T09 · Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Shell Command Injection Through Unescaped Credential Interpolation
- Content
View full analysis
' openclaw config set 'channels.weibo.appSecret' '' ``` The workflow subsequently instructs the agent to execute these commands with user-provided values: ```text 2. Run the two `openclaw config set` commands above with the provided values. ``` ### Technical Analysis The `AppId` and `AppSecret` values originate from the user and are intended to replace placeholders embedded inside single-quoted shell arguments. The skill does not require credential validation, shell-safe escaping, or execution through a structured argument-array API. If an agent constructs a command string by directly replacing the placeholders, a credential containing a single quote can terminate the quoted argument. The remaining content can then introduce shell operators and arbitrary commands. For example, a malicious value following this pattern could escape the intended argument: ```text ' ; attacker_command ; # ``` The vulnerability depends on the agent passing the interpolated command through a shell. It can be prevented by avoiding shell-string construction entirely. ### Attack Path 1. An attacker asks the agent to configure the Weibo channel. 2. The agent requests an AppId and AppSecret as directed by the workflow. 3. The attacker supplies a credential containing a closing single quote, shell separators, and an arbitrary command. 4. The agent substitutes that value into the documented command template. 5. The agent executes the resulting string through a shell. 6. The shell terminates the intended quoted argument and executes the injected command. 7. The attacker's command runs with the operating-system privileges and filesystem or network access available to the agent process. ### Impact Assessment Successful exploitation could permit a ...[truncated 458 chars]- Remediation
View remediation
