T01 · Skill Instruction Hijacking
- Location
scripts/setup_agents.py:224- Finding
Persistent Instruction Injection Through Unsanitized Agent Profile Fields
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it claims, but it needs review because it handles Lark app secrets and writes persistent agent configuration in ways that are under-scoped.
Review before installing. Use a protected config file instead of inline --config for real Lark secrets, check permissions on ~/.openclaw/openclaw.json, inspect generated IDENTITY.md and SOUL.md before using new agents, and confirm that automatic agentToAgent.allow changes match your intended trust boundary.
scripts/setup_agents.py:224Persistent Instruction Injection Through Unsanitized Agent Profile Fields
SKILL.md:44Lark Application Secrets Exposed Through Command-Line Arguments
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
save_config(cfg)
print(f"✅ agent '{agent_id}' 已从配置中移除")
print(f" ⚠️ 工作区目录未删除,请手动确认是否清除:")
print(f" rm -rf {OPENCLAW_DIR}/workspace-{agent_id}")
print(f" rm -rf {OPENCLAW_DIR}/agents/{agent_id}")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
print(f"✅ agent '{agent_id}' 已从配置中移除")
print(f" ⚠️ 工作区目录未删除,请手动确认是否清除:")
print(f" rm -rf {OPENCLAW_DIR}/workspace-{agent_id}")
print(f" rm -rf {OPENCLAW_DIR}/agents/{agent_id}")
# ─── 创建单个 agent ───────────────────────────────────────────────────────────
The skill documents shell execution and file-modifying behavior but does not declare any tool scope or allowed-tools boundary. That creates an unsafe trust gap: an invoking agent may gain or assume broad shell/file capabilities without explicit least-privilege constraints, increasing the risk of unintended filesystem changes or command execution.
The skill instructs users to place Feishu App Secret values directly in command-line arguments and inline JSON. Secrets passed this way can be exposed via shell history, terminal scrollback, process listings, audit logs, and agent transcripts, which is especially risky because these credentials control external service accounts.
The module docstring and all user-facing usage/help documentation in this file are written exclusively in Chinese, which imposes a specific language on users without offering a choice or documenting a justified locale restriction. The stated policy flags language or locale constraints when they are forced without opt-in.
The skill is presented primarily as a batch agent configuration tool, but it also performs destructive deletion and service restarts. That scope expansion is security-relevant because users or orchestrators may invoke it expecting only additive configuration changes, yet it can remove agents and disrupt availability.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def check_plugin_installed() -> bool:
"""检查 @larksuite/openclaw-lark 是否已安装"""
try:
result = subprocess.run(
["openclaw", "plugins", "list", "--json"],
capture_output=True, text=True, timeout=10
)
When creating an agent, the code silently adds the new agent ID to tools.agentToAgent.allow, modifying global inter-agent communication permissions beyond simple Lark account setup. This broadens the agent's ability to interact with other agents and may enable lateral movement or privilege expansion if the new agent is misconfigured or compromised.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd_remove(args.remove, dry_run=args.dry_run)
if args.restart and not args.dry_run:
print("\n🔄 重启 gateway...")
subprocess.run(["openclaw", "gateway", "restart"], check=False)
return
if args.set_channel:
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd_remove(args.remove, dry_run=args.dry_run)
if args.restart and not args.dry_run:
print("\n🔄 重启 gateway...")
subprocess.run(["openclaw", "gateway", "restart"], check=False)
return
if args.set_channel:
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd_remove(args.remove, dry_run=args.dry_run)
if args.restart and not args.dry_run:
print("\n🔄 重启 gateway...")
subprocess.run(["openclaw", "gateway", "restart"], check=False)
return
if args.set_channel:
The file consistently presents activation phrases, workflow, and operational instructions only in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not done here.
The manifest description is written entirely in Chinese and provides no indication that the skill supports other languages or that Chinese is a required locale. Under the policy, forcing a specific language without user opt-in or clear justification is a natural-language policy concern.
No suspicious patterns detected.