T09 · Insecure Skill Coding Practices
- Location
SKILL.md:24- Finding
Safety-Critical Robot Commands Lack Mandatory Control Safeguards
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:24-35
Related Locations:SKILL.md:38-45,SKILL.md:54-59
Vulnerability Type: Unsafe physical actuation without documented authorization, validation, or fail-safe controls
Risk Level: HighVulnerable Code
python from openclaw_control import init_claw, get_claw # Initialize claw claw = init_claw() # Control operations claw.grab(force=50.0) claw.move_to(10, 20, 30) claw.release()The documented voice interface also exposes direct physical actions:
text - "Jarvis, grab the object" - "Jarvis, move to 10 20 30" - "Jarvis, rotate 45 degrees" - "Jarvis, release" - "Jarvis, return to home" - "Jarvis, claw status"The stated operating envelope includes potentially hazardous industrial equipment:
text - Reach: 2-3 meters (model-dependent) - Payload: 3-500 kg (model-dependent) - Precision: ±0.03-0.1 mm - Speed: 1-7000 mm/s - Response Time: <10msTechnical Analysis
The skill documentation presents initialization followed by immediate
grab,move_to, andreleaseoperations. It does not require operator authentication, role-based authorization, explicit confirmation, coordinate validation, workspace limits, force or speed bounds, human-presence checks, or simulation before physical execution.Collision detection is advertised as a feature, but the documented execution procedure does not establish that collision checking is mandatory before movement. No emergency-stop procedure, communications-loss behavior, command timeout, or fail-closed state is documented.
Because the interface accepts voice and programmatic commands, an inaccurate transcription, malformed input, unauthorized speaker, or upstream instruction manipulation could be converted into physical movement without an intervening safety gate.
Attack Path
- An attacker, unauthorized nearby speaker, or compromised upstream ...[truncated 1155 chars]
- Remediation
View remediation
Remediation Suggestions
- Require authenticated operators and role-based authorization before exposing hardware-control functions.
- Require explicit operator confirmation for physical movement, especially for voice-originated commands.
- Validate every coordinate, orientation, speed, force, duration, and axis against model-specific limits.
- Enforce configured workspace boundaries, exclusion zones, and self-collision constraints.
- Default to simulation or dry-run mode until hardware execution is explicitly enabled.
- Require collision checks and human-presence safety checks before and during every movement.
- Use conservative default speed and force limits rather than relying on caller-supplied values.
- Implement watchdog timers, command expiration, communications-loss handling, and a fail-closed safe state.
- Document and test an independent hardware emergency stop that cannot be overridden through the skill.
- Record authenticated command provenance and safety-validation results in an audit log.
- Add negative tests proving that unauthorized, out-of-range, stale, malformed, and unconfirmed commands cannot actuate hardware.
