T09 · Insecure Skill Coding Practices
- Location
handler.ts:139- Finding
Latent Shell Command Injection Through an Unvalidated Workspace Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This hook is a Review case because it can automatically rewrite and delete memory files and create broad Git commits without clear user control.
Install only if you are comfortable with an automatic hook managing your OpenClaw memory files and local Git history. Before enabling it, require explicit opt-in or dry-run behavior, path-limited Git staging, safe non-shell Git execution, validated backups or archive-before-delete, consistent trigger documentation, and no automatic push unless deliberately configured.
handler.ts:139Latent Shell Command Injection Through an Unvalidated Workspace Path
handler.ts:105Non-Transactional and Lossy Deletion of Memory Files
handler.ts:137Automatic Git Commit Stages Unrelated Workspace Changes
The declared purpose sounds like benign context compression, but the documented behavior includes deleting files, rewriting MEMORY.md, and running git commands. This mismatch is dangerous because users may install or approve the skill expecting summarization only, while the hook can automatically perform destructive state changes and persist them via version control.
The skill overwrites MEMORY.md and deletes files automatically without prior confirmation, backup, or clear user-facing warning. Because this skill operates on accumulated user memory, silent destructive actions are especially dangerous and can erase important context or sensitive evidence with little chance of recovery.
The skill automatically deletes memory files and rewrites repository state by appending to MEMORY.md and then committing the changes. In a context-management skill, destructive deletion without an explicit safety boundary, dry-run mode, or user approval can cause irreversible loss of user data and unexpected repository mutation beyond simple 'compression'.
The handler invokes shell-based git commands through execSync, which expands the skill's privileges from memory compression into arbitrary repository mutation. Even if the command strings are mostly fixed, this behavior can create unintended commits, alter audit history, and increases risk if workspaceDir is influenced by untrusted context or points to an unexpected location.
The documented trigger threshold conflicts with the stated skill metadata: the manifest says compression should occur only above 85%, while this hook documentation says cleanup starts above 60%. This mismatch is dangerous because it changes when destructive behavior activates, making data deletion/compression occur much earlier than users or reviewers would expect.
The skill documents automatic deletion of memory files and git push behavior without prominent warning or consent for modification and remote transmission. In this context, that is dangerous because the hook runs on routine events and may silently alter or exfiltrate sensitive conversational history to a repository.
The hook description expands beyond passive context shrinking into deletion of memory files and automatic git commit/push. That is materially broader than the declared purpose and introduces destructive local changes plus potential remote data transmission, which can surprise users and bypass expected consent boundaries.
The documentation states the hook executes silently and only logs output, reducing user awareness of destructive cleanup and repository operations. Silent execution makes the behavior more dangerous in this skill context because it can delete memory and transmit data without timely human review or intervention.
The skill documentation indicates behavior requiring environment and likely broader execution capabilities, but it declares no explicit tool scope or permissions. In a hook that can run automatically, undeclared capability use is dangerous because it hides the true trust boundary and can enable filesystem, environment, or command access without clear user consent or review.
The documentation describes cleanup and compression behavior without a clear warning that stored data may be modified, deleted, and committed automatically. In an auto-triggered hook, lack of disclosure is dangerous because users may expose important notes or lose data without realizing the skill performs destructive and persistent actions.
The file's comments, status messages, and user-facing strings are written in Chinese, and the skill does not indicate that language selection is configurable or intentionally region-specific. This can violate a language/locale policy when users are not given an opt-in or alternative locale.
The docstring claims the handler listens for both message:sent and command:reset events, but the code first returns unless type is 'message' with action 'sent' or 'received', and then immediately returns unless type is 'command' with action 'reset'. Because both conditions cannot be true in one event, the implementation contradicts the documented trigger behavior.
When no workspace is provided, the code falls back to process.env.HOME to locate and operate on a default workspace. Accessing environment-derived global paths is broader than the manifest's narrow purpose of compressing session memories and can redirect operations beyond the immediate session context.
The skill reads historical memory files, extracts selected lines, and appends them into MEMORY.md in plain text, potentially concentrating sensitive information into a more visible, durable file. In a memory-management context this is particularly risky because the deleted source material may contain credentials, personal data, or prior confidential prompts that are then preserved in summarized form.
The skill runs git add and git commit automatically with no warning or consent, causing silent side effects outside the core compression task. In an agent setting, automatic shell-triggered repository actions can surprise users, capture unintended files, and complicate recovery or forensic review.
The manifest describes the skill as automatically compressing session memories when context usage exceeds 60%, but it does not specify what event or platform condition actually invokes the hook, nor any exclusions or negative cases. For a manifest file, this broad automatic behavior can lead to unclear or unintended activation because the trigger scope is not explicitly defined.
The natural-language description is written in Chinese and the document continues primarily in Chinese, with no indication that users may choose another language or that the skill is intentionally region-specific. This can violate language/locale policy when a skill effectively constrains interaction language without opt-in.
The manifest description at L04 and feature list at L17 say the hook runs when context usage exceeds or reaches 85%, but the prose at L13 says it triggers at a 60% threshold. This is an active contradiction in the skill's own documentation about core behavior.
The file presents key operational details in Chinese while other parts are in English, which imposes a language assumption without explicitly offering a user choice or documenting a locale-specific requirement. This can violate language/locale policy when users are not given opt-in or an alternative language path.
The skill manifest context says the skill should auto-compress session memories when context usage exceeds 85%, but package.json describes the behavior as triggering when usage exceeds 60%. This is a direct description-level mismatch about when the skill acts, which changes the intended scope of behavior.
Detected: suspicious.dangerous_exec