T05 · Unauthorized Access and Privilege Escalation
- Location
index.ts:551- Finding
Unrestricted Caller-Controlled Cross-Skill Command Dispatch
- Content
View full analysis
{ const id = await orchestrator.createWorkflow({ name: args.name, steps: args.definition, context: args.context }); ``` The caller-controlled step is subsequently dispatched without validation: ```typescript // Add workflow metadata resolvedArgs._workflow = { workflowId, stepId: step.id, attempt }; this.api.log(`debug`, `Executing ${step.skill}:${step.command} with args: ${JSON.stringify(resolvedArgs)}`); // Execute command via API const result = await this.api.executeCommand(step.skill, step.command, resolvedArgs); ``` ### Technical Analysis The public `workflow create` command accepts an arbitrary object as its workflow definition. The supplied steps determine the `skill`, `command`, and command arguments passed to `api.executeCommand`. No strict step schema, command allowlist, capability check, or per-command authorization is applied before dispatch. Consequently, the orchestrator acts as a generic command proxy. A caller who is authorized to create and start workflows may be able to invoke commands in other installed skills that the caller could not invoke directly. The exact commands available depend on the surrounding OpenClaw environment, but the reachable privilege scope includes every skill and command that the orchestrator's API context is permitted to execute. ### Attack Path 1. An attacker obtains permission to invoke the orchestrator's `workflow create` and `workflow start` subcommands. 2. The attacker creates a ...[truncated 956 chars]- Remediation
View remediation
