T09 · Insecure Skill Coding Practices
- Location
SKILL.md:4- Finding
Shell Command Injection Through User-Controlled Command Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:4andSKILL.md:57-61
Vulnerability Type: Shell command injection
Risk Level: HighVulnerable Code
text description: Save any web page as an Obsidian-compatible Markdown clipping. Triggered by "save <URL>" or "保存这个". Uses Jina Reader API for clean content extraction. Supports custom tags, subfolders, and vault paths. Saves to ~/.openclaw/obsidian-cache/clippings/ by default. TRIGGER "save <URL>" / "保存这个" / any URL with "save" or "clip" -> ALWAYS exec: python3 ~/.openclaw/skills/web-clipper/scripts/save_web_page.py --url "URL" -> Confirm the saved filename to user. NEVER use memory.bash python3 ~/.openclaw/skills/web-clipper/scripts/save_web_page.py \ --url "https://example.com/article" \ --folder "clippings/tech" \ --tags "ai,tools" \ --vault "/path/to/your/obsidian/vault"Technical Analysis
The Skill directs the agent to construct a command by interpolating user-controlled URL, folder, tag, and vault values into a textual shell command. Quoting a value with double quotes does not neutralize shell command substitution, and a quote character supplied by the user can terminate the quoted argument.
For example, if a shell processes a URL containing a payload such as:
text https://example.com/"; id; #direct substitution into the documented command can produce:
bash python3 ~/.openclaw/skills/web-clipper/scripts/save_web_page.py --url "https://example.com/"; id; #"The shell would execute
idas a separate command. Command substitution constructs such as$()can also be evaluated inside double quotes.The Python script uses
argparseand does not itself invoke a shell. The vulnerable boundary is therefore the Skill instruction that encourages textual shell-command construction. Exploitability depends on the agent execution tool passing that command through a shell rather than ...[truncated 1069 chars]- Remediation
View remediation
Remediation Suggestions
-
Require a structured process-execution API that passes an argument array without invoking a shell:
python [ "python3", script_path, "--url", user_url, "--folder", user_folder, "--tags", user_tags, "--vault", user_vault, ] -
Explicitly state in
SKILL.mdthat the command must never be executed withshell=True,sh -c,bash -c, or an equivalent shell interpreter. -
Do not ask the agent to create one textual command through direct interpolation.
-
Validate that URLs contain only expected URL syntax before execution.
-
Treat
--folder,--tags, and--vaultas untrusted data even when the URL is valid. -
If a shell is unavoidable, use a proven platform-specific argument-quoting mechanism for every value and reject shell control characters. Structured non-shell execution remains the preferred fix.
-
