Back to skill

Security audit

storage-router

Security checks for vulnerabilities and agentic risk

Overview

This storage-routing skill is mostly purpose-aligned, but it includes unsafe local configuration loading and broad persistence routing that users should review before installing.

Install only if you are comfortable with this skill influencing where saved content goes across monday.com, GitHub-backed memory, and local files. Before use, replace the shell source pattern with a safe config parser and require explicit confirmation before sending or persisting content outside the current workspace.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:78
Finding

Arbitrary Shell Execution Through Unsafe Configuration Sourcing

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 78–83
Vulnerability Type: Unsafe shell evaluation of a configuration file
Risk Level: High

Vulnerable Code

bash
CONTEXT_FILE="/opt/ocana/openclaw/workspace/skills/storage-router/.context"
[ -f "$CONTEXT_FILE" ] && source "$CONTEXT_FILE"
# Then use: $WORKSPACE_ID, $FOLDER_RESEARCH, $DOC_COMPETITIVE_ANALYSIS, etc.

Technical Analysis

The documented initialization procedure uses the shell built-in source to load .context. Contrary to parsing a passive key-value configuration format, source evaluates all file contents as shell code in the current process.

Consequently, any party capable of modifying /opt/ocana/openclaw/workspace/skills/storage-router/.context can inject shell expressions or commands. Those commands will execute with the privileges and environment of the agent or operator following this procedure. The existence check does not validate file ownership, permissions, content, or expected variable names and therefore does not mitigate this risk.

Attack Path

  1. An attacker gains write access to the fixed .context path, such as through insecure file permissions, a compromised synchronization workflow, or another process operating under the same account.
  2. The attacker adds shell commands to .context, potentially alongside legitimate workspace variables to avoid detection.
  3. The agent or operator runs the documented initialization command.
  4. The shell evaluates the attacker-controlled commands through source.
  5. The injected commands execute with the invoking account's privileges and can access resources available to that account.

Exploitation depends on the attacker first obtaining the ability to modify .context; the audited project does not establish whether that prerequisite exists in a deployment.

Impact Assessment

Successful exploitation permits arbitrary command execution under the invoking agent account. The attacker could read or ...[truncated 279 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not execute configuration data with source, eval, or equivalent shell-evaluation mechanisms.
  • Parse only an explicit allowlist of required keys, such as WORKSPACE_ID, FOLDER_RESEARCH, and DOC_COMPETITIVE_ANALYSIS.
  • Enforce strict value formats for every field. For identifier fields, accept only the expected numeric or otherwise narrowly defined syntax.
  • Reject unknown keys, malformed lines, command substitutions, shell metacharacters, and duplicate definitions.
  • Before reading the file, verify that it is a regular file, is owned by the expected account, is not a symbolic link, and is not writable by group or other users.
  • Store sensitive configuration outside repositories and synchronized directories. Apply restrictive permissions, such as owner read/write access only.
  • Prefer a non-executable format such as JSON and parse it with a data parser rather than a shell.
  • Document failure behavior so missing or invalid configuration causes a safe stop instead of falling back to untrusted values.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad enough to match ordinary user requests such as 'save this' or 'document this', which can cause the skill to activate in unintended contexts. Because this skill influences persistence destinations, accidental invocation could route sensitive or irrelevant information to monday.com, local files, or memory stores without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill instructs the agent to source a local .context file and references handling of credentials/config without explicit safeguards, least-privilege guidance, or user-facing warnings about sensitive data access. In an agentic environment, this can normalize reading local sensitive configuration and increase the chance of exposing internal IDs, tokens, or other secrets through subsequent tool use or output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.