- Finding
Unvalidated and Unquoted Shell Input in the Test Script Template
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 340–351
Vulnerability Type: Unvalidated shell argument, word splitting, pathname expansion, and CLI option injection
Risk Level: Mediumbash SKILL_NAME=$1 echo "Testing skill: $SKILL_NAME" # Validate structure clawhub validate $SKILL_NAME # Test installation clawhub install $SKILL_NAME # Verify installation ls -la ~/.openclaw/workspace/skills/$SKILL_NAMETechnical Analysis
The documented test script assigns the first caller-controlled positional argument to
SKILL_NAMEand subsequently expands it without double quotes. Unquoted shell expansion permits word splitting and pathname expansion, so one supplied value can become multiple command-line arguments or expand into matching filesystem paths.A value beginning with a hyphen may also be interpreted as an option by
clawhuborls, depending on each command's argument parser. This creates a CLI option-injection risk. The template additionally installs a registry skill without pinning an immutable or explicitly reviewed version, meaning the installed content can vary over time.Shell metacharacters contained only in the expanded variable are not automatically reparsed as shell syntax. The directly supported exploitation mechanisms are therefore argument splitting, wildcard expansion, and option injection rather than arbitrary shell-command execution.
Because the vulnerable content is a documentation template rather than an automatically executed project script, exploitation requires a user or agent to copy or execute the example.
Attack Path
- A user or agent adopts the test script shown in
SKILL.md. - An attacker supplies or recommends a specially formed skill-name argument containing whitespace, wildcard characters, or an option-like prefix.
- The shell expands the unquoted value into one or more arguments.
clawhub validate,clawhub install, orlsproces ...[truncated 936 chars]
- A user or agent adopts the test script shown in
- Remediation
View remediation
Remediation Suggestions
Validate the argument against the documented skill-name syntax, quote every variable expansion, reject option-like or malformed values, and use an end-of-options marker where the target command supports it:
bash #!/bin/bash set -euo pipefail SKILL_NAME=${1:?Usage: test-skill.sh <skill-name>} if [[ ! $SKILL_NAME =~ ^[a-z0-9][a-z0-9-]*$ ]]; then printf 'Invalid skill name: %s\n' "$SKILL_NAME" >&2 exit 1 fi printf 'Testing skill: %s\n' "$SKILL_NAME" clawhub validate -- "$SKILL_NAME" clawhub install -- "$SKILL_NAME" ls -la -- "$HOME/.openclaw/workspace/skills/$SKILL_NAME"Confirm that the installed
clawhubversion supports--; otherwise, rely on strict allowlist validation and the command's documented safe argument syntax. Pin an exact trusted skill version where supported, verify publisher identity and integrity metadata before installation, and test the hardened script with whitespace, wildcard, and hyphen-prefixed inputs.
