T09 · Insecure Skill Coding Practices
- Location
scripts/start-browser.sh:20- Finding
Chromium Runs as Root with Its Security Sandbox Disabled
- Content
View full analysis
"$LOG_FILE" 2>&1 & ``` The insecure configuration is also explicitly recommended in `SKILL.md`, lines 41-48, and `references/troubleshooting.md`, lines 17-20. ### Technical Analysis The script launches Chromium with `--no-sandbox`. The project documentation specifically recommends this configuration when OpenClaw or Chromium runs as root. Chromium's sandbox is a defense-in-depth boundary intended to isolate browser renderer processes and web content from the operating-system account running the browser. Disabling it means that exploitation of a browser or renderer vulnerability may provide direct access to the privileges of the Chromium process rather than requiring a separate sandbox escape. The risk is especially significant in the documented root-run workflow. Browser automation is expected to visit and interact with external web pages, including potentially attacker-controlled content. The CDP endpoint also offers extensive browser-control capabilities, although the script's own health check accesses it through loopback. ### Attack Path 1. OpenClaw or an operator invokes `scripts/start-browser.sh` as root. 2. The script starts Chromium with `--no-sandbox`. 3. The automated browser visits an attacker-controlled or compromised web page. 4. The page exploits a Chromium renderer or browser-process vulnerability. 5. Because the sandbox is disabled, the exploit executes with the privileges of the Chromium process. 6. In the documented root-run scenario, the attacker may consequently execute commands, read or modify files, access browser data, or al ...[truncated 836 chars]- Remediation
View remediation
&2 exit 1 fi ``` 4. If an exceptional environment requires `--no-sandbox`, require an explicit opt-in variable and display a prominent security warning rather than enabling it automatically. 5. Place the browser inside an additional isolation boundary, such as a tightly configured container or sandbox with: - No unnecessary host mounts. - A read-only root filesystem where practical. - Dropped Linux capabilities. - Seccomp and mandatory access-control policies. - Restricted network access. 6. Use a separate browser profile with restrictive filesystem permissions and avoid storing privileged authentication material in that profile. 7. Update `SKILL.md` and `references/troubleshooting.md` so that root execution without a sandbox is described as a last-resort unsafe mode, not the preferred configuration. ]]>
