T09 · Insecure Skill Coding Practices
- Location
scripts/fix-all.sh:49- Finding
Predictable Temporary Files Allow Symlink-Based File Clobbering
- Content
View full analysis
/tmp/openclaw_cron_fixed.json FIXED_PEER=$(cat /tmp/openclaw_cron_fixed.json | jq '[.jobs[] | select(.delivery.peer != null)] | length') if [ "$FIXED_PEER" -eq 0 ]; then mv /tmp/openclaw_cron_fixed.json "$JOBS_FILE" fi ``` From `scripts/fix-all-safe.sh`: ```bash TEMP_FILE="/tmp/openclaw_cron_fixed_$$.json" WORK_FILE="$TEMP_FILE" cp "$JOBS_FILE" "$WORK_FILE" jq '( .jobs | map( if .delivery.peer != null then .delivery.to = ("chat:" + .delivery.peer.id) | del(.delivery.peer) | . else . end ) ) | {jobs: .}' "$WORK_FILE" > "$TEMP_FILE.tmp" if [ -s "$TEMP_FILE.tmp" ]; then mv "$TEMP_FILE.tmp" "$WORK_FILE" fi ``` From `scripts/fix-all-with-validation.sh`: ```bash TEMP_FILE="/tmp/openclaw_cron_fixed_$$.json" ... if "$VALIDATE_SCRIPT" "$WORK_FILE" 2>&1 | tee /tmp/validate_output_$$.txt; then ``` The documentation also recommends a fixed path: ```bash jq '...' ~/.openclaw/cron/jobs.json > /tmp/jobs_pending.json ~/.openclaw/skills/cron-helper/scripts/validate-jobs-syntax-v2.sh /tmp/jobs_pending.json mv /tmp/jobs_pending.json ~/.openclaw/cron/jobs.json ``` ### Technical Analysis The scripts create working and output files in the shared `/tmp` directory using fixed names or names based only on the process ID. They do not use `mktemp`, exclusive creation, a private temporary directory, or symlink checks. Shell output redirec ...[truncated 2030 chars]- Remediation
View remediation
