Threat Analysis High

From SKILL.md to Shell Access in Three Lines

Demonstrates how 3 lines of markdown in SKILL.md can escalate to full shell access. Skills operate with same privileges as OpenClaw process, creating unbounded attack surface. Explains how AI agent Skills enter as supply chain threats with same risks as npm packages but amplified by unprecedented access to credentials, files, and external communications.

Details

Type Threat Analysis
Published February 3, 2026
Severity High
Affected Versions All versions with Skills enabled
Fix Available No
Recommendations Sandbox all skills. Review SKILL.md files manually. Restrict file system access
Key Findings

Demonstrates how 3 lines of markdown in a SKILL.md file can escalate to full shell access. Skills operate with same privileges as OpenClaw process

#Skills #Supply Chain #Privilege Escalation #Threat Model

Related Resources