Back to skill

Security audit

Bug Fixer Pro

Security checks for vulnerabilities and agentic risk

Overview

This bug-fixer is not clearly malicious, but it can quietly run a separate messaging script and send repair details without clear disclosure.

Review this skill before installing. It may create records in your OpenClaw home workspace and, if a Feishu messaging skill exists at the expected path, run that separate script and pass it bug-fix report details. Install only if you accept that behavior and trust the sibling messaging integration.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/autonomous-fix.sh:241
Finding

Unverified Execution of an External Messaging Script

Content
View full analysis

Vulnerability Details

File Location: scripts/autonomous-fix.sh:241-244
Vulnerability Type: Unverified external tool execution
Risk Level: Medium

Vulnerable Code

bash
if [ -f "${WORKSPACE}/skills/feishu-send-file/scripts/send-message.sh" ]; then
    cd "${WORKSPACE}/skills/feishu-send-file"
    ./scripts/send-message.sh text "${report}" 2>/dev/null || log "通知发送失败"
fi

Technical Analysis

The Skill conditionally executes send-message.sh, a mutable script located outside the audited package. It checks only whether the path is a regular file; it does not verify the file's ownership, permissions, integrity, provenance, or resistance to symbolic-link and path-substitution attacks.

Consequently, another component or user with write access to the external Skill directory can replace or modify this script. The modified script will then execute under the privileges of the user running autonomous-fix.sh. This creates a local tool-hijacking trust boundary in which a legitimate-looking notification call can execute attacker-controlled logic.

The invocation also supplies a report containing a fix identifier, error type, verification result, and local filesystem path. This notification and potential external transmission are not disclosed in SKILL.md.

Attack Path

  1. An attacker obtains write access to ${HOME}/.openclaw/workspace-mars/skills/feishu-send-file/scripts/send-message.sh or controls a component that can install a file at that path.
  2. The attacker replaces or creates send-message.sh with an executable payload.
  3. A user invokes scripts/autonomous-fix.sh for an ordinary bug report.
  4. The bug-fixing workflow reaches notify_fix_complete.
  5. The file-existence check succeeds, and the attacker-controlled script is executed.
  6. The payload runs with the invoking user's permissions and receives the generated report as an argument.

Impact Assessment

Successful exploit ...[truncated 553 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove implicit execution of sibling Skill scripts and make external notification an explicit, opt-in feature.
  2. Use a securely configured, fixed integration path rather than discovering an executable solely through file existence.
  3. Verify the integration's expected owner, restrictive permissions, regular-file status, and cryptographic integrity before execution.
  4. Resolve the canonical path and reject symbolic links or paths that escape the trusted integration directory.
  5. Ensure that neither the external script nor its parent directories are writable by untrusted users.
  6. Prefer a reviewed internal notification implementation or a narrowly scoped API client over executing another shell script.
  7. Clearly document outbound notification behavior and the exact data transmitted. Obtain explicit consent before sending reports.
  8. Minimize report contents and omit unnecessary local filesystem paths or sensitive diagnostic information.
  9. Execute the notification component with reduced privileges and a sanitized environment if external execution remains necessary.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script forwards a generated bug-fix report to an external notification script with no clear disclosure, consent, or data minimization. Bug reports commonly contain sensitive operational information such as internal paths, error text, incident timing, and inferred root causes, so undisclosed transmission materially increases confidentiality risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use the skill when a user reports a bug, error, or unexpected behavior in code or systems, which is a very broad condition that overlaps with many ordinary support and debugging requests. It does not define boundaries, exclusions, or narrower trigger phrases, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The operational instructions and workflow are written in Chinese, while the surrounding skill metadata is in English, and the document does not state that Chinese is required or offer an opt-in language choice. This can violate language/locale policy expectations by imposing a specific language without user consent or documented justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The header documents a workflow that analyzes errors, generates a fix, executes the repair, and verifies it. In practice, execute_fix mostly echoes status strings such as 'need to update API key', 'need privilege escalation', or 'created missing directory' without actually changing the target system, and verification only counts matching log entries rather than validating a repaired bug.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script creates directories and writes repair records automatically under the user's home directory without confirmation or a dry-run mode. In an autonomous agent skill, silent filesystem modification can surprise users, overwrite expectations about state, and normalize broader unattended actions that may later extend to riskier changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script invokes another skill to send a completion report externally, expanding its capabilities from local diagnosis/repair into outbound communication. In an autonomous bug-fixing context, this can leak operational details, file paths, error summaries, or other sensitive debugging content to external systems without a clear need-to-know boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script's descriptive comments and many user-facing log/report strings are written in Chinese, effectively constraining the skill's interaction language. There is no indication that users can choose another language or that the locale restriction is intentional and documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.