T07 · Tool Hijacking and Spoofing
- Location
scripts/find_auth_skill.py:32- Finding
Authentication Helper Discovery Can Execute a Spoofed Skill Script
- Content
View full analysis
Vulnerability Details
File Location:
scripts/find_auth_skill.py:32-48, with the execution sink atscripts/dmp_api_client.py:47-55
Vulnerability Type: Untrusted tool discovery and execution
Risk Level: HighComplete Code Snippet
Discovery logic in
scripts/find_auth_skill.py:python scan_dirs = [ Path.home() / ".skills", Path.home() / ".openclaw" / "workspace" / "skills", Path.home() / ".openclaw" / "skills", Path.cwd() / ".skills", ] for scan_dir in scan_dirs: if scan_dir.exists(): for skill_dir in scan_dir.iterdir(): if skill_dir.is_dir(): auth_path = skill_dir / "scripts" / "minri_dmp_api.py" if auth_path.exists(): try: with open(auth_path, 'r', encoding='utf-8') as f: content = f.read(500) if "明日DMP" in content or "mingdata" in content.lower(): return auth_path except (OSError, UnicodeDecodeError): continueExecution sink in
scripts/dmp_api_client.py:python def _call(self, method: str, endpoint: str, body: Optional[Dict[str, Any]] = None) -> Dict[str, Any]: """通过subprocess调用鉴权技能的minri_dmp_api.py""" cmd = ["python3", str(self.auth_skill_path), method.upper(), endpoint] if body is not None: cmd.append(json.dumps(body, ensure_ascii=False)) result = subprocess.run( cmd, capture_output=True, text=True, timeout=self.timeout )Technical Analysis
The fallback discovery mechanism scans every immediate child directory under several skill roots, including
.skillsbeneath the current working directory. It does not require the child directory to be namedmingdata-dmp-auth. A candidate is accepted merely because it containsscripts/minri_dmp_api.pyand one of two easily forged strings appears in the first 500 characters.DmpClientsub ...[truncated 1867 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the keyword-based dynamic scan and only accept the exact canonical installation path for
mingdata-dmp-auth. - Resolve the selected path with
Path.resolve()and verify that it remains beneath the expected trusted skill directory. - Reject symlinks and files or parent directories writable by unauthorized local principals.
- Verify the helper against a trusted signed manifest or pinned cryptographic digest before execution.
- Validate package metadata and require the skill directory name and identifier to match
mingdata-dmp-auth. - Do not search relative to
Path.cwd()for authentication code. - Prefer importing or invoking the helper through a trusted registry that returns verified package identities rather than searching the filesystem.
- Fail closed when the verified helper is unavailable instead of selecting a loosely matched replacement.
- Remove the keyword-based dynamic scan and only accept the exact canonical installation path for
