T09 · Insecure Skill Coding Practices
- Location
scripts/analyze_skill.txt:6106- Finding
Automatic execution of untrusted Skill code without explicit opt-in or guaranteed hard isolation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/analyze_skill.txt:6106-6123, 6660-6674, 6950-6955, 7055-7112, 7142-7155, 7228-7245, 7465-7467
Vulnerability Type: Automatic execution of attacker-controlled audit input in a soft sandbox
Risk Level: HighVulnerable Code
python def auto_dynamic_review(results, osv: bool = False): """v3.2.0:批量扫描后对高危(P0/P1) Skill 自动启用动态沙箱取证,不再需用户手动选择。 对每个含 P0/P1 命中的 Skill 重跑 analyze(dynamic=True),动态命中自动计入风险评分/准入/判定。 无 .py 脚本的 Skill 沙箱自然返回空(不适用),仅重扫一次,成本可控。 """ sev_rank = {"P0": 0, "P1": 1, "P2": 2, "P3": 3} for i, r in enumerate(results): if "error" in r: continue worst = min((sev_rank.get(h.get("sev"), 9) for h in collect_all_hits(r)), default=9) if worst > 1: continue root = Path(r.get("skill_path", "")) if not root.is_dir(): continue print(f"🔬 自动沙箱复查高危 Skill:{r['basic_info']['name']}({root})", file=sys.stderr) results[i] = analyze(root, osv=osv, dynamic=True) return resultspython if _c is not None: try: sys.setprofile(_prof) except Exception: pass try: exec(_c, _g) except SystemExit: pass except BaseException as e: _events.append(("error", type(e).__name__))python proc = subprocess.Popen( [sys.executable, "-I", "-S", "-c", probe], cwd=str(workdir), env=env, stdout=subprocess.PIPE, stderr=subprocess.PIPE )python def select_isolation(): """选择隔离后端:Docker > Windows Sandbox > 进程内审计钩子(降级)。""" b = detect_isolation_backends() if b["docker"]: return { "backend": "docker(container)", "hard": True, "note": "Docker 容器隔离:--network=none 断网 + 只读挂载 + cap-drop ALL + 资源限额。", "probe": b } if b["winsandbox"]: return { "backend": "windows-sandbox", "hard": True, "note": "Windows San ...[truncated 5148 chars]- Remediation
View remediation
Remediation Suggestions
- Remove automatic calls to
auto_dynamic_review()from normal batch scans. Dynamic execution must require an explicit--dynamicoption. - Add a separate explicit option such as
--allow-soft-sandboxbefore permitting the audit-hook backend. Without it, fail closed when no hard-isolation backend is available. - Require an interactive confirmation or machine-verifiable acknowledgment before executing any third-party source.
- Implement a real Windows Sandbox execution path before reporting that backend as selected or hard-isolated. Otherwise, mark it unavailable.
- Verify the chosen backend by execution behavior, not merely by executable presence. Do not silently downgrade after selection.
- Run target code only in a disposable OS-level container or VM with:
- No network access.
- Read-only target mounts.
- No host Docker socket or other control sockets.
- No inherited credentials or sensitive environment variables.
- A non-root user and dropped capabilities.
- A read-only root filesystem.
- Strict process, memory, CPU, and time limits.
- Disposable writable storage.
- Make backend failure terminate dynamic analysis rather than falling back to host Python execution.
- Update
SKILL.mdandopenclaw-skill.jsonso their claims accurately describe every execution path and fallback. - Add regression tests proving that batch scans without
--dynamicnever compile or execute files from the audited Skill. - Add tests confirming that backend metadata always matches the backend that actually executed the target.
- Remove automatic calls to
