T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/perm-config.js:85- Finding
Excessive Filesystem Permissions Violate Least Privilege
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a Feishu file-staging helper, but it can persist very broad OpenClaw filesystem permissions and includes a cleanup command that can delete arbitrary writable files.
Install only if you are comfortable manually changing OpenClaw filesystem permissions. Avoid the medium and loose presets, especially /**, and do not run clean.js with any path unless you have verified it points to a temporary file created by this skill.
scripts/perm-config.js:85Excessive Filesystem Permissions Violate Least Privilege
scripts/clean.js:23Arbitrary File Deletion Through Unvalidated Cleanup Path
The skill presents itself as a temporary-directory workaround, yet the instructions explicitly tell users to run scripts that modify persistent OpenClaw configuration and broaden filesystem allowlists up to '/**'. This is dangerous because it turns a narrowly scoped helper into a permission-escalation/configuration utility with system-wide file-read implications.
The skill presents itself as a temporary-directory workaround, yet the instructions explicitly tell users to run scripts that modify persistent OpenClaw configuration and broaden filesystem allowlists up to '/**'. This is dangerous because it turns a narrowly scoped helper into a permission-escalation/configuration utility with system-wide file-read implications.
Referenced artifact was not completely inspected
node scripts/perm-config.js
Referenced artifact was not completely inspected
node scripts/perm-config.js
Referenced artifact was not completely inspected
node scripts/perm-config.js
Referenced artifact was not completely inspected
node scripts/perm-config.js
The lockfile pins axios to 1.13.6, and the supplied advisories indicate multiple known security issues including SSRF-related proxy bypass and prototype-pollution-assisted request/response compromise paths. In a skill whose purpose is sending files over HTTP to Feishu, a vulnerable HTTP client is especially relevant because it handles outbound network requests, headers, redirects, and potentially credentials or file-upload metadata.
form-data 4.0.5 is reported vulnerable to CRLF injection via unescaped multipart field names/filenames. In a file-sending skill, multipart construction is core functionality, so if any filename or form field can be influenced by untrusted input, an attacker may be able to inject malformed parts or smuggle unintended headers/content in outbound requests.
The dependency specification can resolve to axios 1.13.6, which is reported as having multiple known advisories, including SSRF-related and proxy/credential-handling issues. Because this skill is specifically for sending files through Feishu and likely performs outbound HTTP requests, a vulnerable HTTP client is especially relevant and could expose tokens, redirect traffic, or weaken network trust boundaries.
The generated permission presets materially exceed the skill's stated purpose of solving a temporary-directory whitelist issue for Feishu file sending. Offering allowlists that span home directories, multiple drives, system paths, and even whole-system access creates an unnecessary expansion of the host agent's file access surface, enabling unrelated file read/write operations if the skill or another component abuses the granted permissions.
The '宽松' preset explicitly grants '/**', effectively whole-system read/write access. For a file-sending helper whose described goal is only to work around a temporary-directory whitelist, this is unjustified and creates a severe over-permissioning path that could expose sensitive files or allow destructive writes anywhere on the system.
This code persists broad filesystem allowlist entries directly into the user's OpenClaw configuration, changing host-wide security settings rather than just handling the skill's own runtime temp-file behavior. Because the modification is durable and affects a named skill entry, it can silently broaden future access and normalize over-privileged operation beyond the immediate task.
The skill documents scripts that inspect environment-dependent state and modify OpenClaw behavior, but it does not declare explicit tool scope or permissions metadata beyond path requirements. That weakens user visibility and policy enforcement, making it easier for a seemingly simple file-transfer helper to exercise broader capabilities than expected.
The manifest and introductory description frame the skill as a temporary-directory workaround, but the documented behavior includes modifying OpenClaw configuration to expand allowed filesystem access. That mismatch obscures a security-sensitive action, increasing the chance users consent to a broader trust boundary change than they intended.
The documented permission-configuration capability expands OpenClaw file access well beyond temporary-file preparation, including broad path ranges and an option for whole-system access. In context, this is more dangerous because the skill's stated purpose only needs controlled staging in a temp directory, so the extra access is unnecessary and materially increases exposure of sensitive files.
The workflow copies user files into '/tmp' and later deletes them, but the docs do not clearly explain the confidentiality and lifecycle risks of temporary storage. On multi-user or poorly configured systems, temp files may be exposed, left behind after failures, or unintentionally deleted incorrectly.
The documentation instructs users to write to '~/.openclaw/openclaw.json' and choose permission levels, including very broad access, without a clear warning that this changes system-wide agent file access. This can lead to overpermissioned configurations that persist beyond the skill and affect unrelated workflows.
The file’s header comments and CLI output strings are written only in Chinese, with no indication that the skill is region-specific or that users can select another language. This creates a natural-language locale policy issue because the skill implicitly forces a specific language rather than offering choice or documenting a justified constraint.
The script prints the temporary directory path, per-file absolute paths, and associated URLs directly to stdout in structured JSON. In the context of a file-sending helper designed to work around a whitelist restriction, this metadata may expose sensitive local filesystem locations and shareable access URLs to logs, calling processes, or other users who can read command output.
Comments and, more importantly, runtime console messages and usage text are presented only in Chinese throughout the script. This imposes a specific language on all users without any visible locale selection or documented regional constraint.
Even the supposedly safer presets include expansive directories such as all of /home, /Users, /var, /srv, /opt, multiple Windows drives, and private temp areas. This exceeds what is needed for a temporary-directory workaround and increases the blast radius for accidental exposure or intentional misuse of files unrelated to Feishu transfer.
The script writes security-relevant configuration changes to the host OpenClaw config immediately when invoked with an option, without an interactive confirmation step or explicit risk acknowledgment. This makes it easier for users to apply dangerous permission changes unintentionally, especially because the presets themselves are overbroad.
The file’s header comments, usage text, and later console messages are entirely in Chinese, which imposes a specific language on users. The policy only allows this when the skill offers language choice or clearly documents a justified locale restriction, neither of which appears here.
Comments and user-facing error/message strings in this file are written in Chinese, including the thrown error and returned status messages, with no indication that the skill supports alternative languages or that the locale restriction is intentional. This can violate the language/locale policy when a skill effectively forces a specific language without user opt-in.
This code exposes deleteTempFile and cleanTempDir, which permanently delete files via fs.unlinkSync, but there is no confirmation prompt, user-facing log/print, or warning comment/docstring indicating that data will be removed. For code-file review under SQP-2, irreversible file deletions should include some form of disclosure unless clearly covered elsewhere, which is not visible in this file.
No suspicious patterns detected.