T09 · Insecure Skill Coding Practices
- Location
references/delete.md:38- Finding
Unsafe Non-Atomic Rewrite of Sensitive OpenClaw Configuration
- Content
View full analysis
Vulnerability Details
File Location:
references/delete.md, lines 38-56
Vulnerability Type: Unsafe configuration-file handling
Risk Level: Mediumpython import json path = '/Users/honor/.qclaw/openclaw.json' with open(path, 'r') as f: config = json.load(f) # 删除指定飞书账号 accounts = config.get('channels', {}).get('feishu', {}).get('accounts', {}) for account_id in ['{feishuAccount}']: # 列出所有要删除的账号 if account_id in accounts: del accounts[account_id] with open(path, 'w') as f: json.dump(config, f, indent=2)Technical Analysis
The full-uninstall procedure directly edits a sensitive live configuration file using a hard-coded absolute path associated with a specific user. This can target the wrong configuration when the Skill runs under a different account or deployment layout.
Opening the file with mode
wtruncates it before JSON serialization finishes. The operation does not use a same-directory temporary file followed by atomic replacement, file locking, synchronization, or a verified backup. A process interruption, serialization error, disk failure, or concurrent configuration update can therefore leave the file empty, partially written, or missing updates made by another process.This procedure also contradicts the backup and rollback requirement stated in
SKILL.md. The documented deletion sequence provides no implementation that creates a backup before modification or restores it if the direct rewrite fails. Because normal file opening follows symbolic links, unsafe ownership or link conditions at the fixed path could also redirect the write if a local actor already has sufficient access to manipulate that path.Attack Path
- A user selects full agent uninstallation and provides the required confirmation.
- The workflow force-deletes the selected agent and its workspace.
- The Python procedure opens
/Users/honor/.qclaw/openclaw.json, regardless of ...[truncated 1320 chars]
- Remediation
View remediation
Remediation Suggestions
- Resolve the configuration path through the trusted QClaw/OpenClaw wrapper or derive it from the authenticated user's home directory. Do not use a fixed username.
- Canonicalize and validate the path before writing. Confirm that the file is a regular file, is owned by the expected user, and is not a symbolic link.
- Acquire an exclusive lock to prevent concurrent writers from losing each other's updates.
- Create a timestamped backup before modification and verify that the backup can be parsed.
- Write the updated JSON to a temporary file in the same directory with restrictive permissions.
- Flush buffered data and call
fsyncbefore replacing the original file. - Atomically replace the live configuration with the temporary file and preserve the original ownership and access mode.
- Validate the resulting JSON and required configuration structure before considering the deletion successful.
- Restore the verified backup automatically if writing, validation, replacement, or gateway reload fails.
- Prefer a supported configuration API capable of explicit key deletion if one becomes available, avoiding direct modification of the live configuration.
