Back to skill

Security audit

会话名称修改

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned, but it edits OpenClaw session state using an unsafe command template that can execute unintended code if given a crafted session name.

Review before installing. Use only with simple trusted labels, close OpenClaw and back up sessions.json before any edit, and prefer a safer version that passes the session key and label as command arguments or uses an official OpenClaw API instead of interpolating them into python3 -c source.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

Arbitrary Code Execution Through Unsafe Session Label Interpolation

Content
View full analysis
' # Retrieved from sessions_list if key in data: data[key]['label'] = '' with open(path, 'w') as f: json.dump(data, f, indent=2, ensure_ascii=False) print(f'Label set: ') " ``` The displayed English placeholders and comments above correspond to the original template's session-key and new-name placeholders. ### Technical Analysis The skill directs the agent to replace `` with the user-supplied session name inside a single-quoted Python string embedded in a `python3 -c` command. No escaping, encoding, argument passing, or validation boundary is defined. A session name containing a single quote can terminate the intended string and introduce additional Python statements. For example, a value shaped like: ```text '; __import__('os').system('id'); # ``` would cause the generated assignment to become equivalent to: ```python data[key]['label'] = ''; __import__('os').system('id'); #' ``` The injected statement is then evaluated by the Python interpreter. Because the payload can invoke `os.system`, `subprocess`, or arbitrary Python APIs, this is not limited to corrupting the JSON file; it provides a general command-execution primitive. The `` placeholder is also interpolated into executable source. Although the documented source for that value is the trusted `sessions_list` tool, it should still be treated as data rather than generated Python syntax. ### Attack Path 1. An attacker convinces a user or agent to rename a session to a specially crafted value containing a quote and injected Python state ...[truncated 1429 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README instructs users to directly modify a live application data file under ~/.openclaw without warning about corruption, backup, concurrency, or version-compatibility risks. Even though the described goal is legitimate, encouraging direct edits to a session store can lead to accidental data loss or broken session metadata if the file format changes or the app writes concurrently.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad natural-language examples such as '改会话名', 'rename session', and '修改会话标题', which can match ordinary conversation and cause the skill to run when the user did not intend to edit persistent session metadata. Because this skill directly writes to a local JSON state file, unintended invocation can result in unauthorized or accidental renaming of sessions and integrity issues in session organization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The README presents usage primarily in Chinese and instructs the user to '对 OpenClaw 说' followed by Chinese trigger phrases, with only one English example and no explicit statement that users may choose their preferred language. This can be read as a language-default assumption rather than an opt-in or explicit locale choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.