T05 · Unauthorized Access and Privilege Escalation
- Location
scan.sh:477- Finding
Path Traversal in the Skill Comparison Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed OpenClaw skill scanner, but one comparison command can be steered outside the declared skill directories and copy readable files into predictable /tmp locations.
Install only if you are comfortable with it reading installed skill source and contacting GitHub. Run it as a non-root user in an isolated environment, avoid OPENCLAW_NONINTERACTIVE=true unless necessary, and do not use the compare command with untrusted skill names until path validation and mktemp-based temporary directories are fixed.
scan.sh:477Path Traversal in the Skill Comparison Command
scan.sh:486Predictable and Non-Exclusive Temporary Directory Creation
The trigger phrase set includes broad, natural-language requests such as asking whether a skill is safe, which can overlap with ordinary conversation and cause the skill to activate unexpectedly. Because this skill reads local skill directories and may access GitHub and /tmp, accidental invocation expands data exposure and could trigger scanning behavior the user did not explicitly intend.
Several triggers are short and ambiguous, making accidental activation more likely in routine support or discussion contexts. In this skill, unintended activation is more dangerous than usual because the documented behavior includes reading potentially sensitive files from ~/.openclaw/skills and making outbound network requests to GitHub.
The description states the skill will generate a Chinese risk assessment report, which imposes a specific language behavior. Forcing a locale or language without user opt-in is a natural-language policy violation under the stated rules.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
if grep -r "sudo\|chmod\|chown\|kill\|rm -rf" "$dir" 2>/dev/null | grep -qv "#" | grep -q .; then
echo " ⚠️ 危险系统操作 (高风险)"
((risk_score+=30))
echo " 说明: 可导致系统损坏,建议不授予 sudo 权限"
else
echo " ✅ 无危险系统操作"
fi
The compare_skills function uses raw user-supplied skill names in path construction and recursive copy operations without applying the same sanitization used elsewhere. An attacker can supply path traversal values such as '../' to make the script copy arbitrary directories from locations accessible to the user, which can expose sensitive files or cause unintended filesystem access.
The description states that the skill generates a “中文风险评估报告,” which imposes a specific language on output. There is no indication that users can opt into another language or that the Chinese-only behavior is required for a documented region-specific purpose.
The trigger phrase "帮我看看这个技能" is broad and conversational, making accidental invocation more likely during normal discussion about skills. Because this skill has read access to local skill directories and network access to GitHub, unintended activation could expose local skill contents or initiate scanning activity the user did not clearly intend.
The language behavior is determined automatically from the host locale, which can force a specific language variant without the user actively choosing it. The policy allows locale choices when they are explicitly offered or opted into; here, auto-selection happens by default before any user choice is made.
The messages state that network requests are mandatory for trading skills and explain findings in that narrow context. But this script supports scanning arbitrary installed skills and GitHub repositories, so presenting network access as inherently justified conflicts with the actual general-purpose scanning behavior and can mislead users about risk interpretation.
No suspicious patterns detected.