T09 · Insecure Skill Coding Practices
- Location
scripts/bundle.cjs:2- Finding
Shell Command Injection Through Plugin Configuration Values
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly matches its installer purpose, but its setup script handles credentials and local configuration in ways that could expose secrets or delete more than intended.
Review this before installing on a machine with important OpenClaw state or sensitive files. The skill links the machine to a remote service, stores login and credential material locally, installs an unpinned remote plugin, restarts the OpenClaw gateway, and has unsafe cleanup/configuration paths that could expose secrets or delete unintended files if local configuration or remote fields are compromised.
scripts/bundle.cjs:2Shell Command Injection Through Plugin Configuration Values
scripts/bundle.cjs:2Arbitrary Recursive Directory Deletion Through Unvalidated Install Path
scripts/bundle.cjs:2Authentication Credentials Written to Plaintext Logs and Shell Process Arguments
scripts/bundle.cjs:2Installation of an Unpinned Remote Plugin Package
The skill description and all user-facing invocation/install instructions are written entirely in Chinese, including the required example command at L35. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not stated here.
The script does substantially more than local plugin installation: it generates a persistent device identifier, calls remote ClawSentry APIs to create/login tokens, stores login state on disk, and later retrieves identity material used to configure the plugin. That expands the trust boundary from local setup to account binding and remote provisioning, which is security-relevant and not clearly disclosed by the stated skill purpose.
The installer contains account-login polling, device fingerprint generation, and remote identity retrieval logic, which are capabilities beyond a typical package installer and enable ongoing linkage between a local machine and a remote service. In the context of a security-plugin installer, these hidden identity/provisioning behaviors are especially risky because users may grant elevated trust and run the script with broad local permissions.
The script prints a login URL containing a login token directly to stdout and also logs poll activity to disk, increasing the chance that a sensitive token is exposed through terminal history, CI logs, shell capture, or shared consoles. Anyone obtaining that URL may be able to hijack or complete the login flow, depending on server-side protections.
The script not only installs a plugin but also deletes existing plugin configuration/directories and restarts the OpenClaw gateway. Those side effects can disrupt service, remove prior trusted settings, and make rollback harder, while the user-facing framing understates the operational impact.
No suspicious patterns detected.