Back to skill

Security audit

Windows Native Dialog

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for a Windows file-dialog workaround, but it asks for broad persistent tool permissions and host PowerShell execution without enough scoping or user-control guidance.

Use this only if you specifically need a WSL2 workaround for Windows native file dialogs. Before installing or following it, restrict permissions where possible, review the exact PowerShell/Python script being run, use fixed file paths or trusted inputs, require confirmation before publishing, and restore tool permissions after the task.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:16
Finding

Overly Broad Tool Permissions Violate Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 16
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Vulnerable Code:

text
openclaw config set tools.allow '["browser","group:runtime","group:fs","group:web"]'

Technical Analysis

The Skill directs users to enable broad browser, runtime, filesystem, and web tool groups. The documented workflow only requires browser automation and execution of a specific local helper, so unrestricted filesystem and web capabilities are not adequately justified.

This configuration breaks the principle of least privilege by combining capabilities that can read local data, execute commands, and communicate with external systems. If malicious or attacker-controlled content later influences the Agent, these permissions could be chained to perform actions beyond native file-dialog handling. Because the instruction modifies the OpenClaw configuration rather than describing a narrowly scoped, one-time grant, the enlarged permission boundary may also remain available after the immediate workflow unless explicitly reverted.

Attack Path

  1. A user installs or follows the Skill and executes the documented tools.allow configuration command.
  2. The Agent gains access to broad runtime, filesystem, browser, and web tool groups.
  3. Attacker-controlled web content, a malicious prompt, or another untrusted task influences the Agent while those permissions are enabled.
  4. The influenced Agent uses filesystem access to inspect files beyond the intended upload target.
  5. Runtime access is used to execute additional local commands, or web access is used to transmit collected information to an external endpoint.
  6. The unintended access can continue in subsequent operations if the configuration remains enabled.

Impact Assessment

Successful exploitation could provide access to files available under the Agent's operating-system ...[truncated 393 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace broad tool-group grants with an allowlist containing only the exact browser operation and executable required by this workflow.
  • Remove group:web unless an explicit, documented network operation is necessary.
  • Restrict filesystem access to the intended upload file or a dedicated upload directory.
  • Restrict runtime execution to the exact PowerShell executable and a reviewed helper script with fixed arguments.
  • Require explicit user confirmation before running the helper command and before publishing content.
  • Save the prior tool configuration and restore it immediately after the workflow completes.
  • Include the referenced helper script in the audited package, pin its path, and validate or safely quote all filename arguments before passing them to PowerShell.
  • Document the minimum required permissions and fail closed when those scoped permissions are unavailable.
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to invoke Windows PowerShell from WSL2 via exec, which crosses a trust boundary and enables arbitrary host command execution. Even though the example command is simple, the skill provides no warning, validation guidance, or constraints on what may be executed, so a user or downstream agent could adapt this pattern into unsafe command execution on the Windows host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.