T01 · Skill Instruction Hijacking
- Location
SKILL.md:23- Finding
Non-Overridable Skill Instructions Grant Unrestricted Owner Privileges
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is presented as a Feishu chat security layer, but it grants very broad owner powers and can bind that owner from weak or first-contact sources without enough enforcement evidence.
Install only if you can preconfigure and verify the Feishu owner ID before the bot is reachable, and do not rely on this package as the sole enforcement layer for file access, shell commands, or skill installation. Review the first-contact binding behavior and require a real runtime authorization gate before using it in shared or production chat environments.
SKILL.md:23Non-Overridable Skill Instructions Grant Unrestricted Owner Privileges
SKILL.md:43First Private-Message Sender Can Acquire the Privileged Owner Role
verify.sh:108Verifier Reports Static Policy Configuration as Active Security Enforcement
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
*.pem *.p12 *.pfx .env .env.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"~/.gnupg/",
"~/.aws/",
"~/.openclaw/credentials/",
"/etc/passwd",
"/etc/shadow",
"/proc/self/environ",
"/proc/self/cmdline",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"~/.gnupg/",
"~/.aws/",
"~/.openclaw/credentials/",
"/etc/passwd",
"/etc/shadow",
"/proc/self/environ",
"/proc/self/cmdline",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"~/.aws/",
"~/.openclaw/credentials/",
"/etc/passwd",
"/etc/shadow",
"/proc/self/environ",
"/proc/self/cmdline",
"/var/log/",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"~/.aws/",
"~/.openclaw/credentials/",
"/etc/passwd",
"/etc/shadow",
"/proc/self/environ",
"/proc/self/cmdline",
"/var/log/",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"*.pem",
"*.p12",
"*.pfx",
"*.env",
".env.*"
],
"injection_keywords": {
The README presents all user-facing instructions, expected replies, and trigger commands exclusively in Chinese, such as "绑定主人" and "安装技能 xxx". Under the policy, forcing a specific language without user opt-in is a natural-language locale constraint and should be flagged unless the skill offers alternatives or clearly documents a justified region-specific limitation.
The skill describes shell-capable behavior such as executing system commands, reading/modifying files, and includes executable Python snippets, but it does not declare any explicit tool scope or allowed-tools policy. In an agent framework, missing tool declarations can cause over-broad execution capability or bypass policy enforcement, especially for a security-focused skill that is expected to constrain rather than expand execution.
The owner-binding flow is triggered by vague natural-language phrases like '绑定主人' or similar wording, which can be matched accidentally in ordinary conversation or socially engineered by another user. Because this path controls ownership establishment, ambiguous triggering increases the chance of unintended privileged state transitions.
The natural-language command keywords for owner and skill-install actions are predominantly Chinese phrases, which implies the skill recognizes or expects a specific language. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy concern.
All user-visible messages and instructions in the script are presented only in Chinese, including installation status and next-step guidance. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in or an explicitly documented justification.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
setup_directories() {
print_info "创建目录结构..."
mkdir -p "${SCRIPT_DIR}/logs"
chmod 700 "${SCRIPT_DIR}"
chmod 750 "${SCRIPT_DIR}/logs"
print_success "目录创建完成"
}
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
print_info "创建目录结构..."
mkdir -p "${SCRIPT_DIR}/logs"
chmod 700 "${SCRIPT_DIR}"
chmod 750 "${SCRIPT_DIR}/logs"
print_success "目录创建完成"
}
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
print_info "创建目录结构..."
mkdir -p "${SCRIPT_DIR}/logs"
chmod 700 "${SCRIPT_DIR}"
chmod 750 "${SCRIPT_DIR}/logs"
print_success "目录创建完成"
}
The installer automatically pulls an owner identifier from unrelated local state (~/.openclaw/openclaw.json) or FEISHU_OWNER_ID and then uses it to bind and lock the skill configuration. This creates a trust-boundary violation: local ambient data is treated as authoritative identity without explicit user confirmation, so a stale, wrong, or attacker-influenced value could silently assign control of the skill to the wrong account.
The script consumes local config and environment data for security-sensitive owner binding without a user-facing warning or consent step. In an installation context for a chat-security skill, silent identity capture is risky because users may not realize ambient machine state is being used to define who controls the bot.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
set_permissions() {
print_info "设置文件权限..."
chmod 600 "${SCRIPT_DIR}/config.json"
print_success "权限设置完成"
}
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
set_permissions() {
print_info "设置文件权限..."
chmod 600 "${SCRIPT_DIR}/config.json"
print_success "权限设置完成"
}
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
set_permissions() {
print_info "设置文件权限..."
chmod 600 "${SCRIPT_DIR}/config.json"
print_success "权限设置完成"
}
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
print_info "初始化日志文件..."
LOG_FILE="${SCRIPT_DIR}/logs/security.log"
touch "$LOG_FILE"
chmod 640 "$LOG_FILE"
cat >> "$LOG_FILE" << EOF
[$(date '+%Y-%m-%d %H:%M:%S')] [INFO] 飞书群聊安全隔离 Skill v2.0.0 初始化
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
print_info "初始化日志文件..."
LOG_FILE="${SCRIPT_DIR}/logs/security.log"
touch "$LOG_FILE"
chmod 640 "$LOG_FILE"
cat >> "$LOG_FILE" << EOF
[$(date '+%Y-%m-%d %H:%M:%S')] [INFO] 飞书群聊安全隔离 Skill v2.0.0 初始化
The script's header, usage guidance, and all user-facing instructions are written exclusively in Chinese, and later operational guidance requires exact Chinese phrases such as "绑定主人" and "查看主人". This imposes a language requirement on users without any opt-in, alternative locale, or documented regional justification, which matches the language/locale policy violation criteria.
The manual verification checklist says the owner installing a skill should 'directly install successfully', which conflicts with the script's earlier requirement that skill installation approval be enabled. In a security-sensitive verification tool, contradictory operational guidance can cause testers to validate an insecure workflow or normalize bypassing approval controls, weakening the intended access-control model.
The installation flow uses broad natural-language invocation like '安装技能 xxx' without a tightly defined command grammar. That can cause accidental installs from normal discussion text or make approval workflows easier to manipulate through phrasing collisions, although the owner-approval step reduces severity.
The comments imply secure owner identification will be handled later via Feishu API, but the installer already performs owner binding from weaker sources and marks the security state as BOUND and locked = true. This mismatch can mislead operators into believing binding is deferred or verified when, in fact, it already occurred based on unverified local data.
No suspicious patterns detected.