T07 · Tool Hijacking and Spoofing
- Location
scripts/pipeline.py:40- Finding
Unverified execution of sibling skill scripts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This accounting workflow is mostly purpose-aligned, but it processes sensitive financial documents and executes unverified local scripts in ways that make spoofing or unintended data changes a real review concern.
Install only in a trusted, locked-down OpenClaw skills directory. Avoid using the included run_pipeline.py as written, do not run it as root, and require explicit user review before filing or reconciling accounting documents. Prefer pinning or verifying the sibling component scripts and using a dedicated low-privilege account with access only to the intended inbox and client folders.
scripts/pipeline.py:40Unverified execution of sibling skill scripts
scripts/run_pipeline.py:1Current-working-directory script spoofing in pipeline launcher
The skill description includes very broad natural-language triggers such as "traite les mails reçus", "range tout ce qui est arrivé", and "traite cette note de frais", which can overlap with ordinary user requests and cause unintended activation. In this accounting context, accidental invocation is more dangerous because the workflow can classify documents and trigger downstream processing on financial records without an explicit, narrow confirmation step.
The skill states that payment reconciliation launches automatically after classification unless the user passes --no-rapprochement, but the user-facing description does not prominently warn that invoking the skill can modify document organization and start additional processing by default. In a bookkeeping workflow, silent automatic classification and reconciliation can alter financial data handling, create mistaken associations, and make unintended actions harder to detect or undo.
The docstring states that the orchestrator 'ne fait que les appeler dans l'ordre' for the listed steps ①–④ and presents only two modes ending in consolidated reporting. However, the implementation later invokes an additional 'rapprochement-paiements' component automatically unless '--no-rapprochement' is passed, which materially extends the pipeline's behavior beyond what the documentation describes.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def _run(cmd, stdin_obj=None):
"""Lance une brique et renvoie son JSON de sortie (ou {'error': …})."""
res = subprocess.run([PY, *map(str, cmd)],
input=json.dumps(stdin_obj) if stdin_obj is not None else None,
capture_output=True, text=True)
if res.returncode != 0:
The code initializes a client root directory and writes a persistent clients.json file, which affects user data storage. Although the module docstring describes the pipeline behavior, there is no explicit warning at the point of execution that running the script will create or modify files under the chosen client root.
In email mode, the script loads a mail JSON file and forwards it to another component; in inbox mode, it recursively discovers accounting documents and processes them through multiple subprocesses. These operations handle potentially sensitive personal or financial data, but the code provides no visible user disclosure or warning about that data processing.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_rapprochement(clients_root):
"""⑤ Rapproche les paiements une fois les pièces classées. Le moteur retraite
tout le dossier (cache reconstructible), donc on le lance sur la racine entière."""
res = subprocess.run([PY, str(RAPPRO), str(clients_root)], capture_output=True, text=True)
return {"ok": res.returncode == 0, "summary": (res.stdout or res.stderr).strip()}
At L7 the script invokes pipeline.py via runpy after supplying filesystem paths at L4-L5, which implies operational effects on local data. There is no confirmation prompt, logging/print statement, docstring, or comment in this file explaining that it will run the pipeline against those directories.
The module docstring, inline usage descriptions, comments, and runtime summary text are written in French only. This imposes a locale-specific interaction model without any indication of user opt-in or alternative language support.
No suspicious patterns detected.