T09 · Insecure Skill Coding Practices
- Location
skills/safe-edit/safe-edit.sh:181- Finding
PowerShell Code Injection Through Unescaped Windows File Paths
- Content
View full analysis
"$rollback_ps1" << ROLLBACK_EOF # Auto-generated rollback script \$target = "$win_target" \$backup = "$win_backup" if (Test-Path \$backup) { Copy-Item \$backup \$target -Force Write-Host "Rolled back: \$target" } ROLLBACK_EOF if command -v schtasks &> /dev/null; then local task_name="OpenClaw_Rollback_$$" schtasks /create /tn "$task_name" /tr "powershell -ExecutionPolicy Bypass -File '$rollback_ps1'" /sc once /st $(date -d "+15 minutes" +%H:%M) /f 2>/dev/null ``` ### Technical Analysis The target file path originates from the command-line argument supplied to `safe-edit start`. On Windows, the path is converted with `cygpath` when available and then inserted directly into PowerShell source code inside a double-quoted string. No PowerShell escaping is applied before interpolation. A valid path containing a quotation mark, newline, backtick, dollar expression, or other PowerShell syntax can terminate or alter the generated assignment and inject additional commands. The generated script is subsequently registered as a scheduled task and invoked with `ExecutionPolicy Bypass`. Shell quoting around the here-document destination does not protect the contents of the generated PowerShell script. ### Attack Path 1. An attacker creates or causes the operator to select an existing file whose path contains PowerShell metacharacters or embedded script syntax. 2. The operator or agent invokes `safe-edit start` with that path. 3. The script interpolates the path into `rollback.ps1` without PowerShell escaping. 4. `schtasks` registers the generated script for execution after 15 minutes. 5. The scheduled task runs the injected PowerShell commands under the security context us ...[truncated 449 chars]- Remediation
View remediation
