Back to skill

Security audit

Complex Task Orchestrator

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent as a complex-task orchestration helper, but it requires broad persistent logging of user task details and ships a checkpoint script with an unvalidated file path risk.

Review this skill before installing if your tasks may include secrets, customer data, document tokens, business plans, or sensitive file paths. Use it only with clear workspace boundaries, avoid recording raw sensitive details in daily notes, and do not run the checkpoint helper with untrusted task IDs until its path validation is fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/checkpoint.py:30
Finding

Path Traversal Through Unvalidated Checkpoint Identifier

Content
View full analysis

Vulnerability Details

File Location: scripts/checkpoint.py, lines 30-63
Vulnerability Type: Path traversal and unauthorized file access
Risk Level: Medium

Vulnerable Code

python
def create(task_id: str, description: str, total: int):
    """Create a new checkpoint."""
    ensure_dir()
    cp = {
        "task_id": task_id,
        "description": description,
        "total": total,
        "completed": 0,
        "succeeded": 0,
        "failed": 0,
        "failed_items": [],
        "created_at": datetime.now(timezone.utc).isoformat(),
        "last_checkpoint": datetime.now(timezone.utc).isoformat(),
        "output_file": None,
        "status": "running"
    }
    path = os.path.join(CHECKPOINT_DIR, f"{task_id}.json")
    with open(path, "w") as f:
        json.dump(cp, f, indent=2, ensure_ascii=False)

def update(task_id: str, succeeded: int = 0, failed: int = 0,
           failed_items: list = None, output_file: str = None):
    """Update checkpoint progress."""
    path = os.path.join(CHECKPOINT_DIR, f"{task_id}.json")
    with open(path) as f:
        cp = json.load(f)

    # The checkpoint is subsequently written back to the same path.
    with open(path, "w") as f:
        json.dump(cp, f, indent=2, ensure_ascii=False)

def read(task_id: str):
    """Read checkpoint state."""
    path = os.path.join(CHECKPOINT_DIR, f"{task_id}.json")
    if not os.path.exists(path):
        return None
    with open(path) as f:
        cp = json.load(f)
    print(json.dumps(cp, indent=2, ensure_ascii=False))
    return cp

Technical Analysis

The task_id value is obtained from command-line input and embedded directly into a filesystem path:

python
os.path.join(CHECKPOINT_DIR, f"{task_id}.json")

No validation rejects absolute paths, directory separators, or .. traversal components. Consequently, the normalized path is not guar ...[truncated 2502 chars]

Remediation
View remediation

Remediation Suggestions

  1. Strictly validate checkpoint identifiers. Allow only a limited filename-safe character set:

    python
    import re
    
    TASK_ID_PATTERN = re.compile(r"^[A-Za-z0-9_-]+$")
    
    def validate_task_id(task_id: str) -> None:
        if not TASK_ID_PATTERN.fullmatch(task_id):
            raise ValueError("Invalid task ID")
    
  2. Centralize secure path construction. Resolve both the base directory and candidate path, then verify containment:

    python
    from pathlib import Path
    
    CHECKPOINT_DIR = Path(
        "~/.openclaw/workspace/checkpoints"
    ).expanduser().resolve()
    
    def checkpoint_path(task_id: str) -> Path:
        validate_task_id(task_id)
        candidate = (CHECKPOINT_DIR / f"{task_id}.json").resolve()
    
        if candidate.parent != CHECKPOINT_DIR:
            raise ValueError("Checkpoint path escapes the checkpoint directory")
    
        return candidate
    
  3. Reject path syntax explicitly. Do not accept absolute paths, .., /, \, null bytes, or platform-specific path separators as identifiers.

  4. Mitigate symbolic-link attacks. Refuse to operate on symbolic links and, where supported, open files using flags such as O_NOFOLLOW.

  5. Use atomic writes. Write serialized data to a securely created temporary file in the same directory, flush and synchronize it, and then replace the destination atomically with os.replace.

  6. Apply restrictive permissions. Create the checkpoint directory and files with permissions that limit access to the Agent's operating-system account.

  7. Validate loaded checkpoint schemas. Before updating a file, verify that it is a valid checkpoint object with correctly typed and bounded fields.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly instructs file reads and writes such as persistent logs, checkpoint files, and result files, but it does not declare any tool scope or allowed-tools boundary. That creates an authorization ambiguity where an agent may use broader file capabilities than users expect, increasing the chance of unintended persistence or access to sensitive workspace data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill requires writing user requirements, source, key parameters, and status to persistent daily notes before any action, but provides no privacy notice, minimization rule, retention limit, or consent gate. This can cause sensitive task details, credentials, file paths, business data, or personal information to be stored in long-lived logs without user awareness.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to persist requirements and key details in daily notes or work logs before doing anything creates a built-in data retention channel for natural-language user content. In the context of an orchestration skill handling large, complex, potentially business-sensitive tasks, this increases exposure of confidential data and makes leakage through later reads, summaries, or cross-task reuse more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

该规则适用于所有文件类型。L001 以中文标题呈现,全文也以中文固定说明任务模式,但文档未声明语言选择机制、用户可切换选项,或说明这是仅面向特定中文场景的受限资料,存在语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The orchestration skill expands into concrete Feishu document and wiki creation/writing operations, which adds external side-effecting capabilities beyond pure task decomposition guidance. In a broad orchestrator, this can cause the agent to create or modify external resources when the user only asked for planning, increasing the risk of unintended data writes, overwrites, or information leakage into third-party systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

该文档是 markdown 文件,适用 SQP-1。L070 中的“升级 OpenClaw” / “配置一个新环境”缺少明确上下文、范围或限制条件,尤其“配置一个新环境”属于高度通用表达,可能覆盖多种无关任务并造成非预期调用。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L093 的“分析这个 Excel 的数据” / “处理这批 JSON”属于常见泛化请求,没有说明数据规模、处理目标或适用场景,容易与普通数据分析请求重叠。文档中虽随后按数据量给出策略,但未在触发条件本身限定调用边界。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Recommending writing and executing Python scripts materially broadens the skill from orchestration into code execution. In practice, an orchestrator that normalizes 'exec 运行脚本' may trigger unsafe processing of untrusted data or encourage unnecessary execution paths that can access files, consume resources, or perform unintended actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

L115 的“投资决策” / “需要风控审查”表达过于抽象,可能匹配大量不同领域的常规对话。文档没有给出明确的触发边界、输入要求或负例,存在意外激活风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains user-facing natural-language text exclusively in Chinese, starting with the module docstring. The policy requires flagging language or locale constraints when a skill forces a specific language without user opt-in, and there is no indication here that Chinese is optional or region-specific by design.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple print statements and usage instructions shown to end users are only in Chinese, including creation, progress, error, and help output. Because the file gives no option to select another language and no documented rationale for a Chinese-only locale, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill's natural-language instructions and activation description are entirely in Chinese, which can impose a specific language/locale on users or operators without offering an alternative. The policy requires avoiding forced language constraints unless the skill explicitly provides choice or documents a justified locale limitation.

Content

No source excerpt is available for this finding.

Ssd 3

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill tells the agent to create internal work notes about goals, scale, dependencies, and risks without user visibility. Although less severe than the persistent daily log requirement, these notes can still capture sensitive task context or proprietary plans and normalize hidden retention of user-derived information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.