T09 · Insecure Skill Coding Practices
- Location
scripts/case_generator.py:88- Finding
Spreadsheet Formula Injection in Generated Excel Workbooks
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent, but it can overwrite existing test-case spreadsheets and persist PRD-derived files locally without strong safeguards, so it belongs in Review before installation.
Install only if you are comfortable with a Chinese-language testcase workflow that reads local PRDs and configured Excel case libraries, writes generated files and PRD-derived notes under ~/.openclaw/workspace, and may update configured case-library spreadsheets in place. Use backups before running updates, review product config paths, avoid untrusted PRD content in generated spreadsheets, and inspect generated files before opening them in Excel.
scripts/case_generator.py:88Spreadsheet Formula Injection in Generated Excel Workbooks
scripts/case_generator.py:110Output Path Traversal Through Unsanitized Requirement Name
scripts/version_manager.py:58Product Identifier Path Traversal Can Load Out-of-Root Configuration
If the actual skill modifies existing case-library Excel files and local metadata instead of generating separate output files as documented, users may authorize a seemingly safe export workflow while the skill performs destructive in-place changes. That mismatch can lead to silent corruption of trusted test repositories or unintended persistence of user data.
If the actual skill modifies existing case-library Excel files and local metadata instead of generating separate output files as documented, users may authorize a seemingly safe export workflow while the skill performs destructive in-place changes. That mismatch can lead to silent corruption of trusted test repositories or unintended persistence of user data.
The skill description and examples are entirely in Chinese and present the workflow as Chinese-only, with no indication that users may choose another language. This can violate language/locale policy when a specific language is imposed without user opt-in or justification.
The skill describes file reads and writes across the user's home/workspace but does not declare any explicit tool scope or permissions boundaries. This creates an authorization gap where a caller may not understand that the skill can access and persist local files, increasing the chance of unintended data exposure or modification.
The trigger phrases are generic requests like '帮我写测试用例' and '分析这个需求的测试点', which can match ordinary conversations too broadly. In a skill with file access and persistent writes, overbroad activation increases the risk that the skill runs unexpectedly on sensitive PRDs or creates files without the user realizing a side-effecting workflow was invoked.
The skill specifies creating multiple markdown and Excel files under the user's workspace, but it does not present a clear upfront warning that execution will persist potentially sensitive PRD content and derived analysis. Users may disclose confidential product plans assuming transient processing, while the skill silently leaves recoverable artifacts on disk.
The instructions direct the skill to save PRD summaries, test-point analyses, and comparison reports into a long-lived workspace under the user's home directory. PRDs often contain unreleased features, pricing, interfaces, or customer-specific details, so persisting this content by default increases the chance of later disclosure to other tools, users, backups, or compromised local environments.
The format rules require Chinese full-width brackets and Chinese numbering/style conventions, effectively forcing a specific language/locale in the skill output. Because the document does not offer user opt-in or explain that the skill is intentionally limited to a Chinese-language test-case environment, this is a natural-language locale policy concern.
Natural-language content in the file—including the main docstring and inline usage guidance—appears exclusively in Chinese, with no indication that the skill is intentionally limited to a Chinese-speaking audience or that users can opt into another language. The policy requires avoiding forced language or locale unless it is optional or clearly justified.
This file contains user-facing natural-language instructions entirely in Chinese, including the top-level usage docstring and later CLI descriptions, but it does not offer any language selection or indicate that the tool is intentionally limited to a Chinese-speaking audience. That can violate a language/locale policy requiring user choice rather than forcing a specific language by default.
技能清单描述强调的是基于已有用例库和 PRD 进行分析并生成新增/更新两个 Excel 结果文件,而本文件提供的是对既有用例库按 UUID 直接覆盖并保存到原文件的版本管理能力。此外,L139-L142 还会将版本信息写入用户主目录下的元数据文件,这属于额外的持久化副作用,不是描述中显式声明的产出。
manifest 描述的核心目标是生成并区分新增、更新的用例结果文件;而 update_library 会直接打开目标 Excel 用例库、按 UUID 覆盖内容并保存回原路径。这种维护主数据源的写操作更像后台库管理能力,而不是单纯生成输出文件所必需的能力。
The update operation directly overwrites and appends rows in the configured workbook and saves back to the original path with no confirmation, backup, rollback, or integrity validation. In a skill ecosystem where actions may be triggered by user-provided files or automated agent flows, this increases the risk of silent data corruption or irreversible modification of a shared testcase library.
The markdown states that output files are saved to ~/.openclaw/workspace/, which is a user-data affecting operation. While the destination is documented, there is no explicit warning or caution about creating files there or potential overwrites/conflicts with existing files.
The document mandates Chinese-specific conventions such as full-width Chinese brackets and Chinese naming/path conventions, but it does not state that this applies only in a Chinese-language or region-specific workflow. Under the policy, forcing a specific language or locale without opt-in or clear justification can be a natural-language policy issue.
This code performs a filesystem write by saving a generated workbook to a path under the user's workspace, but there is no confirmation prompt, logging, or explicit warning in the function before the write occurs. For code files, file writes should have some form of user disclosure unless the behavior is clearly surfaced; here the side effect is only implied by the function name and docstring, not actively disclosed at execution time.
The function creates directories and writes an output .xlsx file, but it does so silently with no user-facing print/log message or confirmation around the file write. Under the code-file criteria, safety-relevant file writes lacking any visible disclosure should be flagged.
文件头部文档明确声明这是“用例库版本管理工具”,并列出接收增量更新文件、按 UUID 覆盖现有用例等功能;这与技能清单中“针对已有用例库和 PRD 分析交互,最终输出生成的用例”的生成型定位存在明显意图偏移。虽然文档与代码本身一致,但它主动呈现了与技能对外宣称不同的用途。
No suspicious patterns detected.