T09 · Insecure Skill Coding Practices
- Location
scripts/rollback.py:17- Finding
Rollback Can Recursively Delete an Arbitrary Metadata-Defined Directory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its purpose of managing OpenClaw skills, but its backup, rollback, and installer scripts can overwrite or delete broad local data, so it belongs in Review before use.
Use only in a disposable or well-backed-up skill workspace until fixed. Do not run the installer or rollback scripts with elevated privileges, do not roll back from untrusted backup metadata, inspect exact target paths before confirming deletion, and remove symlinks or secrets from skill directories before backup.
scripts/rollback.py:17Rollback Can Recursively Delete an Arbitrary Metadata-Defined Directory
scripts/backup.py:19Backup Follows Symlinks and Can Copy Files Outside the Skill Directory
scripts/proposal.py:99Proposal Identifier Path Traversal Allows Unintended JSON File Modification
scripts/install.py:47Installer Reports Migration Success Without Migrating Data Before Recursive Deletion
scripts/config.py:1Missing Import Disables the Advertised Modification Security Gate
The skill is explicitly designed to modify existing skills according to a generated plan, which is a self-modification capability with direct impact on trusted agent behavior. This is more dangerous in context because the tool also performs backup, rollback, packaging, and version management, giving it broad write access over skill contents and increasing the blast radius of a bad or manipulated change.
A[User submits optimization requirements] --> B[Generate optimization plan]
B --> C[User confirms the plan]
C --> D[Automatically back up the current version]
D --> E[Modify skills according to the plan]
E --> F[Automatic diff comparison + risk assessment]
F --> G[Automatically run test cases]
G --> H[Generate new version records + CHANGELOG]
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Print next steps
print(f"\n[OK] Skill '{skill_name}' initialized successfully at {skill_dir}")
print("\nNext steps:")
print("1. Edit SKILL.md to complete the TODO items and update the description")
if resources:
if include_examples:
print("2. Customize or delete the example files in scripts/, references/, and assets/")
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def test_skips_symlink_to_external_file(self):
skill_dir = self.create_skill("symlink-file-skill")
outside = self.temp_dir / "outside-secret.txt"
outside.write_text("super-secret\n")
link = skill_dir / "loot.txt"
out_dir = self.temp_dir / "out"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def test_skips_symlink_to_external_file(self):
skill_dir = self.create_skill("symlink-file-skill")
outside = self.temp_dir / "outside-secret.txt"
outside.write_text("super-secret\n")
link = skill_dir / "loot.txt"
out_dir = self.temp_dir / "out"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def test_skips_symlink_to_external_file(self):
skill_dir = self.create_skill("symlink-file-skill")
outside = self.temp_dir / "outside-secret.txt"
outside.write_text("super-secret\n")
link = skill_dir / "loot.txt"
out_dir = self.temp_dir / "out"
The documented rollback feature can overwrite the current skill state, but the description does not warn users about potential data loss or the need to preserve uncommitted changes first. In a tool explicitly designed to modify and manage skills, this omission can lead to accidental destructive actions and unsafe operator assumptions.
The installation flow says historical backups and version records will be automatically migrated, but it does not warn that this may import unexpected data, alter local state, or expose prior artifacts the user did not intend to carry forward. Automatic migration of historical data is sensitive because users may not realize what content is being discovered and moved.
The skill describes automatically running test cases after modifying skills, which is an autonomous action that can execute code or scripts derived from the target skill or its environment. In a security-sensitive setting, automatic test execution increases risk because tests may have side effects, run unsafe code, or operate on untrusted content without an explicit execution gate.
C --> D[Automatically back up the current version]
D --> E[Modify skills according to the plan]
E --> F[Automatic diff comparison + risk assessment]
F --> G[Automatically run test cases]
G --> H[Generate new version records + CHANGELOG]
### 3. View Version List
This code file contains natural-language comments and risk labels exclusively in Chinese, including operational guidance such as approval and risk confirmation settings. The file provides no indication that Chinese is optional, user-selected, or required for a justified region-specific context, which can violate language/locale policy requirements.
This Python file contains user-facing docstrings, help text, and console messages entirely in Chinese, including argument descriptions and status/error output. That creates a language/locale constraint in the skill's natural-language behavior without offering an opt-in or documenting that the tool is intended only for a Chinese-speaking context.
This code presents its description, errors, prompts, and status messages in Chinese, beginning with the docstring and visible output strings. That forces a specific language/locale on all users without offering any opt-in or alternative, which matches the policy-violation criteria for language choice.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
show_diff = input("\n是否查看该版本与当前版本的差异? (y/N): ")
if show_diff.lower() == 'y':
diff_script = os.path.join(os.path.dirname(__file__), "diff.py")
subprocess.run([
"python", diff_script,
args.skill_name,
selected_version["version_id"]
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# 执行回滚
rollback_script = os.path.join(os.path.dirname(__file__), "rollback.py")
subprocess.run([
"python", rollback_script,
args.skill_name,
selected_version["version_id"]
The script's user-facing docstrings, status messages, generated markdown content, and CLI help text are consistently in Chinese, which effectively imposes a specific language on users. There is no indication that the skill is region-specific or that users can opt into another language, which matches the language/locale policy-violation criterion.
This code contains multiple natural-language docstrings, status messages, and confirmation prompts only in Chinese, including the CLI description and rollback confirmation text. The file does not provide any user opt-in for language selection or indicate that the skill is intentionally limited to a Chinese-speaking context, which conflicts with the policy against forcing a specific language without user choice.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# 先备份当前版本
import subprocess
subprocess.run([
"python", os.path.join(os.path.dirname(__file__), "backup.py"),
target_path,
"--note", f"auto-backup-before-rollback-to-{args.version_id}"
This Python file contains all user-facing docstrings, status messages, usage text, and confirmation prompts in Chinese only. The file does not offer any language selection or document that the skill is intentionally limited to a Chinese-speaking or region-specific environment, which creates a natural-language locale policy concern.
This script presents user-facing comments, prompts, and status messages entirely in Chinese, including installation choices and destructive-action notices. That can violate a language/locale policy when the skill does not offer user opt-in or an alternative locale.
This code hard-codes the command description and user-visible output in Chinese, including the argument description and error message. Under the natural-language policy rule, forcing a specific language without user opt-in is a locale/language policy violation.
The script's natural-language interface strings are entirely in Chinese, including the command description and all argument help text. This imposes a specific language on users without any opt-in or indication that the skill is intentionally limited to a Chinese-speaking context, which matches the locale-policy concern for natural-language content.
No suspicious patterns detected.