Back to skill

Security audit

Tool Governance

Security checks for vulnerabilities and agentic risk

Overview

This tool-safety skill is not obviously malicious, but its hooks can steer or block agent tool use and mutate Git state while relying on weak validation and overstated safety guarantees.

Install only if you are comfortable reviewing and hardening the hook scripts first. At minimum, validate session IDs before using them in paths, sanitize or avoid replaying raw tool errors into agent context, implement the documented path-boundary checks, and treat Git checkpoints as best-effort rather than guaranteed rollback.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tool-error-tracker.sh:12
Finding

Unvalidated Session Identifier Enables Filesystem Path Traversal and State Poisoning

Content
View full analysis
/dev/null) [ -z "$SESSION_ID" ] && SESSION_ID="${NC_SESSION:-}" [ -z "$SESSION_ID" ] && exit 0 SESSION_DIR="${SESSIONS_DIR}/${SESSION_ID}" mkdir -p "$SESSION_DIR" STATE_FILE="${SESSION_DIR}/tool-errors.json" ``` The resulting path is later written through an atomic replacement: ```bash TMP="${STATE_FILE}.${$}.$(date +%s).tmp" jq -n \ --arg tool "$TOOL" \ --arg hash "$INPUT_HASH" \ --arg error "$ERROR" \ --argjson count "$COUNT" \ --arg first "$(jq -r '.first_at // ""' "$STATE_FILE" 2>/dev/null || echo "$NOW")" \ --arg last "$NOW" \ '{tool_name: $tool, input_hash: $hash, error: $error, count: $count, first_at: (if $first == "" then $last else $first end), last_at: $last}' \ > "$TMP" mv "$TMP" "$STATE_FILE" ``` The advisor constructs a read path in the same way: ```bash # scripts/tool-error-advisor.sh SESSIONS_DIR="${HOME}/.openclaw/shared-context/sessions}" INPUT=$(cat) SESSION_ID=$(echo "$INPUT" | jq -r '.session_id // ""' 2>/dev/null) [ -z "$SESSION_ID" ] && SESSION_ID="${NC_SESSION:-}" [ -z "$SESSION_ID" ] && echo '{"continue":true}' && exit 0 STATE_FILE="${SESSIONS_DIR}/${SESSION_ID}/tool-errors.json" [ -f "$STATE_FILE" ] || { echo '{"continue":true}'; exit 0; } ``` The denial tracker repeats the unsafe construction: ```bash SESSION_ID=$(echo "$INPUT" | jq -r '.session_id // ""' 2>/dev/null) [ -z "$SESSION_ID" ] && SESSION_ID="${NC_SESSION:-}" [ -z "$SESSION_ID" ] && echo '{"continue":true}' && exit 0 SESSION_DIR="${SESSIONS_DIR}/${SESSION_ID}" STATE_FILE="${SESSION_DIR}/de ...[truncated 2285 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
scripts/tool-error-tracker.sh:21
Finding

Attacker-Controlled Tool Errors Are Injected into Agent Governance Context

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tool-input-guard.sh:16
Finding

Bash Safety Guard Is Fail-Open and Omits Its Declared Path-Boundary Enforcement

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/checkpoint-rollback.sh:16
Finding

Checkpoint Hook Suppresses Backup Failures and Does Not Provide the Documented Automatic Rollback

Content
View full analysis
/dev/null; then if ! git diff --quiet 2>/dev/null || ! git diff --cached --quiet 2>/dev/null; then STASH_MSG="harness-checkpoint-$(date +%s)" git stash push -m "$STASH_MSG" --include-untracked &>/dev/null || true jq -n --arg ctx "Auto-checkpoint created: '${STASH_MSG}'. Use 'git stash pop' to restore if needed." \ '{"hookSpecificOutput":{"additionalContext":$ctx}}' exit 0 fi fi fi echo '{"continue":true}' ``` ### Technical Analysis The implementation has several unsafe recovery properties: 1. `git stash push --include-untracked` modifies the working tree by removing current tracked and untracked changes before the proposed command runs. 2. The stash command’s failure is suppressed with `|| true`. 3. The hook reports `Auto-checkpoint created` regardless of whether a stash was successfully created. 4. The precondition checks only tracked and index differences. A repository containing only untracked changes may skip checkpoint creation even though the stash command was intended to include untracked files. 5. The script does not capture or persist the actual stash object reference. 6. No executable PostToolUseFailure rollback script is present in `scripts/`, although `SKILL.md` and `references/checkpoint-rollback.md` describe automatic rollback. 7. Git stash ...[truncated 1811 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (83)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
### 2.4 Graduated permission rules [config]

一刀切的权限模型要么太松(YOLO mode 全放行)要么太紧(每次都确认)。本 pattern 用 PreToolUse hook 对工具调用做三级风险分类:Read/Glob/Grep 为 safe 自动放行,Write/Edit 检查路径是否在项目目录内(系统目录 deny),Bash 按命令内容匹配 dangerous(`rm -rf /`、`curl|sh` 直接 deny)/ medium(`sudo`、`--force` 放行但告警)。风险矩阵可通过外部 JSON 配置扩展,不同项目各自调整。 → [详见](references/graduated-permissions.md)

### 2.5 Component-scoped hooks [config]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
### 2.6 Tool input guard [script]

Agent 构造的 Bash 命令可能意外包含路径逃逸、全局破坏或远程注入——特别是从文件内容提取路径拼接命令时。PreToolUse hook 独立检查三类模式:路径边界(`realpath` 确认在项目根目录内,`/tmp` 和工具路径白名单放行)、破坏性黑名单(`rm -rf /`、`mkfs`、`dd`)、pipe-to-shell(`curl|sh`、`wget|sh`)。命中任一即 deny。独立于 2.4 的粗粒度分层,专做 Bash 细粒度输入校验。 → [详见](references/tool-input-guard.md)

## Hook Protocol: PreToolUse 的三种响应

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
### 2.6 Tool input guard [script]

Agent 构造的 Bash 命令可能意外包含路径逃逸、全局破坏或远程注入——特别是从文件内容提取路径拼接命令时。PreToolUse hook 独立检查三类模式:路径边界(`realpath` 确认在项目根目录内,`/tmp` 和工具路径白名单放行)、破坏性黑名单(`rm -rf /`、`mkfs`、`dd`)、pipe-to-shell(`curl|sh`、`wget|sh`)。命中任一即 deny。独立于 2.4 的粗粒度分层,专做 Bash 细粒度输入校验。 → [详见](references/tool-input-guard.md)

## Hook Protocol: PreToolUse 的三种响应

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
| `tool-input-guard.sh` | PreToolUse (Bash) | 安全验证 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

PreToolUse hook 收到 stdin JSON:

json
{"tool_name": "Bash", "tool_input": {"command": "rm -rf /tmp/build"}}

断路器触发时输出(deny + 原因):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

PreToolUse hook 收到 stdin JSON:

json
{"tool_name": "Bash", "tool_input": {"command": "rm -rf /tmp/build"}}

断路器触发时输出(deny + 原因):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding again reflects the unsafe documentation pattern of modifying a destructive rm command with a likely ineffective '--dry-run' suffix. In a security control skill, incorrect safety examples can directly lead to hazardous real-world implementations.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

updatedInput 修改工具参数(如加 --dry-run):

json
{"decision": "allow", "hookSpecificOutput": {"updatedInput": {"command": "rm -rf /tmp/build --dry-run"}}}

additionalContext 注入建议:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

This duplicate finding again reflects the unsafe documentation pattern of modifying a destructive rm command with a likely ineffective '--dry-run' suffix. In a security control skill, incorrect safety examples can directly lead to hazardous real-world implementations.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

updatedInput 修改工具参数(如加 --dry-run):

json
{"decision": "allow", "hookSpecificOutput": {"updatedInput": {"command": "rm -rf /tmp/build --dry-run"}}}

additionalContext 注入建议:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This duplicate finding again reflects the unsafe documentation pattern of modifying a destructive rm command with a likely ineffective '--dry-run' suffix. In a security control skill, incorrect safety examples can directly lead to hazardous real-world implementations.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

updatedInput 修改工具参数(如加 --dry-run):

json
{"decision": "allow", "hookSpecificOutput": {"updatedInput": {"command": "rm -rf /tmp/build --dry-run"}}}

additionalContext 注入建议:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/graduated-permissions.md (reported line 5)May include surrounding context.

md
## Problem

Claude Code 默认对所有工具调用使用相同的权限模型——要么全部 auto-allow(YOLO mode),要么全部需要确认。但工具的风险差异巨大:Read 文件几乎无害,`rm -rf /` 可能毁掉系统。一刀切的权限模型要么太宽松(安全隐患),要么太严格(效率低下)。

## Solution

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The specific regex rm -rf /[^.] is incomplete and can miss destructive variants, while also creating a false sense of protection. Because this skill is specifically about tool permission governance, an evadable pattern here directly weakens the control layer meant to stop harmful Bash invocations.

Content

Scanner excerpt · references/graduated-permissions.md (reported line 38)May include surrounding context.

md
Bash)
    CMD=$(echo "$TOOL_INPUT" | jq -r '.command // ""')
    # Dangerous patterns
    if echo "$CMD" | grep -qE 'rm -rf /[^.]|mkfs|dd if=|:(){ :|curl.*\|.*sh|wget.*\|.*sh'; then
      echo '{"decision":"deny","reason":"检测到高危命令。请使用更安全的替代方案。"}'
    elif echo "$CMD" | grep -qE 'sudo|chmod 777|git push.*--force'; then
      echo '{"decision":"allow","hookSpecificOutput":{"additionalContext":"[WARN] 检测到中风险命令,已放行但请确认操作意图。"}}'

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The specific regex rm -rf /[^.] is incomplete and can miss destructive variants, while also creating a false sense of protection. Because this skill is specifically about tool permission governance, an evadable pattern here directly weakens the control layer meant to stop harmful Bash invocations.

Content

Scanner excerpt · references/graduated-permissions.md (reported line 38)May include surrounding context.

md
Bash)
    CMD=$(echo "$TOOL_INPUT" | jq -r '.command // ""')
    # Dangerous patterns
    if echo "$CMD" | grep -qE 'rm -rf /[^.]|mkfs|dd if=|:(){ :|curl.*\|.*sh|wget.*\|.*sh'; then
      echo '{"decision":"deny","reason":"检测到高危命令。请使用更安全的替代方案。"}'
    elif echo "$CMD" | grep -qE 'sudo|chmod 777|git push.*--force'; then
      echo '{"decision":"allow","hookSpecificOutput":{"additionalContext":"[WARN] 检测到中风险命令,已放行但请确认操作意图。"}}'

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

Allowing chmod 777 under a warning-only path is unsafe because it can make files or directories world-writable, enabling tampering or privilege boundary erosion. In a tool-governance skill, permissive handling of dangerous parameters undermines the purpose of graduated permissions.

Content

Scanner excerpt · references/graduated-permissions.md (reported line 40)May include surrounding context.

md
# Dangerous patterns
    if echo "$CMD" | grep -qE 'rm -rf /[^.]|mkfs|dd if=|:(){ :|curl.*\|.*sh|wget.*\|.*sh'; then
      echo '{"decision":"deny","reason":"检测到高危命令。请使用更安全的替代方案。"}'
    elif echo "$CMD" | grep -qE 'sudo|chmod 777|git push.*--force'; then
      echo '{"decision":"allow","hookSpecificOutput":{"additionalContext":"[WARN] 检测到中风险命令,已放行但请确认操作意图。"}}'
    fi
    ;;

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/tool-input-guard.md (reported line 9)May include surrounding context.

md
## Solution

PreToolUse hook 专门针对 Bash 工具做输入验证,检查三类危险模式:路径边界逃逸(`../` 到项目外)、破坏性全局操作(`rm -rf /`)、远程代码注入(`curl | sh`)。每类独立检查,命中任一即 deny。

## Implementation

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/tool-input-guard.md (reported line 9)May include surrounding context.

md
## Solution

PreToolUse hook 专门针对 Bash 工具做输入验证,检查三类危险模式:路径边界逃逸(`../` 到项目外)、破坏性全局操作(`rm -rf /`)、远程代码注入(`curl | sh`)。每类独立检查,命中任一即 deny。

## Implementation

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/tool-input-guard.md (reported line 9)May include surrounding context.

md
## Solution

PreToolUse hook 专门针对 Bash 工具做输入验证,检查三类危险模式:路径边界逃逸(`../` 到项目外)、破坏性全局操作(`rm -rf /`)、远程代码注入(`curl | sh`)。每类独立检查,命中任一即 deny。

## Implementation

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/tool-input-guard.md (reported line 23)May include surrounding context.

md
CMD=$(echo "$INPUT" | jq -r '.tool_input.command // ""')
PROJECT_ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)

# 1. 路径边界:检测 ../../../etc/passwd 类逃逸
PATHS=$(echo "$CMD" | grep -oE '(/[a-zA-Z0-9_./-]+|\.\./)' || true)
for P in $PATHS; do
  RESOLVED=$(realpath -m "$P" 2>/dev/null || echo "$P")

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_tool_input_guard.py (reported line 72)May include surrounding context.

python
CMD=$(echo "$INPUT" | jq -r '.tool_input.command // ""')
PROJECT_ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)

# 1. 路径边界:检测 ../../../etc/passwd 类逃逸
PATHS=$(echo "$CMD" | grep -oE '(/[a-zA-Z0-9_./-]+|\.\./)' || true)
for P in $PATHS; do
  RESOLVED=$(realpath -m "$P" 2>/dev/null || echo "$P")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
#!/usr/bin/env bash
# tool-input-guard.sh — PreToolUse hook: validate bash inputs against safety rules
# Blocks dangerous patterns: rm -rf /, curl|sh, chmod 777 on system paths, etc.

set -euo pipefail

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
#!/usr/bin/env bash
# tool-input-guard.sh — PreToolUse hook: validate bash inputs against safety rules
# Blocks dangerous patterns: rm -rf /, curl|sh, chmod 777 on system paths, etc.

set -euo pipefail

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
#!/usr/bin/env bash
# tool-input-guard.sh — PreToolUse hook: validate bash inputs against safety rules
# Blocks dangerous patterns: rm -rf /, curl|sh, chmod 777 on system paths, etc.

set -euo pipefail

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/graduated-permissions.md (reported line 5)May include surrounding context.

md
#!/usr/bin/env bash
# tool-input-guard.sh — PreToolUse hook: validate bash inputs against safety rules
# Blocks dangerous patterns: rm -rf /, curl|sh, chmod 777 on system paths, etc.

set -euo pipefail

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/tool-input-guard.md (reported line 9)May include surrounding context.

md
#!/usr/bin/env bash
# tool-input-guard.sh — PreToolUse hook: validate bash inputs against safety rules
# Blocks dangerous patterns: rm -rf /, curl|sh, chmod 777 on system paths, etc.

set -euo pipefail

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/tool-input-guard.sh (reported line 3)May include surrounding context.

sh
#!/usr/bin/env bash
# tool-input-guard.sh — PreToolUse hook: validate bash inputs against safety rules
# Blocks dangerous patterns: rm -rf /, curl|sh, chmod 777 on system paths, etc.

set -euo pipefail

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · tests/test_tool_input_guard.py (reported line 42)May include surrounding context.

python
#!/usr/bin/env bash
# tool-input-guard.sh — PreToolUse hook: validate bash inputs against safety rules
# Blocks dangerous patterns: rm -rf /, curl|sh, chmod 777 on system paths, etc.

set -euo pipefail

Static analysis

No suspicious patterns detected.