T09 · Insecure Skill Coding Practices
- Location
SKILL.md:94- Finding
Unsafe interpolation of skill names into destructive shell commands
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 94–102
Vulnerability Type: Command injection and unsafe path construction
Risk Level: HighVulnerable Code:
bash ### 5. Optional: Auto-remove dangerous skills If the user confirms, execute removal for DANGEROUS-rated skills: ```bash # For each DANGEROUS skill named [skill-name]: clawhub uninstall [skill-name] 2>/dev/null rm -rf ~/.openclaw/workspace/skills/[skill-name]Technical Analysis
The removal instructions place a skill name obtained from installed-skill metadata directly into shell commands. They do not require shell-safe argument passing, quoting, identifier validation, path canonicalization, or an end-of-options marker.
If an installed skill can have an attacker-controlled name containing shell metacharacters, whitespace, option-like prefixes, or path traversal sequences, mechanical substitution of that name into the documented commands can change their meaning. The
rm -rfoperation is especially dangerous because traversal components could cause the resolved target to leave the intended skills directory.User confirmation does not eliminate this vulnerability: the user may approve removing a dangerous skill without recognizing that its displayed name changes the command or deletion target.
Attack Path
- An attacker causes a skill with a crafted name to be installed or otherwise represented in scanner output.
- The security audit classifies the skill as dangerous.
- The Agent follows the documented removal workflow and substitutes the discovered name for
[skill-name]. - The shell interprets injected metacharacters or option-like content, or
rmresolves traversal components outside the expected skill directory. - Commands execute or files are recursively removed with the privileges of the Agent process.
This path depends on the surrounding platform permitting crafted skill identifiers and on the ...[truncated 513 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer a structured uninstall API that accepts a skill identifier as a discrete argument and does not invoke a shell.
- Enforce a strict allowlist for skill identifiers, such as a narrowly defined set of letters, digits, hyphens, and underscores.
- Reject identifiers containing path separators, traversal components, control characters, whitespace, shell metacharacters, or leading option prefixes.
- Resolve the candidate deletion path canonically and verify that it is a direct child of the canonical skills directory before deletion.
- Pass command arguments as an argument array rather than constructing a shell command string.
- Use an end-of-options marker where supported.
- Avoid exposing raw
rm -rfcommands. Implement deletion through a bounded removal routine that refuses symlinks and out-of-root targets. - Display both the validated identifier and canonical target path when requesting confirmation.
