T09 · Insecure Skill Coding Practices
- Location
scripts/research_ledger.py:165- Finding
Output Directory Escape Enables Arbitrary Recursive Directory Deletion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent research helper, but its ledger tool can delete directories outside its research folder if invoked with unsafe options.
Review before installing. The research workflow itself is disclosed and sensible, but run it in a restricted workspace and avoid using --force or path-like --name values until the ledger script validates that reset targets stay inside the intended research run directory. Do not store secrets or unnecessary private data in evidence logs.
scripts/research_ledger.py:165Output Directory Escape Enables Arbitrary Recursive Directory Deletion
The skill instructs the agent to read local files, write run artifacts, and perform broad web research, but it does not declare any explicit tool scope or permissions boundary. That creates an overbroad operational surface where a host agent may grant more file and network access than necessary, increasing the risk of unintended data exposure, unsafe file access, or over-privileged execution during research runs.
The skill description is extremely broad and overlaps with many general-purpose research, verification, due-diligence, and decision-support tasks, making it likely to be invoked in situations beyond its safest intended use. In combination with file, write, and network-capable behavior, ambiguous routing increases the chance that sensitive tasks are delegated to a skill that performs wide source ingestion and local artifact handling, expanding exposure to prompt-injection and data-leak risks.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.openclaw/skills
unzip skill.zip -d ~/.openclaw/skills
ls ~/.openclaw/skills/deep-research/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/skills
unzip skill.zip -d ~/.openclaw/skills
ls ~/.openclaw/skills/deep-research/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p ~/.openclaw/skills
unzip skill.zip -d ~/.openclaw/skills
ls ~/.openclaw/skills/deep-research/SKILL.md
When --force is supplied, the script recursively deletes an existing non-empty run directory with shutil.rmtree(). Although the CLI help says 'reset an existing non-empty run directory,' there is no runtime confirmation prompt or explicit deletion warning at the point of execution, and this operation can irreversibly remove user data.
No suspicious patterns detected.