T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
Ambiguous Commands Can Trigger Global Modification of Credential-Bearing OpenClaw Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a legitimate model-switching purpose, but it can persistently rewrite the global OpenClaw model setting from ambiguous words while giving inconsistent scope disclosure.
Review before installing. This skill should only be used if you are comfortable with persistent global OpenClaw model changes that may affect cost and future sessions. Prefer using explicit slash commands, confirm before any write, back up ~/.openclaw/openclaw.json, and avoid exposing the full config or API keys in chat, logs, or errors.
SKILL.md:39Ambiguous Commands Can Trigger Global Modification of Credential-Bearing OpenClaw Configuration
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
If `switch-modes.json` gets corrupted:
1. Delete it: `rm ~/.openclaw/workspace/switch-modes.json`
2. Run `/modes setup` to recreate
3. Or manually create with valid JSON structure (see above)
The reference explains direct modification of the global OpenClaw config before prominently warning that the change affects all sessions. Users may reasonably assume the change is local to the current conversation, leading to cross-session behavior changes, unexpected cost increases, or weaker models being selected for unrelated sensitive work.
The skill persists mode configuration in workspace and global config files, and the documentation encourages recreating or updating those files without discussing lifecycle, rollback, or cleanup. Persistent state can silently influence future sessions and users, making behavior changes durable beyond the immediate task.
2. Check `~/.openclaw/workspace/switch-modes.json` exists and is valid JSON
3. Check `~/.openclaw/openclaw.json` was actually updated
4. Verify file permissions (should be readable/writable)
5. Try `/modes setup` again to recreate config
**Common causes:**
- JSON syntax error in config file
The guide says the agent 'scans user message for mode keywords' but does not clearly constrain when switching should occur, what exact commands are authoritative, or what contexts must be excluded. That ambiguity can cause unintended model changes from incidental text, quoted content, or prompt-injected instructions, altering agent behavior and cost/security posture without explicit user intent.
The skill triggers on standalone words like "eco", "balanced", "smart", and "max", which are common in normal conversation and can cause accidental activation. Because this skill performs configuration changes that persist by rewriting the OpenClaw model setting, overly broad matching can lead to unintended model switches, cost changes, or degraded performance without clear user intent.
The skill instructs the agent to write directly to ~/.openclaw/openclaw.json, creating persistent session configuration changes. Persistent modification is risky because an accidental or mis-triggered activation will outlive the current exchange and silently alter future model behavior, including potentially increasing cost or changing trust/performance characteristics.
Update OpenClaw config:
~/.openclaw/openclaw.jsonmodel field with the new model ID~/.openclaw/openclaw.jsonConfirm to user:
No suspicious patterns detected.