T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/publish.py:123- Finding
Path Traversal Allows Unauthorized Git Operations and Potential Public Exposure of Local Directories
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed skill generator, but its save and publish scripts can affect files and public repositories too broadly for the stated workflow.
Review carefully before installing. Use only with trusted skill names, inspect generated files before saving or publishing, avoid running the publish script on unreviewed skills, and do not authorize public GitHub or ClawHub publication until path validation and explicit confirmation controls are added.
scripts/publish.py:123Path Traversal Allows Unauthorized Git Operations and Potential Public Exposure of Local Directories
scripts/generate.py:129LLM-Controlled Skill Name Allows Filesystem Path Traversal and Arbitrary File Placement
scripts/publish.py:91Untrusted Skill Metadata Is Persisted in the Agent Memory Directory
The declared purpose is only skill generation, but the documented behavior also includes external publication, repository creation/push, and promotional content generation. This mismatch is dangerous because users may invoke what appears to be a local content-generation tool while it actually performs outbound publishing and command execution with persistence outside the local environment.
This file automates publication to ClawHub and GitHub, including creating public repositories and pushing local content, despite the skill being described as a generator for reusable Skill code/templates. In this context, the mismatch is dangerous because a user invoking a 'skill generator' may unknowingly trigger external data transfer and public disclosure of generated or local workspace content.
The main workflow orchestrates publishing and promotional actions that materially exceed the manifest's stated 'skill generation' scope. This is dangerous because hidden capability expansion undermines user consent and can lead to unanticipated publication of content to public platforms, increasing confidentiality and supply-chain risk.
The skill advertises capabilities that include reading/writing files and invoking shell commands, but it does not declare any tool scope or permission boundaries. In a generator that can create, save, and publish artifacts, this makes it easier for the skill to perform unintended filesystem changes or command execution without clear user awareness or platform enforcement.
The trigger phrases are broad enough to match common requests like '创建skill' or '做一个skill', increasing the chance of accidental activation. In this context, accidental activation is more dangerous because the skill can lead to file creation and possibly publication workflows rather than a harmless read-only response.
The manifest description and usage are written as directives for Chinese natural-language input ('自然语言描述需求') and do not indicate that other languages are supported or that the Chinese-only expectation is optional. This can be a language/locale policy issue because the skill appears to impose a specific language without user opt-in or justification.
The markdown states that saving can be followed by publication to GitHub and ClawHub, yet it does not prominently warn users about external side effects such as creating repositories, pushing content, or exposing generated material publicly. This is especially risky in a generation skill because generated output may contain sensitive, unreviewed, or policy-violating content that gets published unintentionally.
The usage examples encourage natural-language activation without defining when the skill should and should not take over, which can cause ambiguous routing. Because this skill can create artifacts and initiate downstream publishing steps, ambiguity raises the risk of unintended actions from routine user requests.
This code file contains multiple natural-language strings that assume Chinese as the required interaction language, beginning with the module docstring and continuing in prompts and demo output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.
This Python file contains natural-language descriptions and messages entirely in Chinese, including the module docstring and later user-facing usage text, with no indication that the skill is region-specific or that users can choose another language. That creates a language/locale policy concern because the skill appears to mandate a specific language without opt-in.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""发布到ClawHub"""
print(f"📦 发布到ClawHub: {skill_name}...")
try:
result = subprocess.run(
[CLAWHUB_CMD, "publish", skill_name],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
# 初始化git(如果需要)
if not os.path.exists(os.path.join(local_path, ".git")):
subprocess.run(["git", "init"], cwd=local_path, check=True)
subprocess.run(["git", "add", "."], cwd=local_path, check=True)
subprocess.run(
["git", "commit", "-m", f"Add {skill_name} skill"],
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# 初始化git(如果需要)
if not os.path.exists(os.path.join(local_path, ".git")):
subprocess.run(["git", "init"], cwd=local_path, check=True)
subprocess.run(["git", "add", "."], cwd=local_path, check=True)
subprocess.run(
["git", "commit", "-m", f"Add {skill_name} skill"],
cwd=local_path, check=True
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if not os.path.exists(os.path.join(local_path, ".git")):
subprocess.run(["git", "init"], cwd=local_path, check=True)
subprocess.run(["git", "add", "."], cwd=local_path, check=True)
subprocess.run(
["git", "commit", "-m", f"Add {skill_name} skill"],
cwd=local_path, check=True
)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
)
# 创建GitHub仓库并推送
result = subprocess.run(
["gh", "repo", "create", repo_name, "--public", "--source", ".", "--push"],
cwd=local_path,
capture_output=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
else:
# 仓库可能已存在,尝试推送
if "already exists" in result.stderr:
subprocess.run(["git", "push", "origin", "main"], cwd=local_path, check=True)
return GITHUB_REPO_BASE + repo_name
print(f"⚠️ GitHub发布失败: {result.stderr}")
return None
Generating Douyin promotional copy is outside the declared purpose of creating Skill code/templates and introduces undisclosed marketing behavior. In skill context, this broadens the agent's behavior into promotion and persistence of marketing content, which can surprise users and facilitate unintended external sharing workflows.
The generated Douyin post instructs users to invoke the skill using the Chinese phrase "帮我创建一个{name}" and does not present alternatives for other languages or locales. Because this is natural-language behavior embedded in the code, it constitutes a policy issue unless the skill is explicitly documented as Chinese-only or locale-specific.
The manifest description is written only in Chinese ("自然语言需求转换为Skill结构"), which indicates a language-specific presentation without any visible opt-in, alternative locale, or justification in this file. Under the stated policy, forcing a specific language can be a natural-language policy violation when no user choice is offered.
No suspicious patterns detected.