T09 · Insecure Skill Coding Practices
- Location
scripts/sync-acp-to-main.py:118- Finding
Path Traversal Through Unvalidated Session and Agent Identifiers
- Content
View full analysis
3 else None main_agent = sys.argv[4] if len(sys.argv) > 4 else None success = sync_acp_to_main( acp_sid, acp_agent=acp_agent, main_agent=main_agent, main_session_id=main_sid ) ``` ### Technical Analysis The script embeds caller-controlled agent and session identifiers directly into filesystem paths. It does not validate identifiers as UUIDs or safe agent names, canonicalize the resulting paths, or verify that resolved paths remain beneath the intended `~/.openclaw/agents//sessions` directo ...[truncated 2248 chars]- Remediation
View remediation
