T09 · Insecure Skill Coding Practices
- Location
scripts/recipe_manager.py:87- Finding
Spreadsheet Formula Injection in CSV and Excel Exports
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This recipe-management skill is coherent and purpose-aligned, but users should be aware that it stores local recipe data, can delete entries, and exports spreadsheet files without formula sanitization.
Install only if you are comfortable with the skill keeping a local recipe database in your home directory and creating export files there. Confirm delete/export requests carefully, and treat exported spreadsheets as untrusted if recipe text may come from other people because formula-like values are not sanitized.
scripts/recipe_manager.py:87Spreadsheet Formula Injection in CSV and Excel Exports
README.md:27Unpinned Third-Party Dependency Installation
从该代码片段看,实际行为是配方数据导出,而不是完整的“商用原料配方库”管理与成本计算。导出 CSV/Excel 与声明中的一部分能力一致,但声明强调的核心能力还包括录入配方、调取标准配比、成本计算、多版本管理等,这些在片段中均未体现。虽然单个文件可能只是导出模块,但按本次比对,当前代码块的实际功能范围明显窄于声明。此外,脚本末尾调用了未定义的 export_to_excel(),说明该导出代码本身还存在运行问题。综合判断,描述与此代码块并不准确对应。
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.openclaw/skills/recipe-manager
cp -r * ~/.openclaw/skills/recipe-manager/
openclaw gateway restart
pip3 install pandas openpyxl # 可选,用于导出 Excel
The skill advertises behavior that implies file creation/export and possibly code-assisted operations, but it declares no explicit tool scope or permission boundaries. When a skill can read/write files or invoke shell-like capabilities without a documented allowlist, the runtime may grant broader access than users expect, increasing the risk of unauthorized file access or unsafe command execution.
The trigger phrases are overly broad and overlap with ordinary conversation about recipes, ingredients, and cost. This can cause accidental invocation, leading the assistant to perform state-changing actions such as recording recipes or exporting data when the user may have intended only a general discussion.
The skill includes modification and deletion of recipe data plus CSV export, but it does not warn users before changing stored data or creating files. In practice, this can lead to unintended overwrites, silent data loss, or unanticipated file generation on the host system, especially when paired with ambiguous triggers.
This code exports recipe data to a CSV file in the user's home directory and then writes an Excel file, but the script provides no prior confirmation, warning message, docstring, or explanatory comment about these file-creation side effects. For code files, file writes affecting user data should have some visible disclosure unless clearly documented as part of the skill's stated purpose within the file or accompanying markdown.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
manager = Path(__file__).parent / "recipe_manager.py"
csv_path = Path.home() / "recipes_export.csv"
subprocess.run([sys.executable, str(manager), "export", "--output", str(csv_path)], check=True)
try:
import pandas as pd
The script exposes a destructive delete capability that is not disclosed in the skill metadata or stated capabilities. In an agent setting, hidden capabilities are risky because users or orchestrators may invoke the skill assuming it only stores, retrieves, calculates, and exports recipes, while it can also permanently remove data.
Recipe deletion happens immediately once an ID is provided, with no confirmation, dry-run, recycle bin, or undo path. In a conversational or agent-driven workflow, this increases the chance of accidental or induced data loss from ambiguous prompts, wrong IDs, or prompt-injection-driven tool use.
All user-facing description, triggers, examples, and notes are written only in Chinese, and the trigger model appears to assume Chinese input exclusively. The file does not state that the skill is region-specific or offer an opt-in language/locale choice, which may violate language-choice policy expectations.
The warning message uses Chinese only ("pandas未安装") with no indication that the skill is intentionally locale-specific or that users can opt into a language. This is a natural-language policy concern because the file imposes a specific language in user-facing output without justification or choice.
The script's structure implies it can be run directly via the main guard, but L21 calls export_to_excel(), which is never defined anywhere in the file. This is an intent-code divergence in the file's own execution path: the file appears documented-by-structure as a runnable exporter, but it will raise a NameError instead of performing export logic when invoked normally.
The module docstring and user-facing CSV headers and parsing behavior are written specifically for Chinese usage, and the script assumes Chinese currency/unit expressions such as '元/斤'. There is no indication that language or locale is selectable or that the Chinese-only behavior is a documented regional specialization.
No suspicious patterns detected.