T09 · Insecure Skill Coding Practices
- Location
SKILL.md:25- Finding
Unquoted User-Controlled Time Values in an Exec Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25-34
Vulnerability Type: Command injection through unsafe command construction
Risk Level: MediumVulnerable code snippet:
text 1. Query notifications for the specified time range using exec: If the user does not provide a corresponding time, query notifications from yesterday to the current time: ```text command: openclaw ntf search --from start-time --to end-time yieldMs: 30000Example:
text command: openclaw ntf search --from 2026-03-01T00:00:00+08:00 --to 2026-03-09T23:59:59+08:00 yieldMs: 30000text ### Technical Analysis The Skill instructs the Agent to place a user-selected start and end time directly into a shell-style command executed through `exec`. It does not require strict timestamp validation, shell escaping, quoting, or argument-array invocation. If the execution backend passes the resulting command through a shell, metacharacters embedded in either time value may be interpreted as additional shell syntax rather than as part of a timestamp. This creates a command-injection boundary between untrusted request data and local command execution. The static Skill text does not establish whether the underlying `exec` implementation uses a shell, so successful exploitation depends on the host runtime. Nevertheless, the documented construction is unsafe because it does not constrain values to the expected ISO-8601 format or require a shell-independent invocation method. ### Attack Path 1. An attacker submits a morning-brief request containing a crafted start or end time with shell metacharacters and an additional command. 2. The Agent follows the Skill and substitutes the supplied value into the `openclaw ntf search` command. 3. The Agent sends the assembled command string to `exec`. 4. If `exec` invokes a command shell, the shell interprets the metacharacters and executes the injected command. 5. The injecte ...[truncated 564 chars]- Remediation
View remediation
Remediation Suggestions
- Accept only strict ISO-8601 timestamps, including an explicitly supported timezone format.
- Reject values containing whitespace, shell metacharacters, control characters, unexpected flags, or trailing content.
- Parse each timestamp with a trusted date-time library and serialize it back into a canonical form before execution.
- Invoke the CLI without a shell, using a structured argument array equivalent to:
text ["openclaw", "ntf", "search", "--from", validatedStart, "--to", validatedEnd] - If the platform only supports command strings, apply platform-appropriate shell escaping and quote each validated value; validation must remain the primary control.
- Add tests covering command separators, command substitution, embedded newlines, additional CLI flags, malformed timestamps, and oversized input.
- Run the notification query under least privilege and restrict the execution environment's filesystem and network access to reduce impact if command handling fails.
