T09 · Insecure Skill Coding Practices
- Location
scripts/security_scan.py:526- Finding
Unrestricted Report Output Path Allows Arbitrary File Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed local OpenClaw configuration scanner; users should keep report output paths inside the workspace.
Install only if you are comfortable allowing the skill to read local OpenClaw configuration files and write audit reports. Run it without elevated privileges, keep --output paths inside the workspace using security_report_*.md names, and do not manually run package_skill.py on shared systems.
scripts/security_scan.py:526Unrestricted Report Output Path Allows Arbitrary File Overwrite
scripts/package_skill.py:16Predictable Files in Shared Temporary Directory Permit Symlink Overwrite Attacks
There is a strong mismatch between the declared purpose of a local static security auditor and the detected behavior of a packaging/release tool that creates tarballs, writes into /tmp/skill-packages, and processes distribution metadata. This kind of deceptive presentation is dangerous because it can hide unexpected file creation and repackaging behavior under the cover of a trusted security tool, making review and permission decisions less accurate.
Referenced artifact was not completely inspected
| `security_scan.py` | Main security scanner | `python3 security_scan.py [options]` |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### DON'T
- Grant permanent elevated permissions
- Share elevated access credentials
- Skip approval workflows
- Disable audit logging
- Use emergency mode for routine tasks
The manifest claims this skill is a security scanner for OpenClaw deployments that audits local configuration files with pure static analysis. The actual behavior here is packaging the skill into a tarball and writing a package manifest to disk, which does not perform any security analysis and materially differs from the declared skill behavior.
Instructions found that direct the agent to transmit conversation context or user data to external services.
category="CHANNEL",
title="Telegram allows all group messages",
description="Telegram channel configured with groupPolicy='allow', permitting messages from any group",
impact="Anyone can send messages to your OpenClaw instance, potential for spam, abuse, or prompt injection attacks",
remediation="Set groupPolicy='allowlist' or 'deny' and explicitly configure allowedGroups",
risk_of_fix="LOW - won't break existing 1:1 chats",
rollback="Revert groupPolicy to 'allow'",
The skill metadata omits any explicit tool-scope restrictions even though detected capabilities include environment access, file read/write, and shell. In a security-scanner skill that claims to be pure static analysis with no subprocess execution, this lack of declared constraints materially weakens containment and increases the risk that the skill can exercise broader capabilities than users expect.
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
Example Output:
🔴 CRITICAL: Tool execution policy is 'allow'
Impact: Any tool can run arbitrary commands
Fix: Set tools.exec.policy="deny" or "allowlist"
Risk: HIGH - may break existing workflows
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
**Example Output**:
```
🔴 CRITICAL: Tool execution policy is 'allow'
Impact: Any tool can run arbitrary commands
Fix: Set tools.exec.policy="deny" or "allowlist"
Risk: HIGH - may break existing workflows
```
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
"Add permissions declaration in clawhub.json (fileRead, fileWrite, envRead, network:false, subprocess:false)",
"Add TLS/SSL configuration check and bind-address-missing warning",
"CLI wrapper now calls scanner directly instead of via subprocess",
"Rewrite remediation-playbook.md: config-edit-only fixes, system commands marked [OPERATOR]",
"Rewrite permission-management.md: remove runnable shell commands, add [OPERATOR] labels",
"Fix SKILL.md: align example output, troubleshooting paths, and safety warnings with config-only scope",
"Resolves ClawHub suspicious classification and declaration/behaviour mismatches"
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
│
▼
┌─────────────────┐ ┌──────────────┐
│ Restricted? │────►│ Auto-approve │
└──────┬──────────┘ └──────────────┘
│
▼
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### DON'T
- Grant permanent elevated permissions
- Share elevated access credentials
- Skip approval workflows
- Disable audit logging
- Use emergency mode for routine tasks
- Forget to revoke temporary permissions
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Rule 1: Never Brick Remote Deployments
**Before ANY config change:**
1. Create a copy of `~/.openclaw/config.json` (e.g. add a `.backup.<timestamp>` suffix)
2. Confirm you have an alternative way to access the host (SSH, console, secondary channel)
3. Test the restore procedure
4. Schedule a maintenance window
The manifest presents the skill as a read-only security auditor for local configuration analysis, while this file's top-level documentation explicitly states it packages the skill for distribution and ClawHub publishing. That documentation highlights a materially different intent from the skill's declared operational purpose.
The manifest describes a skill that performs pure static analysis of local OpenClaw configuration files and emphasizes no command execution or probing. This file instead implements a packaging capability that creates output directories and prepares release artifacts, which is not justified by the stated runtime purpose of auditing configurations.
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
finding = Finding(
level="HIGH",
category="CHANNEL",
title="Telegram allowlist is empty",
description="groupPolicy='allowlist' but allowedGroups is empty or not configured",
impact="No groups can message the bot, may indicate misconfiguration",
remediation="Add group IDs to allowedGroups or change groupPolicy",
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
level="MEDIUM",
category="PERMISSION",
title=f"Dangerous tool enabled: {tool}",
description=f"Tool '{tool}' can execute arbitrary code",
impact="Potential for code execution attacks if tool is compromised",
remediation=f"Disable {tool} if not needed, or restrict via allowlist",
risk_of_fix="MEDIUM - may break functionality",
The manifest describes a scanner that audits local configuration files and emphasizes pure static analysis, which implies read-only analysis with safe remediation guidance. The code additionally creates or overwrites a report file on disk, introducing filesystem modification behavior not reflected in the manifest description.
The time-based context example sets "timezone": "Asia/Shanghai", which imposes a specific locale in natural-language/config guidance. The file does not indicate that this is merely an example tied to a region-specific deployment, nor does it offer user/operator choice of timezone.
The docstrings state that all checks derive from local configuration files only, but the implementation also reads the system hostname using platform.node() and includes it in the generated report. That is a direct contradiction to the documented 'configuration files only' claim, even though it is not a high-risk action.
The scanner advertises config-only analysis in its documentation, yet it gathers host metadata outside the configuration files and surfaces it in the report. This is a concrete intent-code divergence because the documented input scope is narrower than the actual implementation.
The scanner's stated purpose is auditing local OpenClaw configuration files, but it also inspects process environment state via OPENCLAW_CONFIG. Reading environment variables is a broader capability than simple local file analysis and is not declared in the manifest scope.
This code performs a file write when an output path is provided, but the only surrounding disclosure is the generic '--output report path' argument help. There is no explicit warning in a comment or user-facing message before the write that running the script will create or overwrite a report file on disk.
No suspicious patterns detected.