T07 · Tool Hijacking and Spoofing
- Location
scripts/feishu_voice.py:41- Finding
Execution of an Unpinned and Externally Mutable TTS Component
- Content
View full analysis
Vulnerability Details
File Location:
scripts/feishu_voice.py:41-50; related dependency declarations atskill-info.json:22-24andSKILL.md:83-86
Vulnerability Type: Untrusted dependency execution and local tool substitution
Risk Level: HighVulnerable Code
python cmd = [ "node", os.path.expanduser("~/.openclaw/workspace/skills/edge-tts/scripts/tts-converter.js"), text, "--voice", config["voice"], "--pitch", config["pitch"], "--rate", config["rate"], "--output", output_mp3 ]python result = subprocess.run(cmd, capture_output=True, text=True, timeout=30)The dependency is declared without an exact version:
json "dependencies": { "edge-tts": ">=0.1.0" }The documented installation command is also unpinned:
bash npm install edge-ttsTechnical Analysis
The Python script executes
tts-converter.jsfrom a fixed path under another skill directory in the current user's workspace. That JavaScript file is not included in this project and therefore was not available for inspection as part of this audit.The dependency declaration permits any version greater than or equal to
0.1.0, and the documented installation command does not use a lockfile, exact version, or integrity verification. In addition, the code does not invoke a verified package entry point. It directly trusts a file in an independently writable local directory.Consequently, the effective executable payload can differ from the code reviewed here. Any process or user capable of replacing that JavaScript file, changing the target through a filesystem link, or influencing the installed dependency can cause arbitrary JavaScript to be executed when the skill is invoked.
Although subprocess arguments are passed as an array and do not create direct shell injection, this does not protect against substitution of the executable JavaScript file itself.
...[truncated 1320 chars]
- Remediation
View remediation
Remediation Suggestions
- Bundle the required converter with this skill and include it in security review, or invoke a package through its documented and verified package entry point.
- Pin the dependency to an exact reviewed version rather than accepting
>=0.1.0. - Commit and enforce an appropriate lockfile containing integrity hashes.
- Install dependencies using a reproducible, integrity-verifying command such as a frozen-lockfile installation.
- Before execution, resolve the converter path and reject symbolic links, unexpected file ownership, or paths outside an approved installation directory.
- Verify the converter against a trusted cryptographic digest before each execution or deploy it in a read-only package directory.
- Avoid relying on another independently mutable skill directory for executable code.
- Run the converter with least privilege, a restricted environment, and limited filesystem and network access.
