T09 · Insecure Skill Coding Practices
- Location
scripts/capture-windows-screen.sh:5- Finding
Unverified External PowerShell Helper Executed with Execution Policy Bypass
- Content
View full analysis
Vulnerability Details
File Location:
scripts/capture-windows-screen.sh, lines 5-17
Vulnerability Type: Execution of an external, integrity-unverified script with PowerShell policy bypass
Risk Level: HighVulnerable Code
bash WIN_SCRIPT='C:\OpenClaw\capture-screen.ps1' OUT_WIN='C:\OpenClaw\latest-screen.png' if [[ ! -x "$WIN_PS" ]]; then echo "PowerShell not found at: $WIN_PS" >&2 exit 1 fi "$WIN_PS" -NoProfile -ExecutionPolicy Bypass -File "$WIN_SCRIPT" -OutputPath "$OUT_WIN" >/dev/nullTechnical Analysis
The Skill invokes
C:\OpenClaw\capture-screen.ps1, a host-side script that is not included in the audited project. Consequently, its source code, ownership, permissions, and integrity cannot be verified from the Skill package.The invocation also uses
-ExecutionPolicy Bypass, disabling the applicable PowerShell execution-policy check for this process. Although execution policy is not a complete security boundary, bypassing it removes a defense that could otherwise prevent or warn about the execution of an untrusted helper.The script verifies only that the PowerShell executable exists and is executable. It does not verify that the external helper:
- Is owned by a trusted administrator or account.
- Is not writable by untrusted users.
- Has an expected cryptographic hash or trusted signature.
- Contains only the intended screenshot functionality.
Therefore, anyone capable of modifying or replacing the external helper can cause arbitrary PowerShell commands to run when the screenshot Skill is invoked.
Attack Path
- An attacker obtains write access to
C:\OpenClaw\capture-screen.ps1or replaces that file through another compromised process or account. - The attacker inserts arbitrary PowerShell commands into the helper, such as commands that read user data, execute programs, or establish network communication.
- A user or Agent invokes `scripts/capture-wi ...[truncated 992 chars]
- Remediation
View remediation
Remediation Suggestions
- Bundle the PowerShell helper inside the reviewed Skill package where possible, so its contents are included in security review and version control.
- Avoid
-ExecutionPolicy Bypass. Use an appropriately signed script and a restrictive execution policy compatible with the deployment environment. - Before execution, verify the helper against a pinned SHA-256 digest or a trusted Authenticode signature.
- Confirm that the helper and its parent directory are owned by a trusted account and are not writable by untrusted users.
- Fail closed if integrity or ownership validation cannot be completed.
- Run the helper under a dedicated least-privileged account with access only to the resources needed for screenshot capture.
- Log integrity-validation failures without exposing sensitive paths or desktop content to unauthorized recipients.
