Back to skill

Security audit

库存查询

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent inventory lookup tool, but its instructions pass user text directly into an execution command without quoting or validation.

Review before installing. This does not look malicious, but it should be changed to invoke query.py with structured arguments or strict quoting and model validation. Install only where inventory data may be shown to the requesting user, and avoid using it in an environment where free-form user text is interpolated into shell commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:10
Finding

Unquoted User Input in Execution Commands Enables Potential Command Injection

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10-16
Vulnerability Type: Command injection through unsafe argument construction
Risk Level: High

Vulnerable code:

text
exec python3 /root/.openclaw/workspace/skills/inventory-query/query.py 库存 用户输入的型号

exec python3 /root/.openclaw/workspace/skills/inventory-query/query.py 补货 用户输入的型号

exec python3 /root/.openclaw/workspace/skills/inventory-query/query.py 全部 用户输入的型号

Technical Analysis

The Skill instructs the Agent to append the user-provided model value directly to an execution command. It does not require shell-safe quoting, validation, or use of a structured argument array.

If the exec facility passes this command through a shell, metacharacters contained in the model value may be interpreted as shell syntax rather than as part of a single argument. The Python script itself does not invoke subprocesses; the vulnerable boundary is the construction and execution of the command before query.py receives its arguments.

Even when shell interpretation is unavailable, unquoted whitespace can split the model into multiple arguments. Because query.py reads only sys.argv[2], this can produce incorrect or truncated searches.

Attack Path

  1. An attacker submits an inventory or replenishment query containing shell metacharacters in the model value.
  2. The Agent follows SKILL.md and inserts the supplied value directly into the documented exec command.
  3. If the execution tool uses a shell, the shell parses the attacker-controlled metacharacters as command syntax.
  4. The injected command executes under the same operating-system account and environment as the Agent runtime.
  5. The attacker may use that access to read accessible files, alter workspace data, invoke installed programs, or access credentials available to that process.

Exploitability depends on whether the Agent's exec implementation invokes a shell. The unsafe instruc ...[truncated 509 chars]

Remediation
View remediation

Remediation Suggestions

  • Invoke the Python script through a structured process API using an argument array, with shell processing disabled.
  • Pass the mode and model as separate arguments, equivalent to:
    python
    subprocess.run(
        ["python3", "/root/.openclaw/workspace/skills/inventory-query/query.py", mode, user_model],
        shell=False,
        check=True
    )
    
  • Update SKILL.md to explicitly prohibit interpolating user input into shell command strings.
  • If a shell is unavoidable, apply robust platform-specific shell quoting to every user-controlled argument. Quoting is secondary to avoiding the shell entirely.
  • Validate model input using an allowlist of expected characters and enforce a reasonable maximum length.
  • Consider using an explicit --model option and an argument parser so user input cannot be confused with command options.
  • Run the Skill under a dedicated least-privileged account with access limited to the required inventory files.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition is broad enough to activate on common inventory-related phrases without clear scoping, which can cause the agent to invoke this skill in unintended contexts. Because the skill then instructs the agent to execute a command and return the output verbatim, accidental activation increases the chance of inappropriate tool use or unintended disclosure from backend query results.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The user-facing usage text is fixed in Chinese, which imposes a specific language on users without any visible opt-in or fallback. The same Chinese-only wording continues throughout the script’s printed output, indicating a locale choice is enforced rather than selectable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.