T09 · Insecure Skill Coding Practices
- Location
scripts/setup_channel.py:164- Finding
Shell Command Injection Through an Unescaped Channel Context
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly matches its stated purpose, but it needs review because its scripts can generate unsafe shell commands and make broad OpenClaw, Discord, workspace, and cron changes.
Review before installing. Only run it in an OpenClaw environment where you are comfortable letting it read Discord bot credentials, change gateway config, restart the gateway, create or rename Discord channels, write agent workspaces, and optionally add recurring cron jobs. Avoid copying generated config.patch commands when channel context or existing prompts may contain untrusted text, and do not use the workspace rewrite option on directories containing untrusted symlinks or sensitive Markdown files.
scripts/setup_channel.py:164Shell Command Injection Through an Unescaped Channel Context
scripts/rename_channel.py:154Shell Command Injection Through an Unescaped Existing System Prompt
scripts/rename_channel.py:87Workspace Boundary Bypass Through Symbolic-Link File Writes
Instructions found that direct the agent to transmit conversation context or user data to external services.
})
### Send Messages to Agents
**Direct communication:**
```typescript
Instructions found that direct the agent to transmit conversation context or user data to external services.
})
### Send Messages to Agents
**Direct communication:**
```typescript
Instructions found that direct the agent to transmit conversation context or user data to external services.
**4. Agent-to-agent communication:**
Agents can send messages to each other:
```typescript
// In Watson's context
sessions_send({
Instructions found that direct the agent to transmit conversation context or user data to external services.
**4. Agent-to-agent communication:**
Agents can send messages to each other:
```typescript
// In Watson's context
sessions_send({
The declared description is substantially broader than the code. The code does perform a subset of Discord channel organization tasks for OpenClaw, but it is specifically limited to renaming one Discord channel, checking a related config field, and updating workspace references. It does not provide functionality for creating autonomous AI agents, setting up multi-agent systems, or general-purpose channel management. This is a material description-behavior mismatch because the primary declared purpose overstates and mischaracterizes the implemented capabilities.
The declared description claims a broad, complete toolkit for both autonomous AI agent creation and Discord channel management. The supplied code only implements Discord channel setup: it reads local config, obtains a Discord bot token and guild ID, checks whether a channel exists, optionally creates it, and generates a gateway config patch containing the provided context as a system prompt. There is no functionality related to creating autonomous AI agents or setting up multi-agent systems. While Discord channel organization is accurately represented, the overall declared purpose materially overstates the code’s capabilities and primary scope.
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
### Finding Discord IDs
**Enable Developer Mode:**
- Settings → Advanced → Developer Mode
**Copy IDs:**
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
### Finding Discord IDs
**Enable Developer Mode:**
- Settings → Advanced → Developer Mode
**Copy IDs:**
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
1. **Organize channels in categories** - Group related agent channels
2. **Use descriptive channel names** - Clear purpose from the name
3. **Set specific system prompts** - Give each channel clear context
4. **Document agent responsibilities** - Keep SOUL.md updated
5. **Set up memory cron jobs** - For agents with ongoing work
6. **Test agents individually** - Before integrating into team
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
try:
prompt = config['channels']['discord']['guilds'][guild_id]['channels'][channel_id].get('systemPrompt', '')
if old_name in prompt:
return prompt
except (KeyError, TypeError):
pass
return None
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- Optional cron job setup
**Discord Channel Management:**
- Create Discord channels via API
- Configure OpenClaw gateway allowlists
- Set channel-specific system prompts
- Rename channels and update references
The README explicitly promotes a 'Health tracking agent' and 'wellness monitoring' but provides no warning about handling sensitive personal or health data, retention, access controls, or regulatory/privacy considerations. In a multi-agent system with Discord bindings and memory logs, this omission can lead users to store or transmit sensitive health information in insecure channels or files.
The skill advertises and instructs use of capabilities that modify files, read environment/configuration, and perform network/API actions, but it declares no explicit tool scope or permission boundaries. In a skill that can patch gateway config, restart services, and call Discord APIs, missing scope disclosure increases the chance of over-privileged execution and unsafe invocation by users or agents.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- **Emoji** (e.g., "🔬")
- **Specialty** (what the agent does)
- **Model** (which LLM to use)
- **Workspace** (where to create agent files)
- **Discord channel ID** (optional)
#### 2. Run Creation Script
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- **Emoji** (e.g., "🔬")
- **Specialty** (what the agent does)
- **Model** (which LLM to use)
- **Workspace** (where to create agent files)
- **Discord channel ID** (optional)
#### 2. Run Creation Script
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- **Emoji** (e.g., "🔬")
- **Specialty** (what the agent does)
- **Model** (which LLM to use)
- **Workspace** (where to create agent files)
- **Discord channel ID** (optional)
#### 2. Run Creation Script
The skill describes automation that creates files, updates gateway configuration, and restarts the gateway, but it does not present a prominent warning about those side effects before operational steps. This omission can cause users or calling agents to trigger disruptive or persistent system changes without informed consent or pre-change review.
The Discord setup and rename workflows perform live API changes and may update workspace files, but the documentation does not foreground these effects as operationally risky actions. That creates a real risk of unintended production changes, data churn, or confusing file rewrites when used by an autonomous agent or inattentive operator.
The script offers to create a recurring cron job that will automatically write to files under the agent workspace on an ongoing basis. Although it prompts once at setup time, it does not clearly communicate the persistence, frequency, and continued autonomous modification behavior as a security-relevant side effect, which can lead to unexpected file changes, data growth, or abuse if the agent/session later behaves unexpectedly.
This creates session persistence by registering an automated recurring task tied to the agent session, allowing the agent to keep acting and writing state over time without further per-run approval. In the context of an agent-management skill, persistence is expected functionality, but it still expands the attack surface because a compromised or misconfigured agent can continue operating, storing data, or consuming resources indefinitely.
echo -e "${YELLOW}📅 Memory System${NC}"
echo ""
echo "Would you like to set up a daily memory cron job for $NAME?"
echo "This will create a job that reviews and updates the agent's daily memory file."
echo ""
read -p "Create daily memory cron? (y/n): " -n 1 -r
echo ""
This code searches all markdown files under the provided workspace and writes changes back to disk automatically when matches are found. Although progress is printed, there is no confirmation prompt or explicit disclosure in the script's top-level usage/docstring that running with --workspace will perform in-place edits across files.
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
## Requirements
**Bot Permissions:**
- `Manage Channels` - To create/rename channels
- `View Channels` - To read channel list
- `Send Messages` - To post in channels
No suspicious patterns detected.