T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Unquoted User Input in Execution Commands Enables Potential Command Injection
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10-16
Vulnerability Type: Command injection through unsafe argument construction
Risk Level: HighVulnerable code:
text exec python3 /root/.openclaw/workspace/skills/inventory-query/query.py 库存 用户输入的型号 exec python3 /root/.openclaw/workspace/skills/inventory-query/query.py 补货 用户输入的型号 exec python3 /root/.openclaw/workspace/skills/inventory-query/query.py 全部 用户输入的型号Technical Analysis
The Skill instructs the Agent to append the user-provided model value directly to an execution command. It does not require shell-safe quoting, validation, or use of a structured argument array.
If the
execfacility passes this command through a shell, metacharacters contained in the model value may be interpreted as shell syntax rather than as part of a single argument. The Python script itself does not invoke subprocesses; the vulnerable boundary is the construction and execution of the command beforequery.pyreceives its arguments.Even when shell interpretation is unavailable, unquoted whitespace can split the model into multiple arguments. Because
query.pyreads onlysys.argv[2], this can produce incorrect or truncated searches.Attack Path
- An attacker submits an inventory or replenishment query containing shell metacharacters in the model value.
- The Agent follows
SKILL.mdand inserts the supplied value directly into the documentedexeccommand. - If the execution tool uses a shell, the shell parses the attacker-controlled metacharacters as command syntax.
- The injected command executes under the same operating-system account and environment as the Agent runtime.
- The attacker may use that access to read accessible files, alter workspace data, invoke installed programs, or access credentials available to that process.
Exploitability depends on whether the Agent's
execimplementation invokes a shell. The unsafe instruc ...[truncated 509 chars]- Remediation
View remediation
Remediation Suggestions
- Invoke the Python script through a structured process API using an argument array, with shell processing disabled.
- Pass the mode and model as separate arguments, equivalent to:
python subprocess.run( ["python3", "/root/.openclaw/workspace/skills/inventory-query/query.py", mode, user_model], shell=False, check=True ) - Update
SKILL.mdto explicitly prohibit interpolating user input into shell command strings. - If a shell is unavoidable, apply robust platform-specific shell quoting to every user-controlled argument. Quoting is secondary to avoiding the shell entirely.
- Validate model input using an allowlist of expected characters and enforce a reasonable maximum length.
- Consider using an explicit
--modeloption and an argument parser so user input cannot be confused with command options. - Run the Skill under a dedicated least-privileged account with access limited to the required inventory files.
