T09 · Insecure Skill Coding Practices
- Location
references/openclaw.md:58- Finding
OAuth Authorization Code Can Be Used for Shell Command Injection
- Content
View full analysis
' ``` ``` ### Technical Analysis The documented procedure accepts any bare string that does not contain `=` or `&` as an OAuth authorization code. It then demonstrates placing that value inside a single-quoted shell command. The validation rules do not reject single quotes, command separators, newlines, control characters, shell metacharacters, or unexpectedly long values. Consequently, a value such as: ```text '; attacker-command; # ``` contains neither `=` nor `&`, so it satisfies the documented bare-code rule. If an agent substitutes it into the command and executes the resulting string through a shell, the single quote terminates the intended argument and the subsequent content is interpreted as a separate command. Keeping this exchange in a private channel protects the credential from disclosure but does not prevent a malicious or compromised participant in that channel from supplying an injection payload. ### Attack Path 1. The agent starts the documented headless OpenClaw OAuth flow. ...[truncated 1179 chars]- Remediation
View remediation
