T09 · Insecure Skill Coding Practices
- Location
scripts/start-tmux-task.sh:193- Finding
Shell Command Injection Through an Unquoted Working Directory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its Claude Code tmux-orchestration purpose, but it gives long-running local or SSH coding agents broad unchecked authority by default.
Install only if you intentionally want Claude Code tasks run in detached tmux sessions and understand that the default mode bypasses normal permission prompts. Prefer disposable or low-privilege workspaces, avoid SSH mode unless hosts and paths are trusted, do not pass untrusted labels/workdirs/prompt files, and review generated reports and diffs before relying on the result.
scripts/start-tmux-task.sh:193Shell Command Injection Through an Unquoted Working Directory
scripts/start-tmux-task.sh:100Remote Command Injection Through Unsafe SSH Command Construction
scripts/start-tmux-task.sh:192Claude Code Is Launched With Permission Enforcement Disabled
scripts/start-tmux-task.sh:55Predictable Shared Temporary Files Permit Symlink and File-Substitution Attacks
The declared description emphasizes triggering Claude Code development tasks in tmux, stable startup, observability, SSH monitoring, and completion callback behavior. This script does none of that. It does not start tmux sessions, launch Claude Code, run coding work, or notify OpenClaw. Instead, it reads task listings from another script, filters for tasks with completion reports and done-like statuses, compares report mtimes against a local state file, emits a summary of completed-but-undelivered tasks, and can update delivery state to mark tasks as delivered. That is a materially different purpose: post-hoc reconciliation/delivery tracking rather than task execution and monitoring.
The declared description emphasizes launching Claude Code work in tmux, ensuring stable startup, allowing SSH monitoring, and notifying OpenClaw upon completion. The supplied code chunk is a reporting utility (summarize-tasks.sh) that calls list-tasks.sh --json, parses statuses with jq, and prints a chat-friendly summary of existing tasks in a namespace. It provides progress visibility in a limited sense, but it neither launches tasks nor handles completion callbacks. Its primary purpose is observational summarization, which is only a supporting/monitoring component of the broader declared skill, not an accurate match for the stated trigger-and-run behavior.
The declared description is about orchestrating Claude Code development work in observable tmux sessions, including startup stability, monitoring, and completion notification. The supplied code does none of that. It only validates an input string and invokes an OpenClaw gateway 'wake' command with that text and a mode, with a fallback for older CLI versions. This is a materially different primary purpose and omits the core described behaviors, so the description does not accurately represent the code chunk.
The skill explicitly instructs launching Claude with --dangerously-skip-permissions, which disables normal permission safeguards for an agent performing coding tasks in a local workspace. In this context, the agent may read, modify, execute, or exfiltrate data through shell-accessible resources with reduced friction, making accidental or malicious prompt-driven actions substantially more dangerous.
The script combines remote session control, shell execution, and optional SSH operation with Claude permission checks disabled, but does not present any user-facing warning or confirmation at launch. That is dangerous because a user may believe they are only starting an observable coding session, while the script actually enables an autonomous agent to act with broad authority on local or remote systems.
The script starts Claude with --dangerously-skip-permissions, explicitly disabling permission safeguards while also placing the agent in a real project directory with network proxy settings and shell access. In this skill’s context, that gives the model broad autonomous ability to read, modify, and execute within the repository beyond what a tmux orchestration helper strictly requires, increasing the chance of unintended destructive actions or prompt-driven abuse.
The skill clearly directs shell-based task orchestration through multiple bash scripts, but it declares no explicit tool scope or permission boundaries. That creates an authorization gap where a broadly triggered skill may invoke powerful local shell actions without transparent constraint, increasing the chance of unintended or unsafe execution.
The trigger condition is broad enough that the skill may activate for many coding-related requests without clear exclusions for sensitive environments, privileged repositories, or untrusted prompts. Because this skill also orchestrates shell commands, tmux sessions, and potentially SSH-monitored workflows, overbroad invocation increases the risk of inappropriate use in high-trust contexts.
The script executes shell code taken directly from arguments via command substitution: lint_out="$($LINT_CMD 2>&1)" and build_out="$($BUILD_CMD 2>&1)". Because these values are treated as full shell commands rather than fixed executables plus validated arguments, any caller able to influence --lint-cmd or --build-cmd can run arbitrary commands with the script's privileges; in this skill context, that is especially dangerous because the skill is explicitly designed to trigger development tasks automatically.
The script emits user-facing status text and a required follow-up reply pattern entirely in Chinese, including the suggested command phrase the user should send. This imposes a specific language on users without offering a choice or documenting a justified locale constraint.
When TARGET=ssh, the script silently copies the prompt/reference file to the remote host and later instructs copying report artifacts back to another host. Even if operationally useful, this can expose sensitive task content, repository details, or generated reports across systems without clear user disclosure or destination validation.
The generated prompt text is entirely in Chinese and instructs the downstream agent in that language, with no indication that the user selected Chinese or that the skill is intentionally limited to a Chinese-speaking context. This constitutes a language/locale policy issue because it imposes a specific language without opt-in or justification.
All user-visible strings are hard-coded in Chinese, so the skill's output enforces a specific language regardless of user preference. Under the policy, fixed locale behavior should either offer opt-in/choice or be clearly documented as a justified region-specific constraint.
The script creates JSON and Markdown report files under /tmp and later writes content to them, but there is no prior warning in the usage text or comments that running the skill will create local report artifacts. For a code-file audit, file writes can warrant disclosure when no user-facing warning or description is present.
This script writes persistent local state to a JSON file under the skill's state directory, and later rewrites that file when marking tasks as delivered. Although the behavior is visible in code comments, there is no runtime disclosure, confirmation, or user-facing notice that invoking the script will create or modify local state.
The comments state that output is designed to be posted to chat, and later the script prints the namespace and task labels/statuses. This discloses operational metadata to a chat audience, but the file provides no explicit user-facing warning, confirmation, or caution that task names and status details will be shared externally.
No suspicious patterns detected.