T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:4- Finding
Excessive Tool Permissions for an Advisory-Only Productivity Skill
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 4
Vulnerability Type: Violation of least privilege through unnecessary shell and filesystem capabilities
Risk Level: MediumComplete Code Snippet:
yaml allowed-tools: Bash, Read, WriteTechnical Analysis
The skill describes task organization, daily planning, time tracking, and workflow advice, none of which inherently require arbitrary shell execution or unrestricted filesystem access. Nevertheless, its manifest authorizes
Bash,Read, andWrite.In particular,
Bashcan expose a broad command-execution surface, whileReadandWritemay permit access to files unrelated to productivity planning. The exact accessible scope depends on the OpenClaw runtime's sandbox and authorization controls, but the manifest does not define narrower path, command, or operation restrictions.No malicious command is present in the audited package. The security defect is the unnecessary capability grant, which increases the consequences of future package compromise, malicious instruction updates, prompt injection, or unsafe content obtained from the externally referenced setup guide.
Attack Path
- A user installs and activates the skill, causing the runtime to grant the tools declared in
allowed-tools. - An attacker compromises a future skill version, influences instructions consumed while the skill is active, or supplies prompt-injection content.
- The injected instructions invoke
Readto collect accessible local information,Writeto alter accessible files, orBashto run commands. - The commands execute with the operating-system identity and sandbox permissions of the OpenClaw process.
The current audited instructions do not independently execute this path; exploitation requires an additional malicious or compromised instruction source.
Impact Assessment
A successful exploit could disclose files readable by the agent proc ...[truncated 431 chars]
- A user installs and activates the skill, causing the runtime to grant the tools declared in
- Remediation
View remediation
Remediation Suggestions
- Remove
Bash,Read, andWriteif the skill only provides conversational planning and prioritization. - If state persistence is required, grant only a narrowly scoped storage interface rather than general filesystem access.
- Restrict reads and writes to a dedicated skill data directory with canonical-path validation.
- Replace unrestricted shell access with purpose-built operations that accept structured arguments.
- Where shell execution is unavoidable, use a strict command allowlist, prohibit shell metacharacters, pass arguments without shell interpolation, and run inside a sandbox with minimal filesystem and network access.
- Require explicit user approval for sensitive file operations or command execution.
- Add automated checks that reject future manifest changes introducing capabilities not justified by documented features.
- Remove
