T09 · Insecure Skill Coding Practices
- Location
SKILL.md:29- Finding
Unvalidated Agent ID Enables Shell Injection and Path Traversal
- Content
View full analysis
", "name": "", "workspace": "/home/xgao/clawd-workspace/" } ``` ```bash mkdir -p /home/xgao/clawd-workspace/ ``` ### Technical Analysis The Skill instructs the agent to collect an attacker-controlled `agent_id` and insert it directly into both a filesystem path and a shell command. It does not require validation, canonicalization, or shell-safe argument handling. If the agent performs literal textual substitution, shell metacharacters in the supplied identifier may terminate or alter the intended `mkdir` command and cause additional commands to run. An identifier containing path separators or traversal components such as `../` may also resolve outside `/home/xgao/clawd-workspace`, resulting in unauthorized directory creation or an unintended workspace path being written into the OpenClaw configuration. The vulnerability is especially significant because an AI agent may treat the documented command as an executable template. The exploitability of shell injection depends on the agent substituting the value into a shell command without safe argument separation, while the path-traversal risk also applies to direct filesystem operations that do not verify the resolved path. ### Attack Path 1. An attacker asks the Skill to create a Telegram agent. 2. The attacker supplies an `agent_id` containing shell control characters, path separators, or traversal sequences. 3. The agent inserts that value into `/home/xgao/clawd-workspace/` as instructed. 4. If the shell template is executed literally, the injected shell syntax alters the command and executes an attacker-selected command with the agent process's privileges. 5. Alternatively, traversal components cause the resolved directory ...[truncated 832 chars]- Remediation
View remediation
