T05 · Unauthorized Access and Privilege Escalation
- Location
HOOK.md:8- Finding
Unnecessary Scheduled-Task Permission Violates Least Privilege
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a node troubleshooting tool, but it asks for an unused persistence-capable cron permission and documents confirmation-free repair mode for system-changing fixes.
Review before installing. The core diagnostic behavior is coherent, but remove or question the system:cron permission unless scheduled checks are explicitly needed, and avoid using any silent repair mode until the skill clearly previews changes, supports rollback or backup guidance, and confirms before token resets or gateway restarts.
HOOK.md:8Unnecessary Scheduled-Task Permission Violates Least Privilege
scripts/utils.js:13Diagnostic Report Generator Inserts Unescaped Data into HTML
${escapeMarkdown(r.output)}${escapeMarkdown(r.details)}This markdown file is written entirely in Chinese, including the final instruction to the user, with no indication that other languages are supported or that Chinese is required for a region-specific purpose. That creates a natural-language locale policy concern because it implicitly constrains user interaction to one language without opt-in.
This markdown file uses a single language throughout and does not indicate that Chinese is optional, user-selected, or required for a justified regional context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.
The skill description is written in Chinese and presents the behavior and marketing copy in a single language, with no indication that users can choose another language or that the skill is intended only for a Chinese-speaking region. This can violate language/locale policy when a skill imposes a specific language without user opt-in.
The silent mode enables auto_confirm=true and states that no confirmation prompt is shown before executing repairs. Given the skill's described ability to reset tokens, restart gateways, and restore defaults under admin/root permissions, this meaningfully increases the chance of unintended or automated disruptive changes without human validation.
openclaw skill run node-connection-doctor --input '{"mode": "fix", "auto_confirm": true}'
注意: 不显示确认提示,直接执行。适合自动化脚本。
The README advertises a silent repair mode that executes fixes immediately with administrator/root privileges and explicitly states it will not show a confirmation prompt. In the context of a tool that can reset tokens, rebind nodes, restart services, and restore default configs, this creates a real risk of unintended destructive configuration changes without adequate warning about rollback, backups, or side effects.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
|---------|---------|
| 🔍 **Auto Diagnosis** | Checks 20+ common issues (gateway status, pairing config, Tailscale, firewall) |
| 📋 **Fix Recommendations** | Provides exact CLI commands for your specific error |
| ⚡ **One-Click Fix** | (Optional) Automatically executes safe fixes (reset token, restart gateway) |
| 📊 **Diagnostic Report** | Exportable summary for support or future reference |
---
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
|---------|---------|
| 🔍 **Auto Diagnosis** | Checks 20+ common issues (gateway status, pairing config, Tailscale, firewall) |
| 📋 **Fix Recommendations** | Provides exact CLI commands for your specific error |
| ⚡ **One-Click Fix** | (Optional) Automatically executes safe fixes (reset token, restart gateway) |
| 📊 **Diagnostic Report** | Exportable summary for support or future reference |
---
The skill advertises system-changing repair actions such as resetting pairing tokens, rebinding the gateway, and restarting services, but the description does not clearly foreground the operational and security consequences of those actions. In a troubleshooting skill for node connectivity, such actions can disrupt service, invalidate existing trust relationships, or cause unintended configuration changes if users do not understand what will be modified.
This markdown file presents the FAQ content in Chinese beginning at the main section heading, and the rest of the user-facing guidance continues in that language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly justified.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
mode: process.argv[2] || 'diagnose', // diagnose | fix
verbose: true,
dry_run: process.argv.includes('--dry-run'),
auto_confirm: false
};
// 直接运行诊断逻辑 (简化版,供截图用)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
mode: process.argv[2] || 'diagnose', // diagnose | fix
verbose: true,
dry_run: process.argv.includes('--dry-run'),
auto_confirm: false
};
// 直接运行诊断逻辑 (简化版,供截图用)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
mode: process.argv[2] || 'diagnose', // diagnose | fix
verbose: true,
dry_run: process.argv.includes('--dry-run'),
auto_confirm: false
};
// 直接运行诊断逻辑 (简化版,供截图用)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
mode: process.argv[2] || 'diagnose', // diagnose | fix
verbose: true,
dry_run: process.argv.includes('--dry-run'),
auto_confirm: false
};
// 直接运行诊断逻辑 (简化版,供截图用)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
mode: process.argv[2] || 'diagnose', // diagnose | fix
verbose: true,
dry_run: process.argv.includes('--dry-run'),
auto_confirm: false
};
// 直接运行诊断逻辑 (简化版,供截图用)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
mode: process.argv[2] || 'diagnose', // diagnose | fix
verbose: true,
dry_run: process.argv.includes('--dry-run'),
auto_confirm: false
};
// 直接运行诊断逻辑 (简化版,供截图用)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
mode: process.argv[2] || 'diagnose', // diagnose | fix
verbose: true,
dry_run: process.argv.includes('--dry-run'),
auto_confirm: false
};
// 直接运行诊断逻辑 (简化版,供截图用)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
mode: process.argv[2] || 'diagnose', // diagnose | fix
verbose: true,
dry_run: process.argv.includes('--dry-run'),
auto_confirm: false
};
// 直接运行诊断逻辑 (简化版,供截图用)
The description 'Automatically diagnose and fix OpenClaw node connection issues' is broad and does not define clear trigger conditions, operational boundaries, or limits on what 'fix' actions may be taken. In a troubleshooting skill that may execute repair actions, vague activation and scope increase the risk of unintended invocation or user misunderstanding about potentially system-affecting behavior.
The manifest sells a 'Full Repair Service' with 'automatic fix execution' but does not include an explicit warning that the skill may modify system or network configuration. In the context of node connectivity, automated fixes could alter gateways, networking, or Tailscale-related settings, making the absence of prominent warning and guardrails materially risky.
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
price: 50
name: Enterprise API
period: monthly
description: Unlimited API access for businesses
documentation: SKILL.md
scripts:
- scripts/diagnose.js
This HTML file presents the skill publishing helper with Chinese-only UI text such as "发布表单" and later Chinese instructions, while the embedded skill content itself is largely English. Because there is no opt-in or documented locale constraint, the file effectively imposes a specific language/locale on users, which matches the language-policy violation criteria.
This markdown file is primarily written in Chinese but includes substantial English interface text and testing language such as output labels and the support note. There is no statement that the skill or guide supports multiple languages or that English is required, so it appears to impose mixed-language usage without explicit user opt-in.
The script's title, status messages, errors, and recommendations are all presented in Chinese, including user-facing console output. This imposes a specific language/locale on all users without any opt-in or documented regional justification, which matches the language-policy concern for natural-language content.
The file includes user-facing natural-language descriptions and comments in Chinese (for example the title and operation descriptions) while other interaction text is in English. Because the skill does not offer a language/locale selection or document that it is intended for a specific locale, this may violate language-choice policy expectations.
The file contains user-facing strings in both Chinese and English, including the title and status messages, but provides no indication that language selection is optional or region-specific. This can violate language/locale policy expectations when a skill imposes or assumes a language without user opt-in.
Detected: suspicious.dangerous_exec