T09 · Insecure Skill Coding Practices
- Location
SKILL.md:78- Finding
Arbitrary Shell Execution Through Unsafe Configuration Sourcing
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 78–83
Vulnerability Type: Unsafe shell evaluation of a configuration file
Risk Level: HighVulnerable Code
bash CONTEXT_FILE="/opt/ocana/openclaw/workspace/skills/storage-router/.context" [ -f "$CONTEXT_FILE" ] && source "$CONTEXT_FILE" # Then use: $WORKSPACE_ID, $FOLDER_RESEARCH, $DOC_COMPETITIVE_ANALYSIS, etc.Technical Analysis
The documented initialization procedure uses the shell built-in
sourceto load.context. Contrary to parsing a passive key-value configuration format,sourceevaluates all file contents as shell code in the current process.Consequently, any party capable of modifying
/opt/ocana/openclaw/workspace/skills/storage-router/.contextcan inject shell expressions or commands. Those commands will execute with the privileges and environment of the agent or operator following this procedure. The existence check does not validate file ownership, permissions, content, or expected variable names and therefore does not mitigate this risk.Attack Path
- An attacker gains write access to the fixed
.contextpath, such as through insecure file permissions, a compromised synchronization workflow, or another process operating under the same account. - The attacker adds shell commands to
.context, potentially alongside legitimate workspace variables to avoid detection. - The agent or operator runs the documented initialization command.
- The shell evaluates the attacker-controlled commands through
source. - The injected commands execute with the invoking account's privileges and can access resources available to that account.
Exploitation depends on the attacker first obtaining the ability to modify
.context; the audited project does not establish whether that prerequisite exists in a deployment.Impact Assessment
Successful exploitation permits arbitrary command execution under the invoking agent account. The attacker could read or ...[truncated 279 chars]
- An attacker gains write access to the fixed
- Remediation
View remediation
Remediation Suggestions
- Do not execute configuration data with
source,eval, or equivalent shell-evaluation mechanisms. - Parse only an explicit allowlist of required keys, such as
WORKSPACE_ID,FOLDER_RESEARCH, andDOC_COMPETITIVE_ANALYSIS. - Enforce strict value formats for every field. For identifier fields, accept only the expected numeric or otherwise narrowly defined syntax.
- Reject unknown keys, malformed lines, command substitutions, shell metacharacters, and duplicate definitions.
- Before reading the file, verify that it is a regular file, is owned by the expected account, is not a symbolic link, and is not writable by group or other users.
- Store sensitive configuration outside repositories and synchronized directories. Apply restrictive permissions, such as owner read/write access only.
- Prefer a non-executable format such as JSON and parse it with a data parser rather than a shell.
- Document failure behavior so missing or invalid configuration causes a safe stop instead of falling back to untrusted values.
- Do not execute configuration data with
