T09 · Insecure Skill Coding Practices
- Location
scripts/generate_workflow.py:287- Finding
Unescaped Task Input Allows JavaScript Injection in Generated Workflows
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly matches its stated workflow-generation purpose, but its generated executable JavaScript can be injected through task text and it writes files to broad or hard-coded paths.
Review generated .js files before running them, avoid untrusted task descriptions, and always pass an explicit output directory. This is suitable only if you accept local file generation and Chinese-language tooling.
scripts/generate_workflow.py:287Unescaped Task Input Allows JavaScript Injection in Generated Workflows
scripts/analyze_subagents.py:74Unnecessary Full Read of Persistent Agent Memory
scripts/security_check.py:189Security Checker Fails Open on Malformed Workflow Fields
If the skill's real function is static security checking plus local report generation, but that output behavior is not disclosed, users may invoke it in sensitive workspaces without understanding that new files will be created. Undeclared report writing can leak data into persisted artifacts, interfere with repositories, or create files that downstream automation mistakenly trusts.
If the skill's real function is static security checking plus local report generation, but that output behavior is not disclosed, users may invoke it in sensitive workspaces without understanding that new files will be created. Undeclared report writing can leak data into persisted artifacts, interfere with repositories, or create files that downstream automation mistakenly trusts.
If the skill's real function is static security checking plus local report generation, but that output behavior is not disclosed, users may invoke it in sensitive workspaces without understanding that new files will be created. Undeclared report writing can leak data into persisted artifacts, interfere with repositories, or create files that downstream automation mistakenly trusts.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
try:
if rule.get("is_batch_check"):
return False # 批量检查单独处理
return rule["check"](agent)
except Exception as e:
return False
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
try:
if rule.get("is_batch_check"):
return False # 批量检查单独处理
return rule["check"](agent)
except Exception as e:
return False
This markdown file contains user-facing instructions exclusively in Chinese, and there is no note offering an alternate language or clarifying that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The skill advertises and demonstrates shell execution and file read/write workflows, but the manifest does not declare any corresponding tool scope such as permissions or allowed-tools. This creates an authority mismatch where operators may trust the metadata while the skill content encourages broader capabilities, increasing the chance of unintended file or command access when integrated into an agent runtime.
This markdown file contains user-facing natural-language content that effectively forces a specific language/locale for understanding and use. The policy allows language constraints only when the skill offers opt-in choice or clearly documents a justified regional limitation, which is not present here.
The document states a hard concurrency safety rule of at most 3 subagents, yet the security-check output later says 4 concurrent agents are acceptable. Contradictory security guidance can cause operators or code generators to exceed intended safety limits, leading to resource exhaustion, monitoring blind spots, or policy bypass in multi-agent execution.
The manifest promises automatic analysis of multiple sub-agents' capabilities, usage patterns, collaboration relationships, and intelligent recommendation of collaboration modes and workflow/security configuration. In code, analysis is limited to substring checks in one docs file, a simple MEMORY.md marker check, static role metadata, and generic model/category recommendations; it does not infer collaboration patterns, recommend parallel/serial/hierarchical modes, or generate workflow/security configurations.
The module docstring describes the tool as scanning configured sub-agent roles, analyzing distributions and usage, and providing recommendations. However, the implementation also creates a new directory and persists a JSON report under the workspace, which is a state-changing file write not mentioned in the stated functionality.
Natural-language strings in the CLI description, argument help, headers, and generated task content are hardcoded in Chinese, which imposes a specific language on users. The policy allows locale constraints only when documented and justified or when the user can opt in, neither of which is present here.
The --output argument allows writing workflow and code files to an arbitrary filesystem path without confinement to a dedicated workspace. If this script is invoked by another agent or automation with attacker-controlled arguments, it can overwrite sensitive files or plant executable artifacts in unintended locations, which is broader access than needed for this skill’s stated purpose.
The script does more than generate analysis metadata: it also emits executable JavaScript workflow code and writes it to disk automatically. In a skill intended for collaboration analysis/design, producing runnable artifacts increases the chance that unsafe or unreviewed task content is operationalized directly, especially because the generated code spawns agent sessions from user-influenced prompts.
The script hard-codes a workspace path and, when no --output is provided, writes reports there automatically. For a security-checking skill, this expands behavior from analysis into persistent filesystem modification, which can leak workflow metadata into an unexpected location and create side effects outside the caller’s explicit intent.
The fixed path /Users/nanlin/.openclaw/workspace assumes access to a specific user’s local workspace and is unrelated to the minimal task of validating a workflow JSON. This can cause unauthorized writes, disclosure of sensitive task/report contents into a personal workspace, and unsafe behavior when run in other environments.
The code creates parent directories and saves a report file automatically even when the user did not explicitly request persistence. In the context of an analysis skill, automatic filesystem writes broaden the operational scope and can leave sensitive artifacts or overwrite expected workspace state.
该段标题和前文规则都强调超时控制,且 L402 写明应满足 timeoutSeconds ≤300。可是在“❌ 超长超时”示例中,代码给出 3600 秒,而注释却写“>1000 秒”,这与文档其他位置使用的 300 秒基线不一致,容易混淆真正的禁止阈值。虽然这是注释层问题,但它直接影响安全规则理解。
The manifest description is written entirely in Chinese, which creates a language-specific user experience without any indication that users can choose another language or that the skill is intended only for a Chinese-speaking context. This is a natural-language policy concern because the file presents a fixed locale implicitly rather than offering opt-in or justification.
The workflow metadata records safety_check as pending, yet the script immediately writes both the workflow and executable JavaScript to disk. This creates a misleading trust signal that may cause downstream tooling or users to assume the artifact is awaiting validation when it already exists in runnable form.
The module docstring and CLI description are primarily in Chinese, and later user-facing messages are also emitted in Chinese. Because the tool does not provide any opt-in or selection mechanism for language/locale, it effectively forces a specific language for users.
No suspicious patterns detected.