T07 · Tool Hijacking and Spoofing
- Location
scripts/autonomous-fix.sh:241- Finding
Unverified Execution of an External Messaging Script
- Content
View full analysis
Vulnerability Details
File Location:
scripts/autonomous-fix.sh:241-244
Vulnerability Type: Unverified external tool execution
Risk Level: MediumVulnerable Code
bash if [ -f "${WORKSPACE}/skills/feishu-send-file/scripts/send-message.sh" ]; then cd "${WORKSPACE}/skills/feishu-send-file" ./scripts/send-message.sh text "${report}" 2>/dev/null || log "通知发送失败" fiTechnical Analysis
The Skill conditionally executes
send-message.sh, a mutable script located outside the audited package. It checks only whether the path is a regular file; it does not verify the file's ownership, permissions, integrity, provenance, or resistance to symbolic-link and path-substitution attacks.Consequently, another component or user with write access to the external Skill directory can replace or modify this script. The modified script will then execute under the privileges of the user running
autonomous-fix.sh. This creates a local tool-hijacking trust boundary in which a legitimate-looking notification call can execute attacker-controlled logic.The invocation also supplies a report containing a fix identifier, error type, verification result, and local filesystem path. This notification and potential external transmission are not disclosed in
SKILL.md.Attack Path
- An attacker obtains write access to
${HOME}/.openclaw/workspace-mars/skills/feishu-send-file/scripts/send-message.shor controls a component that can install a file at that path. - The attacker replaces or creates
send-message.shwith an executable payload. - A user invokes
scripts/autonomous-fix.shfor an ordinary bug report. - The bug-fixing workflow reaches
notify_fix_complete. - The file-existence check succeeds, and the attacker-controlled script is executed.
- The payload runs with the invoking user's permissions and receives the generated report as an argument.
Impact Assessment
Successful exploit ...[truncated 553 chars]
- An attacker obtains write access to
- Remediation
View remediation
Remediation Suggestions
- Remove implicit execution of sibling Skill scripts and make external notification an explicit, opt-in feature.
- Use a securely configured, fixed integration path rather than discovering an executable solely through file existence.
- Verify the integration's expected owner, restrictive permissions, regular-file status, and cryptographic integrity before execution.
- Resolve the canonical path and reject symbolic links or paths that escape the trusted integration directory.
- Ensure that neither the external script nor its parent directories are writable by untrusted users.
- Prefer a reviewed internal notification implementation or a narrowly scoped API client over executing another shell script.
- Clearly document outbound notification behavior and the exact data transmitted. Obtain explicit consent before sending reports.
- Minimize report contents and omit unnecessary local filesystem paths or sensitive diagnostic information.
- Execute the notification component with reduced privileges and a sanitized environment if external execution remains necessary.
