T05 · Unauthorized Access and Privilege Escalation
- Location
model/scripts/veo_worker.py:65- Finding
Unrelated Provider API Credential Sent to a Hard-Coded Third-Party Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This video-generation skill is purpose-aligned at a high level, but it handles local API credentials, background execution, package installation, logging, and browser opening with too little scoping and user control.
Review carefully before installing. Only use this with a dedicated Wanjie/OpenClaw API key that you are willing to send to wanjiedata.com, avoid sensitive prompt content, expect background Python processes and local logs, and do not rely on it unless you accept automatic dependency installation and automatic browser opening of returned links.
model/scripts/veo_worker.py:65Unrelated Provider API Credential Sent to a Hard-Coded Third-Party Service
model/scripts/veo_worker.py:36Untrusted API Response URL Automatically Opened in the Default Browser
model/scripts/video_interface.py:7Automatic Installation of an Unpinned Runtime Dependency
model/scripts/veo_worker.py:75User Prompts and API-Key Fingerprints Persisted in Plaintext Logs
The README explicitly states that the skill may automatically download missing Python dependencies over the network and automatically restart background processes, but it does not clearly warn users that installation/runtime behavior can modify the environment and initiate network activity. In an agent skill context, undocumented self-healing and restart behavior increases risk because it can mask persistence, surprise users, and make system or network changes without informed consent.
The invocation phrase is effectively unconstrained natural-language input ('生成视频:[您的提示词]'), which makes accidental or overly permissive triggering more likely in chat contexts. Because the skill also describes automatic background processing, broad triggering increases the chance that ordinary conversation text could initiate actions without sufficiently explicit user consent.
The skill discloses persistent background behavior, periodic monitoring, file output, automatic dependency installation, and Windows Task Scheduler registration, but does not present a clear, prominent warning or explicit consent flow for those persistence mechanisms. This is dangerous because users may unknowingly install a skill that creates long-lived background execution and scheduled tasks, which can consume resources, persist beyond the chat session, and mask unwanted behavior.
The skill only activates on the Chinese prefix '生成视频:' and responds in Chinese, imposing a specific language without offering any user choice or documenting a justified locale restriction. This is a natural-language policy concern because the language constraint is embedded directly in the interaction behavior.
This code launches a detached Python subprocess to generate a video in the background, which is a safety-relevant operation under the subprocess/shell execution criterion. Although there is a reply after spawning, the code provides no confirmation prompt, pre-execution warning, or explanatory comment disclosing that a background process will be started before the action occurs.
The worker has an unjustified capability to launch external URLs automatically, and the URL source is the remote model/API response rather than a trusted local decision. In the context of an otherwise background video-generation worker, this is risky because it can drive the user into malicious web content or invoke local protocol handlers without clear consent.
This launches the system URL handler on a URL derived from streamed model/API output without validating the scheme, domain, or trustworthiness of the destination. Even though shell injection is avoided by using an argument list, it still enables untrusted remote content to trigger browser or protocol-handler launches on the user's machine.
if platform.system() == 'Windows':
os.startfile(url)
elif platform.system() == 'Darwin': # macOS
subprocess.Popen(['open', url])
else: # Linux
subprocess.Popen(['xdg-open', url])
except Exception as e:
On Linux, the code invokes xdg-open on a URL extracted from untrusted response content, which can open a browser or other registered handler for arbitrary schemes. This expands the attack surface to phishing pages or dangerous custom URI handlers controlled by remote output.
elif platform.system() == 'Darwin': # macOS
subprocess.Popen(['open', url])
else: # Linux
subprocess.Popen(['xdg-open', url])
except Exception as e:
log_exc("[!] 打开URL失败", e)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# 没有 psutil:Windows 用 tasklist 粗略判断;其他平台保守不删锁
try:
if platform.system() == 'Windows':
res = subprocess.run(['tasklist', '/FI', f'PID eq {pid}'],
capture_output=True, text=True)
return str(pid) in res.stdout
except Exception:
The script reads an API key from a local ~/.openclaw config file, giving it access to credentials outside its immediate input surface. In an untrusted skill context, that is an unnecessary secret-access capability and can be abused to use or expose the user's existing credentials without clear authorization.
The code silently accesses a local API key from a user config file, which is sensitive local state, without clear disclosure or opt-in. In a skill setting, covert credential access is especially concerning because users may not expect this component to inherit secrets from another tool's configuration.
User-supplied prompt content is sent to an external third-party API without any visible disclosure, consent flow, or minimization controls in this file. If prompts contain sensitive data, this creates a confidentiality risk through silent data transfer to an outside service.
The script automatically opens a URL returned by remote output without user warning or approval, creating a silent external interaction with the user's desktop environment. This can facilitate phishing, drive-by navigation, or invocation of non-browser URI handlers depending on platform configuration.
Comments and user-facing messages in the file are written only in Chinese, including the returned status message and installation notice. This appears to impose a specific language on user-visible communication without offering a language choice or documenting a justified locale restriction.
The skill can modify the environment by installing packages at runtime despite limited declared context about why this capability is needed. In agent environments, self-modifying behavior reduces predictability and can be abused to fetch unreviewed code or alter system state beyond the user's expectations.
Automatically installing a missing dependency via pip without explicit user confirmation is a real security issue in agent skills. It creates an unreviewed network-enabled code acquisition path and may surprise users by altering the system or pulling packages from untrusted sources.
The code automatically invokes pip at runtime to install a package if it is missing. Runtime package installation changes the execution environment without user approval and can introduce supply-chain risk, especially if package indexes, mirrors, or environment settings are compromised.
importlib.import_module("requests")
except ImportError:
print("[*] 正在安装缺失依赖: requests...")
subprocess.check_call([sys.executable, "-m", "pip", "install", "requests"])
def trigger_veo_generation(prompt, model="veo3.1-fast", seconds=8):
# 在触发前确保环境就绪
The skill launches another script as a detached worker process without transparent justification, and it suppresses output from that worker. In a security review context, this is risky because it enables hidden execution paths and makes it difficult to verify what actions are being taken on the host.
This launches a detached subprocess and suppresses all stdout/stderr, making the worker's behavior opaque to the caller and harder to monitor or audit. Even though shell injection is not present because arguments are passed as a list, stealthy background execution increases the risk of abuse if the worker script is modified or behaves unexpectedly.
if platform.system() == 'Windows':
# 将输出重定向到 NUL 以防止 OpenClaw 报错
with open(os.devnull, 'w') as devnull:
subprocess.Popen(cmd, stdout=devnull, stderr=devnull, creationflags=subprocess.CREATE_NEW_PROCESS_GROUP)
else:
# Linux/macOS 上启动新进程
with open(os.devnull, 'w') as devnull:
This starts a new background session on Unix-like systems while redirecting output to /dev/null, which conceals execution and breaks normal observability. The danger is not command injection here, but the combination of detached execution and hidden output, which can mask unintended or unauthorized actions by the worker process.
else:
# Linux/macOS 上启动新进程
with open(os.devnull, 'w') as devnull:
subprocess.Popen(cmd, stdout=devnull, stderr=devnull, start_new_session=True)
return f"[*] 任务已提交: {prompt},请在聊天窗口耐心等待结果通知。"
The function logs input including the model argument and accepts --model from the CLI, implying the selected model is used for generation. However, the outgoing payload always sets "model": "veo3.1", so the observable behavior contradicts the apparent intent communicated by the interface/logging.
The dependency is specified as requests>=2.25.1, which allows installation of many different future and past-compatible versions rather than a reviewed, fixed release. This weakens supply-chain control and can lead to builds pulling in vulnerable or unexpected versions over time, especially when the package has a history of security advisories.
requests>=2.25.1
The manifest references requests without pinning to a specific version, while the package has multiple known security advisories across its release history. Because the resolved version is not fixed, it is impossible to verify from this file alone whether deployment will use a safe release, creating avoidable exposure to known vulnerable versions.
Detected: suspicious.dangerous_exec