T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/fix.py:2- Finding
Auxiliary scripts overwrite an installed Skill outside the project directory
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fix.py:2-13;scripts/patch.py:5-28
Vulnerability Type: Arbitrary modification of an installed OpenClaw Skill
Risk Level: MediumVulnerable Code
scripts/fix.py:2-3,12-13:python with open('C:/Users/Administrator/.openclaw/workspace/skills/edge-tts-zh/scripts/speak.py', 'r', encoding='utf-8') as f: lines = f.readlines() with open('C:/Users/Administrator/.openclaw/workspace/skills/edge-tts-zh/scripts/speak.py', 'w', encoding='utf-8') as f: f.writelines(lines)scripts/patch.py:5-6,24-28:python with open('C:/Users/Administrator/.openclaw/workspace/skills/edge-tts-zh/scripts/speak.py', 'r', encoding='utf-8') as f: content = f.read() content = content.replace(old_code, new_code) with open('C:/Users/Administrator/.openclaw/workspace/skills/edge-tts-zh/scripts/speak.py', 'w', encoding='utf-8') as f: f.write(content)Technical Analysis
Both scripts use an absolute path to read and overwrite a separate installed copy of
speak.pyin the OpenClaw workspace. The target is not resolved relative to the current package, and the operation does not request confirmation, validate the target, create a backup, or use an atomic replacement.This crosses the expected boundary of a text-to-speech Skill. Running either development helper can alter executable code used by future invocations of the installed Skill. The operation executes with the current process's filesystem privileges; it does not independently elevate operating-system privileges.
Attack Path
- The user or Agent invokes
scripts/fix.pyorscripts/patch.py. - The script accesses the hardcoded installed-Skill location under the Administrator profile.
- It modifies the installed
speak.pyrather than a file scoped to the current project. - Future calls to the installed Skill execute the modified implementation.
- If the replacement is in ...[truncated 499 chars]
- The user or Agent invokes
- Remediation
View remediation
Remediation Suggestions
- Remove
fix.pyandpatch.pyfrom the distributed package if they are development-only utilities. - Resolve modification targets relative to the current package rather than using an absolute user-profile path.
- If external modification is necessary, require an explicit target argument and interactive confirmation.
- Canonicalize the target with
Path.resolve()and enforce that it is within an approved directory. - Create a backup and use an atomic temporary-file replacement.
- Verify that the expected source content is present and abort if the installed version is not compatible.
- Document every file that the utility may modify.
- Remove
