T09 · Insecure Skill Coding Practices
- Location
SKILL.md:84- Finding
Potential Shell Command Injection Through Unsanitized Search Keyword
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 84–90
Vulnerability Type: Shell command injection caused by unsafe interpolation of user-derived input
Risk Level: HighVulnerable Code
markdown Trigger: "find connections for [note]", "what connects to [topic]", "link suggestions for [note]" 1. Read the target note 2. Extract key themes, names, entities 3. Search vault for related notes: ```bash grep -r "[keyword]" /home/node/.openclaw/workspace/Files/HumanVault/ --include="*.md" -l 2>/dev/null | head -20text ### Technical Analysis The skill instructs the agent to derive keywords from a user-selected note or topic and insert them into a shell command. The placeholder `[keyword]` appears inside a double-quoted shell argument, but the instructions do not require shell-safe argument handling, validation, or escaping. If an implementation performs direct textual substitution, a crafted keyword containing a double quote can terminate the intended argument. Shell metacharacters can then introduce an additional command. Merely surrounding interpolated input with double quotes is insufficient when the input itself may contain quote characters and is used to construct shell source. The vulnerability depends on the agent or runtime implementing the documented placeholder through direct shell-string interpolation. A process-execution API that passes the keyword as a distinct argument would prevent this exploitation path. ### Attack Path 1. An attacker invokes the connection-finder workflow with a crafted note name, topic, or keyword. 2. The agent extracts or accepts attacker-controlled text as `[keyword]`. 3. The agent directly substitutes that value into the documented `grep -r "[keyword]" ...` command. 4. A quote in the supplied value terminates the intended `grep` argument. 5. Injected shell syntax causes an additional command to be parsed and executed. 6. The injected command runs w ...[truncated 1192 chars]- Remediation
View remediation
Remediation Suggestions
-
Do not build shell source by interpolating user-controlled or model-derived text.
-
Use a process-execution API that accepts the executable and arguments separately, passing the keyword as one literal argument to
grep. -
Use fixed-string matching with
grep -Fwhen regular-expression behavior is unnecessary. -
Add
--before the keyword so values beginning with a hyphen cannot be interpreted as options. -
If a shell wrapper is unavoidable, pass the keyword as a positional parameter rather than embedding it in the command text:
bash sh -c 'grep -r -F -l --include="*.md" -- "$1" /home/node/.openclaw/workspace/Files/HumanVault/ 2>/dev/null | head -20' sh "$keyword" -
Validate the target path against the expected HumanVault root and reject attempts to select files outside that directory.
-
Update the skill instructions to explicitly prohibit direct substitution into shell commands and require structured argument passing for every user-derived value.
-
Run the skill under a least-privileged account with read-only HumanVault access for review and connection-finder operations.
-
