T09 · Insecure Skill Coding Practices
- Location
SKILL.md:46- Finding
Allowlist-Only File Copying Can Publish Secrets or Malicious Scripts
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:46-61,SKILL.md:114-118, andreferences/text-file-extensions.txt:12-13
Vulnerability Type: Inadequate content validation before copying and publication
Risk Level: HighRelevant code segment from
SKILL.md:46-61(English translation):text Step 1: Read the source Skill → Read SKILL.md and all child files under the WorkBuddy Skill directory → Identify frontmatter fields, document structure, and references/scripts/assets content Step 2: Format conversion → Perform frontmatter field mapping → Perform body adaptation → Copy valid files to the OpenClaw directory Step 3: Compliance validation → Execute all validation rules → Output the validation report → Automatically fix issues or notify the user Step 4: Publish to ClawHub → Confirm login status → Execute clawhub publishRelevant code segment from
SKILL.md:114-118(English translation):text 1. references/*.md → Copy directly 2. references/*.yaml / *.yml → Copy directly 3. references/*.html → Copy directly 4. references/*.json → Copy directly 5. scripts/*.py / *.js / *.bat → Copy directly as text filesRelevant code segment from
references/text-file-extensions.txt:12-13:text Data/configuration: .json, .yaml, .yml, .toml, .xml, .csv, .tsv, .ini, .cfg, .conf, .env, .propertiesTechnical Analysis
The conversion workflow uses an extension allowlist as its principal security boundary. It directly copies executable script formats such as Python, JavaScript, and batch files, as well as potentially sensitive configuration formats such as
.env, JSON, YAML, and INI.A text-file extension only indicates the file representation; it does not establish that the content is safe. An allowlisted file can contain:
- API keys, access tokens, passwords, or private endpoints.
- Destructive or covert script behavior.
...[truncated 2262 chars]
- Remediation
View remediation
Remediation Suggestions
- Deny
.env, credential files, private keys, token caches, and local configuration files by default, regardless of whether their extensions are text-based. - Scan every copied file for secrets using entropy checks, known credential patterns, and provider-specific token detectors.
- Perform static behavioral analysis of executable scripts before copying or publication. Flag process execution, network downloads, persistence mechanisms, destructive filesystem operations, credential access, and obfuscated content.
- Resolve and validate every source path before copying. Reject symbolic links, hard links to files outside the source directory, path traversal, and special device files.
- Generate a complete manifest containing file paths, hashes, sizes, and detected risks.
- Require explicit user approval of the manifest and script changes before publication.
- Separate format validation from security validation. Passing the extension allowlist must never imply that file content is trusted.
- Publish from a newly created staging directory containing only reviewed files rather than recursively copying the source tree.
- Run conversion and analysis in a restricted sandbox without access to unrelated credentials or sensitive host files.
- Abort publication when secret scanning or behavioral analysis produces unresolved findings.
- Deny
