T02 · Agent Memory Poisoning
- Location
scripts/operation_search.py:239- Finding
Persistent ControlMemory Records Are Executed as Untrusted Shell Commands
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This macOS desktop-control skill matches much of its purpose, but it includes unsafe persistent command, scheduled task, and sync behavior that needs careful review before installation.
Install only if you are comfortable granting a terminal or agent broad macOS control permissions. Avoid enabling ClawHub sync or cron helpers until the skill uses structured allowlisted actions instead of stored shell scripts, pins dependencies, and adds explicit review before executing or sharing operation records.
scripts/operation_search.py:239Persistent ControlMemory Records Are Executed as Untrusted Shell Commands
scripts/natural_language.py:356Natural-Language Parameters Are Interpolated into Shell Commands
scripts/scheduled_task.sh:44Scheduled-Task Interface Installs Arbitrary Persistent Shell Commands
scripts/setup_cron.sh:49ClawHub Synchronization Can Be Installed as a Recurring Background Network Task
scripts/control_memory.py:39Stable Host-and-Username Fingerprint Is Collected for Contributor Attribution
SKILL.md:45Python Dependencies Are Unpinned and Installed from Mutable Package Index State
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
创建配置文件:
nano /Users/zhangchangsha/.openclaw/workspace/skills/macos-desktop-control/.env
内容:
The changelog describes a desktop-control skill that activates from broad natural-language requests like everyday conversational phrases, without any documented scoping, confirmation, or allowlist boundaries. In a powerful macOS control context, ambiguous activation can cause unintended screenshots, app launches/closes, window moves, or automation flows from benign user text or prompt-injected content.
The documented command examples include common conversational phrases such as opening apps, closing apps, and starting workflows without any scope constraints or safety gates. Because this skill controls the desktop, these broad phrases increase the risk of accidental execution, misuse via indirect prompt text, and harmful state changes triggered from ordinary language.
The example code explicitly recommends extending the dispatcher with subprocess.run(..., shell=True), which is dangerous in a natural-language command framework because future developers may interpolate user-derived text into shell commands. That creates a straightforward command-injection path that could execute arbitrary shell commands on the user's macOS system.
elif action == 'new_action':
print("执行新动作...")
subprocess.run("具体命令", shell=True)
The example uses subprocess.run with shell=True and interpolates the app variable directly into the shell command, which enables command injection if app is attacker-controlled or derived from natural-language input. In a desktop-control skill, that is especially dangerous because the whole purpose is to act on user requests, making untrusted input highly likely and potentially leading to arbitrary local command execution.
# 在 natural_language.py 中
# 成功执行后自动记录
if action == 'app_open':
subprocess.run(f"open -a '{app}'", shell=True)
# 记录到 ControlMemory
memory.record_success(
app_name=app,
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
uage.py 中
if action == 'app_open': subprocess.run(f"open -a '{app}'", shell=True) # 记录到 ControlMemory memory.record_success( app_name=app, command=f"打开{app}", script=f"open -a '{app}'" )
---
### 3. 同步到 ClawHub
```bash
# 手动同步
python3 scripts/clawhub_sync.py
# 自动同步(每小时)
# 配置 crontab
0 * * * * cd /Users/zhangchangsha/.openclaw/workspace/skills/macos-desktop-control && python3 scripts/clawhub_sync.py
用户操作
↓
自然语言控制
↓
执行成功
↓
ControlMemory 记录
↓
本地存储 (controlmemory.md)
↓
ClawHub 同步 (每小时)
↓
社区共享
def is_duplicate(self, new_record):
"""检查是否重复"""
app = new_record['app']
command = new_record['command']
script = new_record['script']
# 检查应用和命令组合
if f"###
The plan explicitly expands a local macOS desktop-control skill into a cloud-connected telemetry and sharing system by adding ClawHub upload/download and community synchronization. That materially changes the trust boundary and capability scope from local automation to remote data transfer, which is dangerous because it can exfiltrate user behavior and command contents without that functionality being clearly part of the stated skill purpose.
The sample code stores raw command text in a record object and immediately calls remote synchronization for each new record. This is a concrete exfiltration path: sensitive user input is captured at the point of execution and sent off-device without any shown redaction, review, or explicit user approval.
The ClawHubSync design adds scheduled remote download/upload behavior and merge logic to a skill described as desktop control via native macOS tools. Introducing API-based data transfer and periodic synchronization creates a new exfiltration and supply-chain surface not reflected in the skill metadata, increasing the likelihood that users or reviewers will underestimate the security impact.
The documented flow automatically executes previously stored scripts selected by similarity matching, which is dangerous because natural-language similarity is not a security boundary. A stale, poisoned, or overly broad stored operation could be matched to a new request and executed without fresh validation, enabling unintended command execution with system impact.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
The skill heavily guides users to modify macOS privacy settings and grant Accessibility, AppleEvents, and ScreenCapture, but its top-level description does not sufficiently emphasize the sensitivity of those grants or their abuse potential. For a desktop-control tool, broad TCC permissions meaningfully increase the consequences of misuse because they enable observation and control of other apps and on-screen data.
No suspicious patterns detected.