T09 · Insecure Skill Coding Practices
- Location
scripts/setup_channel.py:98- Finding
Shell Command Injection in Generated Gateway Configuration Command
- Content
View full analysis
Dict[str, Any]: """Build gateway config patch for the channel.""" return { "channels": { "discord": { "guilds": { guild_id: { "channels": { channel_id: { "allow": True, "requireMention": False, "systemPrompt": context } } } } } } } ``` ```python print(f"\nopenclaw gateway config.patch --raw '{json.dumps(patch)}'") ``` ### Technical Analysis The user-provided `--context` value is inserted into a JSON object and then rendered inside a shell command enclosed by single quotes. JSON serialization escapes JSON metacharacters, but it does not escape single quotes for a POSIX shell. Consequently, a context containing a single quote can terminate the shell argument. Additional shell syntax can then introduce an arbitrary command. The command is not executed directly by the Python script, but the documented workflow explicitly instructs the operator to copy and run the generated command. This creates a command-injection boundary when context values are untrusted or supplied by another user or automation system. For example, a context with the following structure can break out of the quoted JSON argument: ```text description'; attacker-command; # ``` The final command displayed to the operator would contain shell syntax outside the intended `--raw` argument. ### Attack Path 1. An attacker influences the ...[truncated 1220 chars]- Remediation
View remediation
