Back to skill

Security audit

Claw Orchestrator - CC+WBClaw多Agent协作

Security checks for vulnerabilities and agentic risk

Overview

This skill is a review item because it automatically hands user tasks to an external agent with broad file read/write authority and bypassed permission checks.

Install only if you are comfortable with an external Claude CLI being able to read and write files in the configured WorkBuddy directory without normal permission prompts. Prefer a version that removes `bypassPermissions`, avoids `shell=True`, pins the Claude CLI package or binary, confines outputs to a sandbox directory, and asks before storing task text in memory.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
claw_orch.py:33
Finding

User-Controlled Task Enables Shell Command Injection

Content
View full analysis

Vulnerability Details

File Location: claw_orch.py, lines 33-46
Vulnerability Type: OS command injection through an interpolated shell command
Risk Level: High

Vulnerable Code

python
prompt = f"""{task}

Write the complete deliverable files NOW. Do not describe what you'll do - just write the files.
Use the Write tool. No conversation, no explanation. Execute immediately."""

cmd = f'"{NODE}" "{NPX}" claude -p "{prompt}" --allowedTools "Read,Write" --permission-mode bypassPermissions --max-turns 5'

print(f"🧠 CC Agent (claude-sonnet-4.6) 分析+生成中...", flush=True)
env = os.environ.copy()
env["PATH"] = os.path.dirname(NODE) + ";" + env.get("PATH", "")

r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=180, cwd=WORKDIR,
                   env=env, encoding="utf-8", errors="replace")

Technical Analysis

The task originates from command-line arguments or interactive user input and is inserted into prompt without validation or escaping. That prompt is then placed inside a quoted command string and executed using subprocess.run(..., shell=True).

Because the operating-system shell parses the resulting string, an attacker can include a closing quotation mark and shell control operators in the task. This terminates the intended -p argument and introduces an independent command. Quoting the surrounding argument is insufficient because attacker-controlled quotation marks are not escaped.

Attack Path

  1. An attacker supplies a crafted task through sys.argv or the interactive prompt.
  2. The task contains a quotation mark followed by Windows shell operators such as &.
  3. The task is interpolated into cmd, breaking out of the intended -p argument.
  4. subprocess.run() passes the entire command string to the shell because shell=True.
  5. The shell executes the injected command with the privileges and environment of the user running the orchestrator.

...[truncated 724 chars]

Remediation
View remediation

Remediation Suggestions

  • Eliminate shell interpretation and pass each command argument separately:

    python
    cmd = [
        NODE,
        NPX,
        "claude",
        "-p",
        prompt,
        "--allowedTools",
        "Read,Write",
        "--permission-mode",
        "default",
        "--max-turns",
        "5",
    ]
    
    r = subprocess.run(
        cmd,
        shell=False,
        capture_output=True,
        text=True,
        timeout=180,
        cwd=WORKDIR,
        env=env,
        encoding="utf-8",
        errors="replace",
        check=False,
    )
    
  • Do not attempt to fix the issue solely through manual shell escaping; avoiding a shell is substantially safer.

  • Impose task length limits and reject control characters where they are not required.

  • Run the delegated process in an isolated, minimally privileged account or sandbox.

  • Add regression tests containing quotation marks, ampersands, pipes, redirection characters, and line breaks.

T08 · Insecure Dependencies

Error
Location
claw_orch.py:38
Finding

Unpinned and Ambiguously Resolved npm Executable Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: claw_orch.py, lines 9-10 and 38; SKILL.md, lines 24-27 and 48-57
Vulnerability Type: Unsafe third-party package resolution without version or integrity pinning
Risk Level: High

Vulnerable Code

python
NODE = r"C:\Users\zen.yang\.workbuddy\binaries\node\versions\22.12.0\node.exe"
NPX = r"C:\Users\zen.yang\.workbuddy\binaries\node\versions\22.12.0\node_modules\npm\bin\npx-cli.js"
python
cmd = f'"{NODE}" "{NPX}" claude -p "{prompt}" --allowedTools "Read,Write" --permission-mode bypassPermissions --max-turns 5'

The documented invocation has the same issue:

bash
npx claude -p "任务" \
  --allowedTools "Read,Write" \
  --permission-mode bypassPermissions \
  --max-turns 5

Technical Analysis

The Skill asks npx to execute the bare package or binary name claude without specifying an exact package version, package scope, registry, lockfile, or integrity value. If an appropriate local executable is unavailable, npx can resolve and obtain a package through npm configuration. Consequently, the code that ultimately runs is not fully identified by the audited project.

A mutable or unintended package resolution can cause package code, including applicable installation lifecycle behavior and the selected executable, to run locally. The hard-coded path to npx-cli.js does not solve this issue because it fixes the npm launcher location, not the identity or integrity of the package selected by npx.

Attack Path

  1. A user invokes the orchestrator in an environment where the expected claude executable is absent, changed, or resolved differently.
  2. npx searches configured local and remote package sources for the unqualified name.
  3. A compromised, substituted, or otherwise unintended package/version is selected.
  4. Package-controlled code executes under the invoking user's account.
  5. That code receives access to the working ...[truncated 617 chars]
Remediation
View remediation

Remediation Suggestions

  • Identify and use the verified official package rather than an ambiguous bare package name.
  • Install an exact reviewed version during a controlled setup phase and execute its fixed local binary directly.
  • Commit and enforce a lockfile containing package integrity metadata.
  • Configure an explicitly trusted registry and reject unexpected registry overrides.
  • Avoid runtime package acquisition through npx; use reproducible installation and deployment instead.
  • Where operationally possible, disable package lifecycle scripts and verify package signatures or checksums.
  • Record the resolved package name, version, source, and integrity value for auditability.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
claw_orch.py:33
Finding

Attacker-Influenced Agent Runs with Permission Checks Bypassed

Content
View full analysis

Vulnerability Details

File Location: claw_orch.py, lines 33-38
Vulnerability Type: Excessive delegated file permissions and missing approval boundary
Risk Level: High

Vulnerable Code

python
prompt = f"""{task}

Write the complete deliverable files NOW. Do not describe what you'll do - just write the files.
Use the Write tool. No conversation, no explanation. Execute immediately."""

cmd = f'"{NODE}" "{NPX}" claude -p "{prompt}" --allowedTools "Read,Write" --permission-mode bypassPermissions --max-turns 5'

The Skill documentation explicitly requires the same permission bypass:

bash
npx claude -p "任务" \
  --allowedTools "Read,Write" \
  --permission-mode bypassPermissions \
  --max-turns 5

Technical Analysis

The delegated agent receives a prompt derived directly from the user's task and is granted both Read and Write tools while operating in bypassPermissions mode. This removes normal approval checks from file operations and fails to limit the agent to a dedicated output directory.

The intended function is to create deliverable files, which does not justify unrestricted reading or overwriting of all files accessible to the process. Prompt instructions are not a security boundary: a malicious task can explicitly request access to unrelated paths, while an accidental or adversarially influenced agent action can also target sensitive files.

Attack Path

  1. An attacker submits a task instructing the delegated agent to read a sensitive file, overwrite an existing project file, or write outside the intended output area.
  2. The untrusted instruction is included directly in the delegated agent's prompt.
  3. The agent is launched with Read and Write capabilities.
  4. bypassPermissions suppresses the normal approval boundary.
  5. The requested operation is performed wherever the operating-system account has access.

This path does not require shell-command injec ...[truncated 526 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove --permission-mode bypassPermissions and retain interactive or policy-based approval for sensitive operations.
  • Create a fresh sandbox directory for each task and restrict the delegated process to that directory.
  • Grant Write only where required; grant Read only for explicitly selected input files.
  • Validate every requested output path by resolving it and confirming that it remains beneath the sandbox root.
  • Reject absolute paths, parent-directory traversal, symbolic-link escapes, and overwrites of pre-existing files.
  • Run the external agent under a dedicated low-privilege account or container with a read-only host filesystem and a narrowly mounted output directory.
  • Present the planned file operations to the user for approval before committing them to the main workspace.
  • Treat generated HTML and executable files as untrusted and inspect them before previewing or running them.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior materially exceeds the declared purpose: the description frames the external agent as doing analysis/design, but the workflow grants it direct file-writing authority with bypassPermissions and has it produce deliverable artifacts itself. This mismatch can mislead users and supervising systems about the true trust boundary and causes undeclared privileged behavior to be exercised under a safer-sounding label.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code launches an external agent with --allowedTools "Read,Write" and --permission-mode bypassPermissions, then instructs it to immediately write deliverable files. Combined with unreviewed user task input and automatic execution, this removes safety gates and allows arbitrary workspace modification by an LLM-driven subprocess.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · claw_orch.py (reported line 35)May include surrounding context.

python
cmd = f'"{NODE}" "{NPX}" claude -p "{prompt}" --allowedTools "Read,Write" --permission-mode bypassPermissions --max-turns 5'
    
    print(f"🧠 CC Agent (claude-sonnet-4.6) 分析+生成中...", flush=True)
    env = os.environ.copy()
    env["PATH"] = os.path.dirname(NODE) + ";" + env.get("PATH", "")
    
    r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=180, cwd=WORKDIR,

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This subprocess launch combines shell=True, inherited environment, and an LLM CLI configured with write tools and bypassed permissions. In this skill context, that is especially dangerous because the entire purpose is to let an external model analyze arbitrary tasks and immediately modify files, turning parameter abuse into high-risk autonomous action.

Content

Scanner excerpt · claw_orch.py (reported line 38)May include surrounding context.

python
env = os.environ.copy()
    env["PATH"] = os.path.dirname(NODE) + ";" + env.get("PATH", "")
    
    r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=180, cwd=WORKDIR, 
                       env=env, encoding="utf-8", errors="replace")
    t1 = time.time()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill documents shell execution, file reads/writes, and persistent memory updates, yet the manifest declares no explicit tool scope or permission boundaries. This creates hidden capability expansion: a caller may invoke the skill expecting analysis/orchestration, while it can actually perform local command execution and filesystem modification without transparent declaration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation claims a two-stage separation where CC Agent analyzes and WBClaw executes, but the actual workflow has CC Agent directly producing the task output files. This weakens trust-boundary clarity and may cause operators to underestimate which component is performing privileged actions, making review and consent controls less effective.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad and loosely scoped, which increases the chance the skill will activate for ambiguous requests and forward them into a powerful file-writing orchestration flow. In combination with shell execution and permission bypass, overbroad invocation criteria raise the likelihood of unintended or unsafe execution from ordinary user phrasing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow explicitly grants Claude Code Agent --permission-mode bypassPermissions together with Read,Write tools, which defeats normal approval controls for local file modification. In the context of user-provided task forwarding, this is dangerous because prompt-influenced or malicious tasks can directly cause unauthorized creation or overwrite of files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Using npx claude without a pinned package version introduces supply-chain risk because the resolved package may change over time or be replaced by a compromised release. Since this command is paired with elevated file-writing behavior and permission bypass, a malicious or unexpected package version could gain direct write access to local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that it will automatically write reports, output files, and persistent memory/log files without clearly warning users that local state will be modified. This is dangerous because users may treat the skill as advisory/orchestration-only while it silently creates or alters artifacts, including long-lived memory files that persist beyond the current task.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This invocation again relies on an unpinned npx claude resolution path, which makes runtime behavior dependent on external package state. In an orchestration skill that forwards user tasks to a subprocess with file-write permissions, that materially increases the blast radius of a supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The third unpinned npx claude example repeats the same supply-chain exposure and normalizes insecure operational guidance. Because the skill presents these commands as validated workflow steps, users are more likely to adopt them broadly, compounding risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring presents usage entirely in Chinese, and the script later uses Chinese user-facing prompts/messages, establishing a fixed language expectation. There is no indication that the user can choose a language or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

The subprocess invocation is built as a single shell command string and executed with shell=True while embedding untrusted user-controlled task text into the prompt. This creates command-injection risk on Windows shell parsing boundaries and also launches a downstream agent with file-write capability, amplifying impact beyond simple process execution.

Content

Scanner excerpt · claw_orch.py (reported line 38)May include surrounding context.

python
env = os.environ.copy()
    env["PATH"] = os.path.dirname(NODE) + ";" + env.get("PATH", "")
    
    r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=180, cwd=WORKDIR, 
                       env=env, encoding="utf-8", errors="replace")
    t1 = time.time()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code unconditionally creates or overwrites task_report.md in the working directory. The surrounding docstrings and user-facing messages do not clearly disclose ahead of time that the script will write a report file to disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script silently persists a portion of the user's task text into a dated memory file, which can retain sensitive prompts, credentials, internal project details, or personal data without consent. This creates a confidentiality and privacy risk, especially in an orchestration tool handling arbitrary user requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.