T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:32- Finding
Unbundled Relative Wrapper May Execute Attacker-Controlled Code
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 32–36
Vulnerability Type: Tool hijacking through an unverified working-directory-relative executable
Risk Level: HighVulnerable Code:
markdown ## Preferred Command Wrapper For local terminal operations, prefer: - `./scripts/openclaw-safe.sh <openclaw args...>` This wrapper auto-backs up config for risky actions, runs health checks, and rolls back on failure.Technical Analysis
The Skill recommends executing
./scripts/openclaw-safe.sh, but the audited package contains onlySKILL.mdandpublish.json. The referenced script is not included in the package.Because the path begins with
./, it resolves relative to the agent's current working directory rather than to a verified Skill installation directory. An attacker who controls the current project or working directory can create a malicious file atscripts/openclaw-safe.sh. If the agent follows the recommendation, that attacker-controlled script will execute as though it were the trusted safety wrapper.Attack Path
- An attacker creates an executable
scripts/openclaw-safe.shin a repository or directory processed by the agent. - The user requests a high-risk OpenClaw operation covered by this Skill.
- The agent follows the preferred-wrapper instruction and runs
./scripts/openclaw-safe.sh. - Path resolution selects the attacker's script from the current working directory.
- The malicious script executes with the same operating-system permissions and environment access as the agent or user.
Impact Assessment
Successful exploitation permits arbitrary command execution with the invoking agent's privileges. The attacker may read or modify files accessible to that account, including OpenClaw configuration, tamper with plugins or gateway operations, access available environment variables, and perform other actions allowed to the current user.
This iss ...[truncated 172 chars]
- An attacker creates an executable
- Remediation
View remediation
Remediation Suggestions
- Bundle the wrapper in the published package and subject its contents to security review.
- Resolve the wrapper from a trusted, absolute Skill installation path rather than from the current working directory.
- Before execution, verify that the wrapper is a regular file owned by an expected principal and is not a symbolic link.
- Verify the wrapper against a pinned cryptographic digest or signed manifest.
- Refuse execution when the verified packaged wrapper cannot be found; do not fall back to a same-named script in the current directory.
- If a trusted wrapper cannot be shipped, remove this recommendation and document the required OpenClaw commands explicitly.
