Back to skill

Security audit

Code Stats

Security checks for vulnerabilities and agentic risk

Overview

This skill counts code files and lines, but it needs review because its recursive scanner can follow symlinks outside the intended workspace and read more files than a user may expect.

Review before installing if your workspace may contain symlinks to sensitive or very large directories. Prefer a version that lets you choose the repository path, rejects or safely handles symlinks, enforces workspace containment, and has file/depth limits.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:35
Finding

Workspace Boundary Bypass Through Symbolic-Link Traversal

Content
View full analysis

Vulnerability Details

File Location: index.js, lines 35–39
Vulnerability Type: Unrestricted symbolic-link traversal
Risk Level: Medium

js
const fullPath = path.join(dir, item);
const stat = fs.statSync(fullPath);

if (stat.isDirectory()) {
  walkDir(fullPath, stats);
} else {

Technical Analysis

The recursive scanner uses fs.statSync(), which follows symbolic links, and does not validate the canonical path of each traversed entry against the configured workspace root. Consequently, a symbolic link located within /home/duan/.openclaw/workspace can resolve to a directory outside that workspace.

Once followed, walkDir() recursively enumerates the linked directory, while countLines() reads accessible files to calculate line counts. The code neither rejects symbolic links through fs.lstatSync() nor tracks canonical directories already visited. This also permits symbolic-link cycles that can cause unbounded recursion until the process fails.

Attack Path

  1. An attacker gains the ability to add a filesystem entry to the scanned workspace, such as through a cloned or extracted repository.
  2. The attacker creates a symbolic link inside the workspace that points to an accessible directory outside it.
  3. A user invokes the Skill through node index.js or npm start.
  4. fs.statSync() follows the symbolic link and reports the target as a directory.
  5. walkDir() recursively enumerates the external target, and countLines() reads its files.
  6. Aggregate file and line statistics for out-of-scope data are included in program output. If the link creates a directory cycle, recursion may instead exhaust process resources or terminate with an error.

Impact Assessment

Exploitation occurs with the filesystem privileges of the Node.js process; it does not grant additional operating-system privileges. The scanner can read any file reachable through the symbolic link that the invokin ...[truncated 489 chars]

Remediation
View remediation

Remediation Suggestions

  1. Use fs.lstatSync() for each directory entry and reject symbolic links before traversal:
    js
    const stat = fs.lstatSync(fullPath);
    if (stat.isSymbolicLink()) continue;
    
  2. Canonicalize the workspace root and every candidate path with fs.realpathSync(). Traverse a path only when it equals the canonical root or begins with the canonical root followed by path.sep.
  3. Maintain a set of visited canonical directory paths, or device/inode pairs, to prevent cycles and repeated traversal.
  4. Handle filesystem errors around readdirSync(), lstatSync(), and realpathSync() so inaccessible or concurrently removed entries do not terminate the scan.
  5. Consider traversal limits, such as maximum depth, file count, and file size, to reduce denial-of-service risk from hostile repository contents.
  6. Accept an explicitly selected repository path rather than relying solely on the hardcoded, user-specific workspace path, and document the enforced traversal boundary.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is written entirely in Chinese and does not indicate that other languages are supported or that the language choice is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.