T09 · Insecure Skill Coding Practices
- Location
dist/scanner.js:145- Finding
Runtime Build Directories Are Excluded from Security Scanning
- Content
View full analysis
Vulnerability Details
File Location:
dist/scanner.js:145-170; equivalent exclusions also occur indist/trojan-detector.js:122-143,dist/prompt-poison-detector.js:120-142, anddist/hallucination-detector.js:123-138
Vulnerability Type: Security scanner bypass through incomplete file coverage
Risk Level: MediumVulnerable Code
js async collectSkillFiles(skillPath) { const files = []; async function collect(dir) { try { const entries = await fs.readdir(dir, { withFileTypes: true }); for (const entry of entries) { const fullPath = path.join(dir, entry.name); if (entry.isDirectory()) { // Skip directories such as node_modules if (!['node_modules', '.git', 'dist', 'build'].includes(entry.name)) { await collect(fullPath); } } else if (entry.isFile()) { // Only inspect relevant file types const ext = path.extname(entry.name).toLowerCase(); if (['.md', '.js', '.ts', '.json', '.sh', '.bat', '.ps1'].includes(ext) || entry.name === 'package.json' || entry.name === 'SKILL.md') { files.push(fullPath); } } } } catch (error) { // Ignore inaccessible directories } } await collect(skillPath); return files; }The same vulnerable exclusion model is used by the specialized detectors:
js if (!['node_modules', '.git', 'dist', 'build', 'test', '__tests__'].includes(entry.name)) { await collect(fullPath); }Technical Analysis
The scanner recursively analyzes selected source and documentation files but categorically excludes directories named
distandbuild. T ...[truncated 2363 chars]- Remediation
View remediation
Remediation Suggestions
- Do not exclude
distorbuilddirectories when they contain executable package artifacts. - Parse
package.json,openclaw.plugin.json, and other supported manifests before scanning. - Resolve and always scan all declared runtime entry points, including:
mainexportsbin- OpenClaw extension entries
- Plugin entry points
- Lifecycle and package scripts
- Scan both source files and distributed artifacts because generated output may differ from the source.
- Restrict exclusions to dependencies, caches, and version-control metadata, while still checking whether a manifest points into an excluded directory.
- Record every skipped path and the reason it was skipped in the final report.
- Treat unreadable runtime files or directories as an incomplete scan rather than silently reporting them as clean.
- Add regression tests containing a benign source tree and a malicious
dist/index.js, and verify that the runtime payload is detected. - Consider comparing source and compiled artifacts or verifying reproducible builds to identify package-content discrepancies.
- Do not exclude
