T09 · Insecure Skill Coding Practices
- Location
scripts/kb-llm.py:137- Finding
LLM-Controlled Path Traversal Enables Arbitrary Markdown File Writes
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an enterprise knowledge-base/Odoo sync tool, but it ships risky default Odoo credentials and can expose or overwrite sensitive knowledge-base content without enough safeguards.
Review this skill before installing or running it. Replace and rotate the bundled Odoo credential, do not store passwords or API tokens in ordinary knowledge-base articles, run Odoo export only with a known target and dry-run first, and avoid bulk activation across all agents unless that is explicitly intended. Treat LLM-generated wiki output as untrusted until filenames, paths, and article content are reviewed.
scripts/kb-llm.py:137LLM-Controlled Path Traversal Enables Arbitrary Markdown File Writes
scripts/kb-odoo-export.py:151Department-Restricted Articles Are Exported as Workspace-Visible
config.enterprise.json:2Plaintext Odoo Credential Is Shipped in Runtime Configuration
scripts/kb-odoo-export.py:54Unsanitized Markdown Content Is Written into Odoo HTML Articles
{p.strip()}
" if not p.strip().startswith('<') else p for p in paragraphs if p.strip() ] return '\n'.join(paragraphs) ``` The generated HTML is sent directly to Odoo: ```python with open(wiki_path, 'r', encoding='utf-8') as f: content = f.read() fm, body = extract_frontmatter(content) title = fm.get('title', os.path.basename(wiki ...[truncated 2056 chars]The description promises an enterprise knowledge-base skill with Odoo Knowledge sync and access-control features. The supplied code chunk only performs local setup for an agent-specific knowledge-base workspace: it creates directories, writes a simple config file, creates an index markdown file, and prints instructions. There is no evidence of Odoo API interaction, synchronization logic, permission enforcement, visibility settings, or credential handling. While this could be a supporting activation script within a larger skill, based on the supplied code chunk alone the actual behavior is materially narrower and different from the declared purpose.
声明描述强调的是企业版知识库能力,尤其是 Odoo Knowledge 同步以及权限、凭证等企业特性。但提供的代码没有任何 Odoo 接口调用、认证处理、权限逻辑、可见性策略或企业配置管理。相反,它只是一个用于将 raw/ 文档整理为 LLM 编译任务的脚本,负责收集文档、拼接 prompt、初始化 wiki 索引文件,并提示使用 OpenClaw 执行后续编译。因此代码实际行为与声明的核心用途存在明显偏差,属于实质性不匹配。
The declared description emphasizes an enterprise knowledge base with Odoo Knowledge sync, visibility controls, departmental permissions, and credential management. The supplied code does none of these. It only reads markdown files from a local wiki directory, categorizes them by simple text matching (type: paper/article/note), and writes index markdown files. This is a materially different primary purpose and lacks the enterprise/Odoo-related capabilities claimed in the description.
The description emphasizes an enterprise edition knowledge-base system with Odoo Knowledge sync and administrative/security features. The actual code chunk is narrowly focused on ingesting content from a URL, local file, or text into dated files under a raw directory. It performs basic argument parsing, filename sanitization, file copying, and markdown stub generation. There is no code interacting with Odoo, no API calls, no synchronization logic, no permission or visibility enforcement, and no credential handling. This is a material description-behavior mismatch, not merely an implementation detail omission.
The description claims an enterprise edition with Odoo Knowledge sync and access-control/credential-management features. The supplied code chunk does not implement any of those capabilities. It only initializes folders and starter files for a local knowledge-base project. While initialization may be a supporting detail of a larger system, this chunk’s actual behavior is materially narrower than the declared purpose and does not evidence the described enterprise-specific functionality.
The declared description emphasizes an enterprise edition with Odoo Knowledge sync and access-control/credential features. The supplied code only performs administrative local setup: it enumerates agent directories, creates per-agent kb subdirectories and seed files, and writes basic configuration. This is related to knowledge-base activation, but it does not implement the key enterprise capabilities claimed in the description. Additionally, the code has an undeclared bulk operation scope affecting all agents on disk. Therefore the description does not accurately represent what this code chunk actually does.
The declared description presents an enterprise knowledge base extension centered on Odoo Knowledge synchronization and enterprise access-control features. The supplied code chunk instead implements a knowledge-base compilation helper: it reads a prompt file, loads LLM provider configuration, makes outbound HTTP requests to an LLM service, parses structured model output, and writes compiled wiki Markdown files. While LLM-based knowledge compilation could be a supporting component of a knowledge-base product, the specific enterprise features emphasized in the description—Odoo Knowledge sync, visibility control, department-level permissions, and credential management—are not present in this code. Conversely, the code performs an undeclared networked LLM-calling capability using provider credentials from local config. Therefore this chunk does not accurately match the declared purpose.
The declared description presents an enterprise knowledge-base product with Odoo Knowledge sync and access-management features. The supplied code chunk is only a local lint/health-check utility for wiki content: it enumerates markdown files, creates a prompt describing consistency/link/content checks, and suggests invoking OpenClaw manually. This is a materially different purpose and lacks the headline enterprise/Odoo capabilities described. Therefore the description does not accurately represent this code chunk.
The declared description emphasizes an enterprise edition knowledge-base system with Odoo Knowledge sync, access-control features, and credential management. The supplied code chunk only performs a local text search over Markdown files in a wiki/ directory and formats results. It does not interact with Odoo, external services, credentials, permission systems, or visibility controls. While search could be a supporting KB feature, this specific code chunk does not substantiate the core declared enterprise/Odoo capabilities, so the description does not accurately represent the behavior shown.
The instruction to store all account passwords and API tokens in a shared Odoo knowledge base is a serious secret-management anti-pattern. Natural-language knowledge repositories are broadly readable, searchable, syncable, and often included in exports, backups, or LLM context, making credential theft, lateral movement, and accidental disclosure far more likely in an enterprise setting.
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill documents exporting articles to Odoo and handling credentials but does not provide an explicit warning that content will be transmitted to an external service and may create or modify records remotely. In a knowledge-base context, this increases the chance of accidental data exfiltration, unintended publication, or unauthorized modification of enterprise content because users may trigger sync/export without understanding the consequences.
The trigger list includes generic phrases such as "编译知识库" and "体检知识库", which could overlap with ordinary requests about knowledge-base maintenance rather than this specific enterprise skill. The file also does not provide exclusion conditions or negative examples to clarify when the skill should not activate.
The documentation presents kb-odoo-export as a normal workflow step and notes that preview mode requires --dry-run, but it does not clearly warn that the default behavior will create or update records in a remote Odoo Knowledge instance. In an enterprise knowledge-base context, this can lead to unintended publication or synchronization of internal content to an external system, especially when visibility settings or target environment are misconfigured.
The natural-language instruction explicitly requires summaries and body text to be written in Chinese. This is a language policy constraint applied unconditionally, and the file does not provide user opt-in, alternative locale selection, or a documented region-specific justification.
The script concatenates the full contents of every file under raw/ into a single prompt file intended for LLM processing, but it does not warn the operator that potentially sensitive enterprise documents will be aggregated and exposed to an external model workflow. In an enterprise knowledge-base skill that explicitly supports Odoo Knowledge sync and enterprise credential handling, this increases the likelihood of confidential business data, internal procedures, or regulated content being unintentionally disclosed.
This shell script's natural-language comments, usage text, and echo output are written in Chinese, which imposes a specific language/locale on users without offering a choice or documenting that the skill is intended only for a Chinese-speaking context. The policy explicitly calls for flagging language or locale constraints when they are forced without opt-in.
This shell script presents its description, usage examples, and later user-facing output entirely in Chinese, with no option to choose another language or locale. That is a natural-language policy concern under the language/locale rule because the skill imposes a specific language by default rather than offering user choice or documenting a justified locale restriction.
The script performs bulk installation against every local OpenClaw agent under ~/.openclaw/agents, which is broader than the enterprise skill’s stated purpose and can modify agents that did not explicitly opt in. In a multi-agent or shared workstation environment, this increases the blast radius of mistakes, causes unintended configuration changes, and may overwrite trust boundaries by enabling a knowledge-base component everywhere.
The script writes LLM-generated content directly to disk as markdown files without validation, confirmation, or clear user warning. Because the response can contain attacker-influenced text, filenames, frontmatter, and markdown content, this creates a trust-boundary violation that can persist untrusted output into the knowledge base and potentially enable content poisoning or unsafe file writes in downstream workflows.
The script sends the full prompt file contents to an external LLM provider over the network without an explicit disclosure or consent step at the point of transfer. In an enterprise knowledge-base skill, prompts may embed internal documents, credentials, URLs, or proprietary material, so silent transmission increases the risk of unintended data exposure to third-party services.
Natural-language strings in the docstring, CLI help, and runtime messages are all presented only in Chinese. Because there is no opt-in, locale selection, or documented region-specific justification, this constitutes a language/locale policy violation under the stated rule.
This code loads and uses the Odoo password from configuration to establish XML-RPC access, then later uses that connection to send knowledge-base content to a remote service. While the module docstring says it syncs to Odoo, there is no explicit warning at the connection point or before transmission about credential use or remote data export, which fits the missing user disclosure criteria for code files.
The script generates a prompt that explicitly instructs an LLM to directly modify wiki files and create a health report, but it does not require user confirmation, dry-run behavior, scoped edit constraints, or review-before-write safeguards. In an enterprise knowledge-base skill, this is risky because the wiki content itself is adversarial input to the downstream model, so prompt injection inside entries could steer the LLM into making unintended or destructive edits across the repository.
The script's description, usage text, and runtime messages are written only in Chinese, which imposes a specific language on users. Under the policy, locale or language constraints should either be optional for the user or clearly documented as a justified region-specific limitation.
No suspicious patterns detected.