T01 · Skill Instruction Hijacking
- Location
audit.sh:20- Finding
Agent prompt and command injection through an untrusted target path
- Content
View full analysis
"$REPORT_DIR/security.txt" 2>&1 & SEC_PID=$! ``` The same substitution pattern is used for the code-quality, documentation, and license sub-agents: ```bash --task "$(cat ~/.openclaw/workspace/skills/pre-publish-security/agents/code-quality.md | sed "s|{{TARGET}}|$TARGET_PATH|g")" ``` From `agents/security-auditor.md`: ```markdown **Target:** {{TARGET}} ## Commands to Run ```bash cd {{TARGET}} # Pattern scan grep -r -E "(github_pat_|ghp_|AKIA|api_key|apikey|Bearer|password=|pwd=)" . \ --exclude-dir=node_modules \ --exclude-dir=.git \ 2>/dev/null || true # Git history scan (last 10 commits) git log -p -10 | grep -E "(github_pat_|ghp_|AKIA|api_key|Bearer)" || true # Check for credential files find . -name ".env*" -o -name "*credentials*" -o -name "*.pem" | head -20 ``` ``` ### Technical Analysis `TARGET_PATH` is supplied by the caller and is substituted directly into natural-language agent instructions using `sed`. No canonicalization, control-character rejection, structured argument passing, or prompt-boundary protection is applied. A target value containing newline characters can add new instructions to the delegated task. Because the substituted value also appears in an unquoted `cd {{TARGET}}` shell example, shell metacharacters in the value can alter the command if the sub-agent executes the generated command block. The vulnerability crosses two interpretation boundaries: 1. The value is interpreted as part of an AI agent prompt. ...[truncated 1655 chars]- Remediation
View remediation
