T09 · Insecure Skill Coding Practices
- Location
scripts/check.sh:11- Finding
Arbitrary Shell Command Execution Through Executable Configuration
- Content
View full analysis
Vulnerability Details
File Location:
scripts/check.sh:11-27
Vulnerability Type: Unsafe execution of configuration data
Risk Level: MediumVulnerable Code:
bash # Load config if [ ! -f "$CONFIG_FILE" ]; then mkdir -p "$CONFIG_DIR" echo "# DeadOrNot Configuration" > "$CONFIG_FILE" echo "TIMEOUT_HOURS=24" >> "$CONFIG_FILE" echo "NOTIFY_EMAIL=" >> "$CONFIG_FILE" echo "MESSAGE=User is unresponsive!" >> "$CONFIG_FILE" echo "ASK_HOUR=10" >> "$CONFIG_FILE" echo "SMTP_SERVER=smtp.qq.com" >> "$CONFIG_FILE" echo "SMTP_PORT=465" >> "$CONFIG_FILE" echo "SMTP_EMAIL=" >> "$CONFIG_FILE" echo "SMTP_PASSWORD=" >> "$CONFIG_FILE" fi source "$CONFIG_FILE"Technical Analysis
The configuration file is documented and created as a collection of key-value settings, but
source "$CONFIG_FILE"causes Bash to interpret its entire contents as executable shell code. The file can therefore contain command substitutions, redirections, function calls, external commands, or other shell syntax in addition to ordinary assignments.Any local process or user capable of modifying
~/.openclaw/apps/deadornot/configcan insert arbitrary commands. Becausecheck.shis intended to run automatically through cron, the injected commands will execute when the scheduled job next starts.The injected code runs with the same operating-system identity and permissions as the account that owns the cron job. This does not directly grant root privileges unless the job is improperly installed under a privileged account, but it provides arbitrary code execution within the affected user account.
Attack Path
- An attacker obtains write access to
~/.openclaw/apps/deadornot/config, such as through another compromised process, an overly permissive directory, or shared local-account access. - The attacker appends a shell payload, for example a command that copies user data or launc ...[truncated 786 chars]
- An attacker obtains write access to
- Remediation
View remediation
Remediation Suggestions
- Do not use
source,., orevalto load a data-only configuration file. - Parse only explicitly supported keys such as
TIMEOUT_HOURS,ASK_HOUR,SMTP_SERVER, andSMTP_PORT. - Reject unknown keys, command substitutions, shell metacharacters, multiline values, and malformed records.
- Validate
TIMEOUT_HOURS,ASK_HOUR, andSMTP_PORTas bounded integers before using them in arithmetic or network operations. - Prefer a non-executable format such as JSON and parse it with a parser that never evaluates shell code.
- Create the configuration directory with mode
0700and configuration file with mode0600. - Before each scheduled execution, verify that the configuration is a regular file owned by the expected user and is not writable by group or other users.
- Do not use
