T09 · Insecure Skill Coding Practices
- Location
scripts/goal-task.sh:65- Finding
Python Code Injection Through Unsafely Interpolated Task Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This scheduling helper has a coherent purpose, but its script can run unintended local code from crafted task text and can leave persistent cron jobs using a local gateway token.
Install only if you are comfortable with a shell script reading your OpenClaw gateway token and creating, updating, and deleting persistent remote cron jobs. Do not pass untrusted task text to goal_task until the JSON/Python construction is fixed, and check for stale goal-task cron jobs after use.
scripts/goal-task.sh:65Python Code Injection Through Unsafely Interpolated Task Data
scripts/goal-task.sh:65Recurring Cron Job Can Persist Indefinitely When Agent-Driven Cleanup Fails
scripts/goal-task.sh:77Gateway Authentication Token Is Exposed Through Process Arguments
The description is written as an instruction/presentation entirely in Chinese and frames the skill behavior in that locale without any indication that users may choose another language. Under the policy, language-specific behavior should not be forced unless there is explicit opt-in or a documented region-specific justification.
The documentation explicitly states that the script will automatically read a gateway token from ~/.openclaw/openclaw.json, but it does not warn the user that sensitive credentials will be accessed and used. This can normalize implicit credential use, reduce informed consent, and increase the chance that a skill executes with broader privileges than the operator expects.
The metadata is internally contradictory: it declares that no credentials are required, but then states that a gateway token is read from a local credentials file at runtime. This can mislead users, reviewers, and automation into granting or exposing access they did not expect, and it obscures the skill's true trust and credential requirements.
Saying 'No credentials required' while simultaneously disclosing runtime token access is a security-significant misrepresentation. In this skill context, the skill creates cron tasks and interacts with a gateway, so hidden credential use increases the risk of unauthorized scheduling actions or misuse of an existing local token under false assumptions of harmlessness.
The script reads a gateway authentication token directly from the user's local config file and then uses it to create, update, and delete remote cron jobs. While token access is functionally related to the feature, silently harvesting credentials from a private config path expands the skill's privilege boundary and creates unnecessary secret exposure if the script is modified, logged, or reused in other contexts.
The script accesses a gateway token and performs remote state-changing actions against the cron service without any user-facing disclosure, confirmation, or consent step. This is dangerous because users invoking a seemingly simple scheduling helper may not realize it can read local secrets and mutate persistent remote jobs on their behalf.
The natural-language comments and user-facing guidance are written in Chinese, and later runtime messages also assume that locale without any opt-in or alternative. This can violate language policy when a skill forces a specific language rather than offering user choice or documenting a justified locale constraint.
No suspicious patterns detected.