T05 · Unauthorized Access and Privilege Escalation
- Location
model/scripts/veo_worker.py:68- Finding
Unscoped Provider Credential Access and Transmission
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent video-generation integration, but it uses broad local credentials, background execution, runtime installation, and automatic URL opening in ways users should review before installing.
Install only if you are comfortable with this skill reading your OpenClaw provider API key, sending prompts and that credential to the Wanjie endpoint, writing prompt-bearing logs locally, installing Python packages at runtime if missing, running background workers or scheduled monitoring, and opening returned links automatically. Prefer a version that uses a dedicated skill-scoped credential, pins dependencies, redacts logs, validates returned URLs, and documents how to disable background monitoring.
model/scripts/veo_worker.py:68Unscoped Provider Credential Access and Transmission
model/scripts/veo_worker.py:206Automatic Launch of an Unvalidated URL from Remote Model Output
model/scripts/video_interface.py:7Automatic Installation of an Unpinned Runtime Dependency
model/scripts/veo_worker.py:75Persistent Plaintext Logging of User Prompts and API-Key Fragments
The README explicitly tells users to ensure network connectivity so the skill can automatically download missing Python dependencies at runtime. This creates an undocumented supply-chain and environment-modification risk: the skill may change the host system and fetch code from external sources without clear trust boundaries, version pinning, or operator approval. In the context of an agent skill with background automation and self-healing behavior, that is more dangerous because network access and automatic restarts can repeatedly trigger external downloads without close user oversight.
The skill explicitly describes persistent background monitoring, automatic task handling, scheduled execution, and writing results to local files, but it does not clearly warn users that it will make ongoing system changes and continue operating after the initial interaction. This is dangerous because users may unknowingly install a skill that creates persistence via Windows Task Scheduler and performs unattended actions or writes data to disk outside the immediate request context.
This code launches a detached Python subprocess to generate a video, but there is no confirmation prompt, comment explaining the safety impact, or user-visible disclosure before execution. Although a reply is returned afterward, it does not warn the user that an external process is being spawned in the background.
The code automatically launches a URL returned from a remote API using the platform URL opener. Although it avoids shell injection by passing an argument list, it still causes untrusted remote content to be executed in the user's browser or associated handler without confirmation, enabling phishing, drive-by navigation, or abuse of custom URI schemes if a malicious or compromised service returns a crafted link.
if platform.system() == 'Windows':
os.startfile(url)
elif platform.system() == 'Darwin': # macOS
subprocess.Popen(['open', url])
else: # Linux
subprocess.Popen(['xdg-open', url])
except Exception as e:
On Linux, the script passes an untrusted URL directly to xdg-open, which will invoke the default handler for the supplied scheme. This is not command injection, but it is still unsafe automatic handling of attacker-controlled content and may trigger browser navigation, local app launch, or custom protocol handlers without user approval.
elif platform.system() == 'Darwin': # macOS
subprocess.Popen(['open', url])
else: # Linux
subprocess.Popen(['xdg-open', url])
except Exception as e:
log_exc("[!] 打开URL失败", e)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# 没有 psutil:Windows 用 tasklist 粗略判断;其他平台保守不删锁
try:
if platform.system() == 'Windows':
res = subprocess.run(['tasklist', '/FI', f'PID eq {pid}'],
capture_output=True, text=True)
return str(pid) in res.stdout
except Exception:
The function signature and logged input imply that the caller-provided model and seconds values influence video generation. However, the request payload hardcodes "veo3.1" and never includes or uses seconds, so the documented/advertised inputs do not match actual behavior.
The script reads an API key from a local configuration file and logs a fingerprint of it without any consent or warning. Even partial disclosure can aid secret correlation across logs and environments, and the more significant issue is that a hidden background worker accesses credentials from another tool's config and transmits them to a third-party API with little transparency.
User-supplied prompt content is sent to an external API endpoint, and the script also logs the full prompt locally. In an agent-skill context, prompts may contain sensitive user data, secrets, or proprietary content, so silent exfiltration to a third party materially increases privacy and data-leak risk.
The script automatically opens a URL extracted from streamed remote output without validating its scheme, host, or safety. In this skill context, that is more dangerous because the URL is entirely controlled by an external service response and the launch is automatic, enabling phishing pages, malicious downloads, or invocation of custom URI handlers on the host.
Comments, status messages, and the function's returned user-facing text are written in Chinese, which can impose a fixed language experience on users without opt-in. Under the policy, a skill should not force a specific language or locale unless it is clearly justified or the user is given a choice.
The skill both installs packages at runtime and launches a separate worker process, giving it the ability to change its execution environment and then execute additional code outside the main flow. That combination materially expands attack surface and makes the skill more dangerous than a normal content-generation interface, especially since no stated purpose justifies these capabilities in the visible code.
The skill silently installs a missing dependency without requiring confirmation or providing a meaningful warning about modifying the system environment. In agent or shared-host settings, this can violate operator expectations, introduce unreviewed code into the environment, and create reliability and supply-chain concerns.
The code automatically invokes pip at runtime to install a package into the current Python environment without explicit user approval or any integrity controls such as pinning, hashes, or an isolated virtual environment. Even though the package name is fixed, modifying the runtime environment from within a skill increases supply-chain and environment-tampering risk and can have unexpected side effects in shared deployments.
importlib.import_module("requests")
except ImportError:
print("[*] 正在安装缺失依赖: requests...")
subprocess.check_call([sys.executable, "-m", "pip", "install", "requests"])
def trigger_veo_generation(prompt, model="veo3.1-fast", seconds=8):
# 在触发前确保环境就绪
The code launches a background subprocess and only returns a generic success message, without clearly disclosing that execution is detached or what command is being run. This reduces informed consent and makes it harder for users or platform operators to monitor, cancel, or investigate the process if something goes wrong.
This launches a detached background worker process while suppressing all stdout and stderr, which reduces visibility into what the child process is doing and makes misuse or failure harder to detect. While the command is passed as an argument list rather than a shell string, the hidden detached execution model is still risky in an agent skill because it can continue operating outside normal interaction controls and auditing.
if platform.system() == 'Windows':
# 将输出重定向到 NUL 以防止 OpenClaw 报错
with open(os.devnull, 'w') as devnull:
subprocess.Popen(cmd, stdout=devnull, stderr=devnull, creationflags=subprocess.CREATE_NEW_PROCESS_GROUP)
else:
# Linux/macOS 上启动新进程
with open(os.devnull, 'w') as devnull:
This Unix/macOS path also spawns a detached worker session with output redirected to /dev/null, creating the same monitoring and control problem as on Windows. In a skill context, silent background execution is more dangerous because it can persist beyond the initiating request and conceal unwanted behavior in the worker script.
else:
# Linux/macOS 上启动新进程
with open(os.devnull, 'w') as devnull:
subprocess.Popen(cmd, stdout=devnull, stderr=devnull, start_new_session=True)
return f"[*] 任务已提交: {prompt},请在聊天窗口耐心等待结果通知。"
The natural-language instructions and trigger example are entirely Chinese, and the usage guidance at L28 only presents a Chinese invocation format. There is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language context.
The usage instructions only present the trigger phrase in Chinese (生成视频:[您的提示词]) and do not indicate that other languages are supported or that the language requirement is optional. This can constitute a language/locale policy issue because it implicitly forces a specific language without opt-in or justification.
The comment indicates a benign readiness check before generation, but ensure_dependencies can call pip to install requests, which changes the runtime environment. That goes beyond merely checking readiness and creates a mismatch between the documented intent and actual behavior.
The dependency is specified as requests>=2.25.1, which permits installation of many future and historical versions rather than a single reviewed release. This weakens supply-chain control and reproducibility, and can allow deployment of a vulnerable or incompatible version without the maintainer realizing it.
requests>=2.25.1
requests has multiple known advisories, and because the manifest does not pin an exact version, it is not possible to verify whether the installed version is affected. In practice, this means deployments may resolve to a vulnerable release, exposing the skill to known issues such as credential leakage or other request-handling flaws depending on the resolved version.
Detected: suspicious.dangerous_exec