T09 · Insecure Skill Coding Practices
- Location
tools/exec_tools.py:65- Finding
Unrestricted Shell Command Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill openly provides powerful local tools, but they are broad enough to run commands, delete files, use sudo, send network requests with credentials, and persist memory without clear safeguards.
Install only if you intend to give this skill broad local-machine authority. Use it in a sandboxed workspace with an unprivileged account, avoid entering sudo passwords or API credentials, and treat natural-language delete, shell, Git push, and network/API requests as high-risk operations that need manual review.
tools/exec_tools.py:65Unrestricted Shell Command Execution
tools/exec_tools.py:326Privileged Command Injection and Sudo Password Exposure
tools/file_tools.py:55Unconfined Arbitrary Filesystem Read, Write, and Deletion
tools/web_tools.py:306Server-Side Request Forgery and Credential Transmission to Arbitrary URLs
tools/session_tools.py:152Python Code Injection Through Session Message Construction
The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.
The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.
The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.
The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.
The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.
The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.
The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.
The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.
The documentation explicitly exposes risky capabilities such as shell_sudo, background process execution, process killing, and system information collection, yet those high-risk actions are not paired with explicit permission declarations or strong warnings. In a skill ecosystem, under-declared privileged and destructive operations increase the chance of unsafe use, privilege abuse, or accidental system damage.
Referenced artifact was not completely inspected
[](./SKILL.md)
The discovery logic loads every non-underscored .py file from user-writable locations, including ~/.openclaw/tools and the current working directory, then executes the module via spec.loader.exec_module(). Import-time code in those files runs immediately, so merely triggering discovery can execute arbitrary Python code planted by a local attacker, a malicious repository, or an untrusted workspace. In this skill context, the package explicitly enhances agent tooling and auto-discovers tools, which makes this especially dangerous because users may run it in varied directories and may not realize discovery is equivalent to code execution.
This finding points to the same weak denylist logic around 'rm -rf /'. The issue is not the literal string itself but that the security model depends on brittle pattern matching while still permitting arbitrary command execution.
try:
# 安全检查:禁止危险命令
dangerous = ["rm -rf /", "mkfs", "dd if=/dev/zero", ":(){:|:&};:"]
for d in dangerous:
if d in command:
return ToolResult(success=False, error=f"危险命令被拒绝: {d}")
This finding points to the same weak denylist logic around 'rm -rf /'. The issue is not the literal string itself but that the security model depends on brittle pattern matching while still permitting arbitrary command execution.
try:
# 安全检查:禁止危险命令
dangerous = ["rm -rf /", "mkfs", "dd if=/dev/zero", ":(){:|:&};:"]
for d in dangerous:
if d in command:
return ToolResult(success=False, error=f"危险命令被拒绝: {d}")
Copying the full parent process environment into shell-executed commands can expose sensitive secrets such as API keys, tokens, and credentials to arbitrary commands. In a tool that already permits arbitrary command execution, inheriting all environment variables materially increases blast radius and data-exfiltration risk.
return ToolResult(success=False, error=f"危险命令被拒绝: {d}")
# 构建环境
cmd_env = os.environ.copy()
if env:
cmd_env.update(env)
This tool executes attacker-controlled commands via sudo and even supports passing a sudo password, all without an approval barrier. In agent contexts this is extremely dangerous because it enables privilege escalation, arbitrary root command execution, and likely credential exposure through process invocation patterns and logs.
The shell pipeline 'echo ... | sudo -S {command}' chains multiple sensitive operations and embeds untrusted command text directly into a shell string. This enables command chaining/injection and privileged execution in a single step, greatly amplifying the consequences of parameter abuse.
# 如果提供了密码,使用 -S 从 stdin 读取
if password:
full_cmd = f"echo {shlex.quote(password)} | sudo -S {command}"
else:
full_cmd = sudo_cmd
The script runner inherits the complete process environment before launching potentially untrusted scripts. That can leak secrets to executed code and enable abuse of tokens, cloud credentials, or internal endpoints available via environment variables.
cmd = [interpreter, str(script_path)] + args
# 环境变量
cmd_env = os.environ.copy()
if env:
cmd_env.update(env)
The regex-edit branch is implemented incorrectly: pattern.sub(new_text, content if global_replace else new_text, ...) uses new_text as the replacement target when global_replace is false, rather than the file content. That can cause the tool to discard the original file body and write only new_text, creating unintended destructive file modification. In this skill context, a general-purpose file editing tool is high risk because agents may use it on source code, configs, or system files.
The intent rules map natural-language input directly to shell_exec for commands like ls, cd, pwd, cat, rm, mkdir, touch, and echo, and also accept broad '执行/运行 ...' patterns. This allows arbitrary or destructive shell actions to be triggered from loosely parsed user text without confirmation, allowlisting, or safety checks, which is especially dangerous because natural-language interfaces increase the chance of accidental execution.
The pattern '删除 /absolute/path' is translated directly into file_delete on a resolved absolute path with no warning, policy check, or confirmation. A user can accidentally or maliciously delete sensitive files anywhere accessible to the process, and path resolution makes targeting system locations straightforward.
The calculator tool evaluates user-controlled input with Python eval(). Although the code restricts input to digits and arithmetic characters, using eval on untrusted input is still an unsafe pattern because it can enable denial-of-service via extremely expensive expressions and can become code execution if the filter is later weakened or bypassed. In a tool framework that exposes execution-like capabilities, this pattern increases risk because it may be reused or extended unsafely.
if not all(c in allowed_chars for c in expression):
return ToolResult(success=False, error="包含不允许的字符")
result = eval(expression) # 注意:生产环境应该用 ast 解析
return ToolResult(success=True, data=result)
except Exception as e:
return ToolResult(success=False, error=str(e))
The README explicitly states that natural-language requests will automatically invoke sensitive tools such as file reads, shell execution, network access, Git push, and memory operations, but it does not describe confirmation prompts, scope restrictions, or safety interlocks. In an agent skill context, documenting seamless automatic execution of destructive or exfiltration-capable actions increases the risk of prompt-triggered misuse, accidental command execution, or unauthorized data access.
The skill advertises and demonstrates access to sensitive capabilities including file read/write, shell execution, network access, Git operations, and even sudo-style execution, but does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch weakens reviewability and policy enforcement, making it easier for a powerful skill to be installed or invoked without clear operator awareness of its effective privileges.
The documentation prominently lists destructive and privileged capabilities including file deletion, shell execution, background tasks, process killing, sudo execution, Git push/pull, and agent delegation, but does not clearly warn users about their risks or safe operating expectations. In a skill meant for natural-language invocation, this is especially dangerous because casual phrasing could trigger impactful operations on the local system or remote repositories.
Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.
for module_name, var_name in tool_modules:
try:
module = __import__(module_name, fromlist=[var_name])
tool_classes = getattr(module, var_name, [])
if tool_classes:
Detected: suspicious.dynamic_code_execution