T09 · Insecure Skill Coding Practices
- Location
SKILL.md:260- Finding
Shell Command Injection Through Conversation-Controlled Task Parameters
- Content
View full analysis
" --cron "" --agent-turn "" ``` ```bash # Write the prompt to a file first cat > /tmp/task_prompt.txt << 'PROMPT_EOF' {完整 prompt 内容} PROMPT_EOF # Then create the task openclaw cron add --name "销售业绩周报" --cron "0 9 * * 1" --agent-turn "$(cat /tmp/task_prompt.txt)" ``` ### Technical Analysis The Skill directs the Agent to interpolate a task name, cron expression, and generated prompt into shell source. These values are derived wholly or partly from conversation-controlled content. The instructions do not require strict validation, shell-safe encoding, or execution through an argument-array API. If the Agent generates the displayed command by substituting values directly into its text, embedded quotation marks, heredoc terminators, newlines, or shell operators may alter the intended command structure. The heredoc approach remains susceptible to generated content containing a line exactly equal to `PROMPT_EOF`, which terminates the heredoc early. Subsequent attacker-controlled lines can then be interpreted as shell commands. The warning elsewhere in the Skill that prompts may contain special characters does not provide a reliable security control. Moving content into a heredoc only changes the injection boundary; it does not make arbitrary generated content safe when a fixed delimiter is used. ### Attack Path 1. An attacker supplies analysis text, a report name, or another parameter containing shell syntax. 2. The Skill records that content and incorporates it into the scheduled-task configuration or prompt. 3. The Agent emits and executes the documented shell command. 4. The malicious value breaks out of its quoted argument, or a line matching `PROMPT_EOF` closes the heredoc. 5. Remaining attacker-controlled text is parsed by the shel ...[truncated 991 chars]- Remediation
View remediation
