T09 · Insecure Skill Coding Practices
- Location
lib/validator.js:32- Finding
Unvalidated Agent ID Enables Filesystem Path Traversal
- Content
View full analysis
{ if (!fs.existsSync(dir)) { fs.mkdirSync(dir, { recursive: true }); } }); return dirs; } ``` ### Technical Analysis The `--id` command-line argument is copied into `newAgent.id` without validation and subsequently used as a filesystem path component. The code does not reject path separators, `.` components, or `..` traversal components. `path.join()` normalizes traversal components but does not enforce that the resulting path remains below `baseDir`. Consequently, a malicious Agent ID can cause paths such as the Agent directory and session directory to resolve outside `~/.openclaw`. The recursive `fs.mkdirSync()` calls then create directories at those resolved locations using the privileges of ...[truncated 1529 chars]- Remediation
View remediation
