T09 · Insecure Skill Coding Practices
- Location
测试中文/package_skill.py:75- Finding
Recursive Packaging May Disclose Sensitive Files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly a skill-authoring helper, but it can modify and package agent-skill files with weak scope controls and a packager that may include unintended private files.
Install only if you intentionally want an agent to create, edit, and package OpenClaw skills. Review every SKILL.md diff, use a dedicated target directory, keep secrets and local-only files out of skill folders, inspect the generated .skill archive before sharing, and do not treat the included official tag as proof of trusted OpenClaw provenance.
测试中文/package_skill.py:75Recursive Packaging May Disclose Sensitive Files
The declared description says this skill is for authoring, editing, improving, reviewing, auditing, cleaning up, restructuring, and validating AgentSkills. However, the actual code does not implement those editing or audit behaviors. Its primary function is to package an existing skill directory into a .skill archive after running validation. It creates output files on disk, walks directories, filters files, and writes a zip-format archive. While validation is loosely related to the declared purpose, the main behavior—building distributable packages—is a materially different capability not represented in the description. Therefore this is a clear description-to-behavior mismatch.
The declared description centers on authoring, editing, auditing, and restructuring AgentSkills and SKILL.md content. The actual code does not create or edit skills for users; instead, it is an automated unit/regression test module for packaging behavior. Its primary function is to verify that package_skill securely builds archives and handles symlinks, path traversal, nested files, and output-archive exclusion. That is a materially different purpose from skill creation or cleanup, so this is a clear description-behavior mismatch.
The declared description presents a broad skill-management capability: create, edit, improve, audit, tidy up, clean up, restructure, and validate AgentSkills. The supplied code only covers one narrow subset of that description: creating a new skill scaffold from a template. It does not inspect existing skills, modify SKILL.md files, move files, remove stale content, review or audit anything, or validate a skill against a specification. While 'create a new skill from scratch' is included in the description, the actual code's primary behavior is much narrower than the declared purpose, so the description does not accurately represent the code chunk as a whole.
The declared description frames the skill as an authoring/review/audit/cleanup tool for AgentSkills and SKILL.md files. The supplied code does not create, edit, improve, review, or restructure skills. Its primary function is to validate a skill folder and package it into a .skill file using zip compression. While validation is mentioned in the description, here it is only a prerequisite step supporting packaging, which is an undeclared and materially different primary capability. Therefore the description does not accurately represent the code's actual behavior.
The declared description presents a broad skill-authoring and maintenance capability: creating skills from scratch, editing/improving them, cleaning up directories, moving files, and auditing against the AgentSkills spec. The supplied code does not implement any write, modification, restructuring, or generation behavior. It only reads SKILL.md from a provided directory and performs a narrow validation of frontmatter presence, allowed keys, and basic constraints on name and description. While this limited validation partially overlaps with the phrase 'audit' or 'validate against the AgentSkills spec,' the overall declared purpose substantially overstates the implemented functionality and primary purpose of this code chunk.
The declared description focuses on authoring and maintaining skill contents and directories—creating new skills, editing SKILL.md, tidying structure, removing stale content, and auditing against the AgentSkills spec. The actual code does not create or modify skills in that way. Instead, it defines regression tests for a packaging module, verifying that packaging includes expected files and excludes unsafe symlinked or out-of-root content. This is a materially different primary purpose: testing secure packaging logic rather than editing or auditing skill definitions/content. While 'audit' appears in the description, the code is specifically about automated packaging security tests, which is an undeclared and distinct capability.
The declared description presents a skill whose primary purpose is to create, edit, review, audit, or restructure AgentSkills and related files. The actual code shown does not perform those authoring or cleanup tasks; instead, it is a test suite for a validation utility. While validation is mentioned in the description, this code specifically implements automated regression tests for validator behavior, which is a materially different purpose from directly creating or auditing skill contents. The filesystem use here is limited to temporary test setup and is consistent with testing, not with the declared editing/restructuring workflow. Therefore this is a meaningful description-behavior mismatch.
The skill explicitly instructs the agent to create and edit skill resources and SKILL.md, which is a self-modification capability. In an agent skill, self-modification is high risk because a prompted or compromised workflow could rewrite its own instructions or neighboring skills, weakening safeguards, persisting malicious changes, or altering future behavior.
1. Understand the skill with concrete examples
2. Plan reusable skill contents (scripts, references, assets)
3. Initialize the skill (run init_skill.py)
4. Edit the skill (implement resources and write SKILL.md)
5. Package the skill (run package_skill.py)
6. Iterate based on real usage
The 'Update SKILL.md' instruction directly authorizes rewriting the skill’s own control document. Because SKILL.md defines behavior and triggering context, allowing routine updates creates a persistence mechanism for accidental or adversarial prompt injection to modify future executions.
If you used `--examples`, delete any placeholder files that are not needed for the skill. Only create resource directories that are actually required.
#### Update SKILL.md
**Writing Guidelines:** Always use imperative/infinitive form.
This section explicitly instructs the agent to create and edit skills, including running initialization and packaging scripts and writing SKILL.md content. Because this is a meta-skill that changes agent behavior artifacts, it enables self-modification of future instructions and capabilities. In the presence of prompt injection or weak approval boundaries, a user could leverage this workflow to introduce unsafe instructions, broaden triggers, or persist malicious behavior into distributable skill packages.
1. Understand the skill with concrete examples
2. Plan reusable skill contents (scripts, references, assets)
3. Initialize the skill (run init_skill.py)
4. Edit the skill (implement resources and write SKILL.md)
5. Package the skill (run package_skill.py)
6. Iterate based on real usage
The 'Update SKILL.md' instruction directly tells the agent to modify the instruction file that controls future skill behavior. This is a classic self-modification sink: changing frontmatter affects activation, while changing the body affects operational behavior after triggering. Since the skill is specifically designed to rewrite skills, an attacker could use apparently benign requests to smuggle in unsafe routing language or operational instructions that persist beyond the current session.
If you used `--examples`, delete any placeholder files that are not needed for the skill. Only create resource directories that are actually required.
#### Update SKILL.md
**Writing Guidelines:** Always use imperative/infinitive form.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def test_skips_symlink_to_external_file(self):
skill_dir = self.create_skill("symlink-file-skill")
outside = self.temp_dir / "outside-secret.txt"
outside.write_text("super-secret\n")
link = skill_dir / "loot.txt"
out_dir = self.temp_dir / "out"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def test_skips_symlink_to_external_file(self):
skill_dir = self.create_skill("symlink-file-skill")
outside = self.temp_dir / "outside-secret.txt"
outside.write_text("super-secret\n")
link = skill_dir / "loot.txt"
out_dir = self.temp_dir / "out"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def test_skips_symlink_to_external_file(self):
skill_dir = self.create_skill("symlink-file-skill")
outside = self.temp_dir / "outside-secret.txt"
outside.write_text("super-secret\n")
link = skill_dir / "loot.txt"
out_dir = self.temp_dir / "out"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def test_skips_symlink_to_external_file(self):
skill_dir = self.create_skill("symlink-file-skill")
outside = self.temp_dir / "outside-secret.txt"
outside.write_text("super-secret\n")
link = skill_dir / "loot.txt"
out_dir = self.temp_dir / "out"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def test_skips_symlink_to_external_file(self):
skill_dir = self.create_skill("symlink-file-skill")
outside = self.temp_dir / "outside-secret.txt"
outside.write_text("super-secret\n")
link = skill_dir / "loot.txt"
out_dir = self.temp_dir / "out"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def test_skips_symlink_to_external_file(self):
skill_dir = self.create_skill("symlink-file-skill")
outside = self.temp_dir / "outside-secret.txt"
outside.write_text("super-secret\n")
link = skill_dir / "loot.txt"
out_dir = self.temp_dir / "out"
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Print next steps
print(f"\n[OK] Skill '{skill_name}' initialized successfully at {skill_dir}")
print("\nNext steps:")
print("1. Edit SKILL.md to complete the TODO items and update the description")
if resources:
if include_examples:
print("2. Customize or delete the example files in scripts/, references/, and assets/")
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Print next steps
print(f"\n[OK] Skill '{skill_name}' initialized successfully at {skill_dir}")
print("\nNext steps:")
print("1. Edit SKILL.md to complete the TODO items and update the description")
if resources:
if include_examples:
print("2. Customize or delete the example files in scripts/, references/, and assets/")
The skill instructs the agent to read and write files and execute local scripts (init_skill.py, package_skill.py) without declaring any explicit tool scope or restrictions. In a skill that can modify skill directories and package artifacts, missing scope increases the blast radius of accidental or prompt-induced actions because the agent has no embedded guardrails limiting filesystem or shell usage.
The trigger description includes broad everyday phrases like 'improve this skill', 'review the skill', and 'clean up the skill', which can cause unintended activation in loosely related conversations. For a skill that can guide file modification, script execution, and packaging, accidental triggering increases the chance of unnecessary or unsafe changes to local content.
The description contains very broad trigger phrases such as creating, improving, reviewing, cleaning up, or auditing a skill. Because trigger metadata is always in context and governs activation, this can cause the skill to activate for many generic editing or review requests, increasing the chance that a skill with file-modification guidance is invoked inappropriately. In an agent setting, overbroad routing can become a security issue by widening the situations where the model is encouraged to restructure files, run helper scripts, or modify instructions without strong user intent.
The regex ^[a-z0-9-]+$ and accompanying error message require skill names to use lowercase ASCII letters, digits, and hyphens only. This is a natural-language/locale policy concern because it hard-codes an English-centric naming convention and rejects names in other scripts, with no opt-in, alternative, or justification shown in the file.
This code creates a new directory tree and writes SKILL.md and optional example files to disk. Although it prints success messages after actions complete, there is no explicit pre-action warning, confirmation prompt, or docstring/comment disclosing that running the command will modify the filesystem at the provided path.
No suspicious patterns detected.