T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:36- Finding
Execution of Unbundled Script from a Mutable Global Installation Path
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 36-37 and 81-86
Vulnerability Type: T07: Tool Hijacking and Spoofing
Risk Level: MediumVulnerable Code
text Step 1 — Run the analyzer script via bash tool: python3 ~/.npm-global/lib/node_modules/openclaw/skills/btc-analyzer/analyze.pytext - Always run the script via bash tool — never fabricate or guess output values. - Do not hardcode prices or decisions. - If script fails, show the actual error message to the user. - This skill uses Binance public API only — no API key or authentication required. - Data is real-time; do not cache or reuse previous results.Technical Analysis
The Skill requires the agent to execute
analyze.pyfrom a mutable global npm installation directory. That script is not included in the audited project, which contains onlySKILL.md. The executable code and its asserted behavior therefore cannot be verified as part of this audit.The fixed path does not establish the script's provenance or integrity. Any process or user capable of modifying that global installation can replace the expected analyzer with different Python code. The instruction to “always run” the script then provides a legitimate-looking execution path for the substituted implementation. Claims that the script only uses Binance's public API, requires no credentials, and emits a specific JSON structure are documentation assertions rather than enforceable controls.
Attack Path
- An attacker, compromised installer, or malicious package obtains write access to
~/.npm-global/lib/node_modules/openclaw/skills/btc-analyzer/analyze.pyor its parent directory. - The attacker creates or replaces
analyze.pywith attacker-controlled Python code. - A user requests BTC analysis, causing the Skill workflow to be activated.
- Following
SKILL.md, the agent invokes the global script through Bash withpython3. - Python executes ...[truncated 968 chars]
- An attacker, compromised installer, or malicious package obtains write access to
- Remediation
View remediation
Remediation Suggestions
- Bundle
analyze.pywithin the reviewed Skill package so the instructions and executable implementation are distributed and audited together. - Resolve the script path relative to the Skill's verified installation directory rather than using a mutable global npm path.
- Verify the bundled script's cryptographic hash or package signature before execution.
- Restrict file permissions so untrusted users and unrelated package installers cannot modify the script or its parent directories.
- Execute the analyzer with least privilege in a sandbox that limits filesystem access, environment-variable access, subprocess creation, and outbound networking.
- Apply an outbound network allowlist restricted to the documented Binance HTTPS endpoint.
- Validate the script's JSON output against a strict schema before presenting it to the user.
- Fail safely when the bundled script is missing or fails integrity validation; do not search for or execute an alternative script from global paths.
- Include the implementation and dependency metadata in future security reviews so its calculations, network behavior, and error handling can be verified.
- Bundle
