Back to skill

Security audit

Safe Edit

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent safety goal, but it also makes high-impact system changes and schedules unreviewed rollback code without enough scoping or disclosure.

Review this skill carefully before installing. It may be useful for protecting risky config edits, but it should not be used on production or privileged systems unless the rollback script is packaged and verified, package installation is made explicit, scheduler state is scoped per operation, and high-risk file targets require clear user confirmation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
skills/safe-edit/safe-edit.sh:181
Finding

PowerShell Code Injection Through Unescaped Windows File Paths

Content
View full analysis
"$rollback_ps1" << ROLLBACK_EOF # Auto-generated rollback script \$target = "$win_target" \$backup = "$win_backup" if (Test-Path \$backup) { Copy-Item \$backup \$target -Force Write-Host "Rolled back: \$target" } ROLLBACK_EOF if command -v schtasks &> /dev/null; then local task_name="OpenClaw_Rollback_$$" schtasks /create /tn "$task_name" /tr "powershell -ExecutionPolicy Bypass -File '$rollback_ps1'" /sc once /st $(date -d "+15 minutes" +%H:%M) /f 2>/dev/null ``` ### Technical Analysis The target file path originates from the command-line argument supplied to `safe-edit start`. On Windows, the path is converted with `cygpath` when available and then inserted directly into PowerShell source code inside a double-quoted string. No PowerShell escaping is applied before interpolation. A valid path containing a quotation mark, newline, backtick, dollar expression, or other PowerShell syntax can terminate or alter the generated assignment and inject additional commands. The generated script is subsequently registered as a scheduled task and invoked with `ExecutionPolicy Bypass`. Shell quoting around the here-document destination does not protect the contents of the generated PowerShell script. ### Attack Path 1. An attacker creates or causes the operator to select an existing file whose path contains PowerShell metacharacters or embedded script syntax. 2. The operator or agent invokes `safe-edit start` with that path. 3. The script interpolates the path into `rollback.ps1` without PowerShell escaping. 4. `schtasks` registers the generated script for execution after 15 minutes. 5. The scheduled task runs the injected PowerShell commands under the security context us ...[truncated 449 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
skills/safe-edit/safe-edit.sh:12
Finding

Scheduled Execution of an Unpackaged and Unverified Rollback Script

Content
View full analysis
/dev/null ``` ### Technical Analysis The Linux, WSL, FreeBSD, and some macOS rollback paths schedule `/root/.openclaw/scripts/rollback.sh`. That file is not present in the audited package. The Skill neither creates it nor validates its existence, ownership, permissions, integrity, or contents before passing it to `at`. The scheduled command also receives no explicit target or backup path. Consequently, the reviewed implementation does not establish that the external script will restore the file selected by the current operation. This creates a local tool-hijacking boundary: a legitimate-looking Skill invocation delegates delayed execution to mutable code outside the reviewed package. ### Attack Path 1. A malicious or compromised local component places or modifies `/root/.openclaw/scripts/rollback.sh`. 2. A privileged user or agent invokes `safe-edit start` for a configuration file. 3. The Skill submits the external file to `at` without verifying its identity or contents. 4. Fifteen minutes later, `at` executes the substituted script under the submitting account. 5. The substituted script performs attacker-selected actions. The same defect can also cause a non-adversarial rollback failure when the external file is absent or incompatible. ### Impact Assessment The external script executes with the privileges of the account that submitted the `at` job. In the intended root-oriented deployment, compromise of the external script can lead to arbitrary root-level command execution and complete host compromise. Even withou ...[truncated 115 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/safe-edit/safe-edit.sh:103
Finding

Global Rollback State Permits Cross-Operation Job Confusion

Content
View full analysis
/dev/null at_job_id=$(atq | tail -1 | awk '{print $1}') if [ -n "$at_job_id" ]; then log "Linux at rollback task configured: job_id=$at_job_id, scheduled in 15 minutes" echo "$at_job_id" > "$BACKUP_DIR/.at_job_id" ``` ```bash if [ -f "$BACKUP_DIR/.at_job_id" ]; then local job_id job_id=$(cat "$BACKUP_DIR/.at_job_id") atrm "$job_id" 2>/dev/null || true rm -f "$BACKUP_DIR/.at_job_id" fi if [ -f "$BACKUP_DIR/.rollback_pid" ]; then local pid pid=$(cat "$BACKUP_DIR/.rollback_pid") kill "$pid" 2>/dev/null || true rm -f "$BACKUP_DIR/.rollback_pid" fi if [ -f "$BACKUP_DIR/.windows_task" ]; then local task_name task_name=$(cat "$BACKUP_DIR/.windows_task") schtasks /delete /tn "$task_name" /f 2>/dev/null || true rm -f "$BACKUP_DIR/.windows_task" fi ``` ```bash cp "$target_file" "$backup_file" echo "$backup_file" > "$BACKUP_DIR/.last_backup" ``` ### Technical Analysis All operations share fixed files such as `.at_job_id`, `.rollback_pid`, `.windows_task`, and `.last_backup`. A second `start` invocation overwrites the state of the first operation. A subsequent `confirm` or `cancel` therefore acts only on whichever identifiers were written most recently. The `at` job identifier is obtained using `atq | tail -1`, rather than from the submission result. This is not a reliable association in the presence of existing or concurrent jobs and can capture a different job. The background-process cancellation path trusts a stored PID without verifying process start time or command identity. If a process exits and its PID is reused, a later cancellation can signal an unrelated process. ### Attack Path 1. Two edits are started c ...[truncated 787 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
skills/safe-edit/safe-edit.sh:89
Finding

Automatic Privileged Package Installation Exceeds Declared Permissions

Content
View full analysis
/dev/null; then warn "The at command is unavailable; attempting installation..." if command -v apt-get &> /dev/null; then apt-get install -y at elif command -v yum &> /dev/null; then yum install -y at else error "Unable to install the at command" return 1 fi fi ``` The Skill manifests declare an empty permission list: ```yaml metadata: {"openclaw":{"emoji":"🛡️","requires":{},"permissions":[]}} ``` ### Technical Analysis Invoking the backup workflow can silently call a system package manager with automatic confirmation. Installing operating-system software is broader than the minimum behavior necessary to back up a file or report that a prerequisite is unavailable. The installation requires elevated privileges and may contact configured package repositories. These effects are not represented by the empty permission declaration, and the user is not asked for explicit authorization before the system is modified. This finding does not indicate dependency confusion or a known malicious package. The security issue is the undeclared and unnecessary privileged side effect. ### Attack Path 1. The Skill runs on a Linux host where `at` is unavailable. 2. A user or agent invokes `safe-edit start`. 3. The script automatically executes `apt-get install -y at` or `yum install -y at`. 4. The package manager modifies the host and retrieves packages using its configured repositories without an explicit approval step. ### Impact Assessment The command can install packages and associated services, scripts, users, files, or configuration with administrative privileges. The immediate scope is the operating system package database and any actions performed by package maintainer scripts. ...[truncated 132 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/safe-edit/safe-edit.sh:219
Finding

Documented Immediate Rollback Command Only Cancels Recovery

Content
View full analysis
/dev/null || true rm -f "$BACKUP_DIR/.at_job_id" fi if [ -f "$BACKUP_DIR/.rollback_pid" ]; then local pid pid=$(cat "$BACKUP_DIR/.rollback_pid") kill "$pid" 2>/dev/null || true rm -f "$BACKUP_DIR/.rollback_pid" fi if [ -f "$BACKUP_DIR/.windows_task" ]; then local task_name task_name=$(cat "$BACKUP_DIR/.windows_task") schtasks /delete /tn "$task_name" /f 2>/dev/null || true rm -f "$BACKUP_DIR/.windows_task" fi success "Rollback task canceled" } ``` ```bash cancel) cancel_rollback "$os_type" ;; ``` ### Technical Analysis The Skill documentation presents the cancellation workflow as an option to use after discovering an incorrect edit and describes it as an immediate rollback. The implementation does not copy the backup over the target file. It only removes the delayed recovery job or terminates the sleeping rollback process. As a result, invoking the documented recovery action when a configuration is already broken removes the only automatic restoration mechanism while leaving the broken configuration in place. ### Attack Path 1. A user starts a protected edit and modifies a critical configuration incorrectly. 2. The user follows the documented cancellation or immediate-rollback workflow. 3. The script deletes the scheduled task or terminates the background rollback process. 4. No backup is restored. 5. The invalid configuration remains ...[truncated 477 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims to provide safe configuration editing with rollback, but the documented behavior also implies privileged side effects beyond that scope: installing packages, writing under fixed /root paths, invoking an external rollback script whose behavior is not described, and creating scheduled tasks on Windows. This mismatch is dangerous because users and orchestrators may grant trust based on the declared purpose while the skill can persist changes or execute additional privileged actions that were never transparently disclosed.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest declares no permissions, yet the skill instructs the agent to modify arbitrary local configuration files, invoke a local script, and schedule rollback tasks. This creates a dangerous mismatch between declared capability and actual expected behavior, undermining permission-based review and enabling high-impact file or task changes without transparent authorization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script installs system packages (apt-get install -y at / yum install -y at) as part of a helper whose stated purpose is only to back up files and schedule rollback. This expands its privilege and system-modification scope unexpectedly, can alter package state on production hosts, and may execute with root privileges in exactly the environments where configuration-edit helpers are used.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/safe-edit/safe-edit.sh (reported line 227)May include surrounding context.

sh
local job_id
        job_id=$(cat "$BACKUP_DIR/.at_job_id")
        atrm "$job_id" 2>/dev/null || true
        rm -f "$BACKUP_DIR/.at_job_id"
        log "已取消 at 回滚任务: $job_id"
    fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/safe-edit/safe-edit.sh (reported line 236)May include surrounding context.

sh
local pid
        pid=$(cat "$BACKUP_DIR/.rollback_pid")
        kill "$pid" 2>/dev/null || true
        rm -f "$BACKUP_DIR/.rollback_pid"
        log "已终止回滚进程: $pid"
    fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The script reads a task name from $BACKUP_DIR/.windows_task and passes it directly to schtasks /delete /tn "$task_name" /f. If an attacker can modify that state file, the script may delete an arbitrary scheduled task when run with the user's or administrator's privileges, which is especially relevant because this helper operates in privileged configuration-management contexts.

Content

Scanner excerpt · skills/safe-edit/safe-edit.sh (reported line 244)May include surrounding context.

sh
if [ -f "$BACKUP_DIR/.windows_task" ]; then
        local task_name
        task_name=$(cat "$BACKUP_DIR/.windows_task")
        schtasks /delete /tn "$task_name" /f 2>/dev/null || true
        rm -f "$BACKUP_DIR/.windows_task"
        log "已删除 Windows 计划任务: $task_name"
    fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills/safe-edit/safe-edit.sh (reported line 245)May include surrounding context.

sh
local task_name
        task_name=$(cat "$BACKUP_DIR/.windows_task")
        schtasks /delete /tn "$task_name" /f 2>/dev/null || true
        rm -f "$BACKUP_DIR/.windows_task"
        log "已删除 Windows 计划任务: $task_name"
    fi

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to activate on many ordinary configuration-editing requests, which can cause the agent to invoke privileged backup, scheduling, or rollback behavior unexpectedly. In a skill that may touch system config, root-owned paths, and scheduled tasks, overbroad activation increases the chance of unintended execution and expands the attack surface for prompt-trigger abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing instructions, trigger phrases, and example dialogues are written only in Chinese and assume Chinese-language commands such as "safe-edit 确认成功". This can violate language/locale policy when the skill is applied generally, because it forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are very broad and match common requests such as modifying configuration or cron jobs, causing the skill to activate in many contexts without sufficient scoping. In a skill that leads to file modification and task scheduling, over-broad triggering increases the chance of unintended invocation and risky automation on sensitive system files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage string says users can simply say '使用 safe-edit' before modifying configuration files, which is a broad activation phrase with no stated scope limits, confirmation requirements, or exclusions for sensitive targets. In an agent environment, overly generic invocation can cause the skill to activate in unintended contexts and perform backup/rollback automation around privileged or critical files without sufficient user intent validation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comments, warnings, help output, and user-facing status messages are written in Chinese throughout the script, including the usage text shown to end users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which this file does not do.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The header/help text says the skill supports Windows, including Git Bash/WSL, but the schtasks path computes the start time with 'date -d', which is not generally available in native Windows command environments and is inconsistent with the stated platform support. This is an intent/documentation contradiction rather than a mere omission because the code advertises support for a platform path it may not actually handle.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content and usage instructions are provided in Chinese, and the file does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file describes behavior that automatically backs up and later restores important configuration files, which can affect system integrity and user data. While the feature is framed as safety-oriented, the description does not explicitly warn users that the skill will write backup files and perform automatic file restoration on their system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's user-facing instructions and examples are entirely in Chinese, including command guidance and confirmation phrasing, with no indication that users may choose another language. This creates a language/locale policy concern because the skill effectively forces one language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package description is written only in Chinese and presents the skill in a single language without any indication that users can choose their preferred language. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The display name, description, requirements note, and usage instructions are presented in Chinese, with no indication that users can choose another language or that the skill is intentionally restricted to a Chinese-speaking locale. That can conflict with a language/locale policy requiring user opt-in or documented regional scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.