T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
Execution of an Unverified Mutable Script Outside the Skill Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20-23
Vulnerability Type: Unverified external local script execution
Risk Level: MediumComplete Code Snippet:
markdown 1. 运行维护脚本: ```bash /home/admin/.openclaw/workspace/scripts/system-maintenance.shtext ### Technical Analysis The skill instructs the agent to execute `/home/admin/.openclaw/workspace/scripts/system-maintenance.sh`, an absolute host-local path outside the audited project. The referenced script is not included in the project, so its commands, integrity controls, required privileges, network behavior, file access, and potentially destructive maintenance actions cannot be reviewed. Because the effective behavior is delegated to a mutable external file, the behavior observed when the skill is invoked may differ from the behavior originally intended or reviewed. If another user, process, or compromised component can modify or replace that script, it can cause attacker-controlled commands to execute under the identity and permissions of the agent or service invoking the skill. The absolute path also couples the skill to a particular administrator environment and provides no integrity verification before execution. This finding does not establish that the referenced script is currently malicious. It identifies an insecure trust boundary: the project directs execution of code whose contents and provenance are unavailable for verification. ### Attack Path 1. An attacker first obtains write access to `/home/admin/.openclaw/workspace/scripts/system-maintenance.sh` or to a parent directory that permits replacing the file. 2. The attacker modifies or replaces the maintenance script with commands of their choice. 3. A user requests system maintenance or uses another trigger documented by the skill. 4. The agent follows the skill instructions and executes the external script without validating its ownership, permissions, integrity, or c ...[truncated 1172 chars]- Remediation
View remediation
Remediation Suggestions
- Include the maintenance script inside the audited skill package so its complete behavior can be reviewed and version-controlled.
- Invoke the script through a controlled project-relative path rather than a hardcoded administrator-specific absolute path.
- Verify the script's cryptographic hash or signature immediately before execution, using a trusted manifest that cannot be modified by the same account responsible for the script.
- Restrict ownership and permissions so the script and its parent directories are writable only by a trusted administrative identity and are not writable by the runtime account.
- Run diagnostics with a least-privileged service account. Isolate privileged repair operations and authorize them individually rather than granting the whole script elevated access.
- Separate read-only health checks from state-changing repairs. Require explicit user confirmation before destructive, privileged, or service-restarting operations.
- Validate the script as a regular file, reject symbolic links, and ensure its resolved path remains within an approved directory before execution.
- Document every command, external dependency, file accessed, network endpoint contacted, and privilege required by the maintenance process.
- Record integrity-check results and executed actions in protected audit logs while avoiding the storage of secrets or sensitive command output.
