T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/start-tmux-task.sh:193- Finding
Claude Code Is Launched with Permission Safeguards Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent as a Claude Code tmux orchestrator, but it starts coding agents with permission safeguards disabled and has under-scoped shell, SSH, and temp-file handling that users should review before installing.
Install only if you are comfortable with this skill starting autonomous Claude Code sessions that can modify the selected repository without normal permission prompts. Prefer a sandbox, VM, container, or dedicated low-privilege account; avoid untrusted task text, paths, and prompt files; and review or remove the unsafe launch mode, SSH/SCP behavior, and `/tmp` report handling before using it on sensitive projects.
scripts/start-tmux-task.sh:193Claude Code Is Launched with Permission Safeguards Disabled
scripts/start-tmux-task.sh:193Shell Command Injection Through Unvalidated Orchestrator Arguments
scripts/start-tmux-task.sh:55Predictable Temporary Files Allow Symlink Clobbering and Completion Report Spoofing
The declared description emphasizes triggering Claude Code development tasks in observable tmux sessions with stable startup and progress visibility, plus completion callback behavior. This code chunk instead appears to be a completion/reporting helper that assumes work has already happened: it changes into a workdir, inspects git status/diff, runs lint/build quality checks, determines a simple risk/recommendation, writes JSON and Markdown reports, and optionally sends a wake notification. The only tmux-related behavior is deriving a session name for filenames; there is no tmux control, no session creation/monitoring, and no Claude Code task startup. The notification aspect is somewhat aligned, but the primary purpose is materially different and includes undeclared capabilities around repository inspection, command execution, and report generation.
The declared description emphasizes launching Claude Code development work in tmux with stable startup, progress visibility, SSH monitoring, and completion callbacks to OpenClaw. This script does not start or manage coding sessions, does not trigger Claude Code tasks, and does not perform any callback or push to OpenClaw. Instead, it inspects task listings from another script, checks report file mtimes against a local delivery-state JSON file, outputs a summary of completed-but-undelivered tasks, and can mark them as delivered. While tmux session names and attach commands are included for observability, the primary purpose is post-completion reconciliation and delivery-state management, which is materially different from the declared purpose.
The declared purpose emphasizes initiating Claude Code work in tmux sessions and handling observability plus completion notification. The actual code chunk is a reporting utility (summarize-tasks.sh) that consumes task listings and formats a status heartbeat for chat. While this is loosely related to progress visibility, it omits the core declared behaviors of triggering tasks, setting up sessions, and notifying OpenClaw on completion. Therefore the code chunk's primary purpose is materially different from the declared description.
The declared description centers on orchestrating Claude Code coding jobs inside observable tmux sessions and notifying OpenClaw upon completion. The actual code chunk is a small wrapper around openclaw gateway call wake (or a legacy fallback) that sends arbitrary text and a mode to OpenClaw, then exits. It does not launch development tasks, manage sessions, expose progress, support SSH access, or handle completion state. Its primary purpose is materially different from the declared purpose, so this is a clear mismatch.
The skill explicitly instructs launching claude --dangerously-skip-permissions, which disables normal permission safeguards for subsequent coding actions. In a skill designed to run arbitrary development tasks in a user workdir, this materially increases the risk of unauthorized file changes, command execution, secret exposure, and destructive actions without user-facing warning or consent.
The script starts Claude with --dangerously-skip-permissions, explicitly disabling approval and permission safeguards for an agent that is then instructed to perform coding tasks in a real working directory. In this skill context, that materially increases the chance of unauthorized file changes, command execution, secret exposure, or destructive actions, especially because the whole purpose of the skill is to launch autonomous development work in tmux sessions.
This finding is substantively the same unsafe behavior as SDI-2: the script suppresses Claude's safety/permission controls without any explicit confirmation step or warning to the operator. In a tool designed to trigger coding work automatically and remotely, hiding the reduction in safety controls makes accidental misuse and high-impact agent actions significantly more likely.
The skill clearly directs shell execution through multiple local scripts, but it declares no explicit tool scope or permissions boundary. That creates ambiguous authority and weakens review controls, increasing the chance that an agent can execute commands in contexts the user did not expect.
The trigger text is broad enough to match routine coding requests, which could cause the skill to activate in situations where the user did not intend remote orchestration or shell-based task launching. Over-broad activation increases the chance of unnecessary privileged execution and reduces meaningful user consent.
The skill is described as triggering Claude Code work in tmux and reporting completion, but this helper also accepts free-form --lint-cmd and --build-cmd values and executes them as shell commands. Running arbitrary commands is a broader capability than merely generating completion status and is not explicitly justified by the manifest description of progress visibility and completion callback behavior.
The script executes user-supplied command strings from --lint-cmd and --build-cmd through command substitution, which can run arbitrary shell commands in the target working directory. Although this behavior may be functional, the file itself provides no warning, confirmation, or explanatory comment that these supplied commands will be executed.
The script emits user-facing status and instruction text in Chinese only, including the final recommended reply format. This imposes a specific language/locale choice without offering the user an option or documenting a justified locale restriction.
The manifest focuses on starting Claude Code work in observable tmux sessions and providing progress visibility plus completion callback. In addition to that, the script copies the reference prompt to a remote host and later instructs Claude to copy JSON/Markdown reports to a separate Mac mini via scp, which is cross-host file transfer behavior not reflected in the description.
The generated prompt content in lines L155-L184 is entirely in Chinese and instructs the downstream agent in that language, effectively imposing a locale/language choice. There is no visible opt-in, configuration, or justification indicating that this skill is intentionally region-specific.
The user-facing output strings from L29 onward are consistently Chinese, including headings, status messages, and instructions. This imposes a specific language on all users without any opt-in or documented locale justification, which matches the natural-language policy violation criteria.
The script writes predictable report filenames into /tmp using a session-derived name, which exposes it to symlink and clobbering issues in multi-user environments. A local attacker could pre-create a symlink at the expected path and cause the script to overwrite an arbitrary file writable by the script's user, or read sensitive build/report data from world-accessible temporary locations.
This code creates and later updates a persistent state file under the skill directory, which is a file-write operation. Although the script has internal comments, there is no user-facing prompt, log, or explicit disclosure at the write points that local state will be created and modified.
No suspicious patterns detected.