Back to skill

Security audit

OpenClaw Session Logs

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to search old chat logs, but it encourages broad access to complete historical transcripts without clear consent, scoping, or redaction controls.

Install only if you are comfortable with an agent reading your local OpenClaw session history. Use it with narrow requests such as a specific session, date, or phrase, and avoid broad all-session searches unless you explicitly intend that. Do not ask it to display raw transcripts unless needed, and review/redact secrets or personal information before sharing results.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:105
Finding

Unrestricted Search Across Sensitive Historical Session Logs

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–21, 105–110, and 120–125
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Vulnerable Code

markdown
Session logs live under the active state directory:
`$OPENCLAW_STATE_DIR/agents/<agentId>/sessions/` (default: `~/.openclaw/agents/<agentId>/sessions/`).
Use the `agent=<id>` value from the system prompt Runtime line.

- **`sessions.json`** - Index mapping session keys to session IDs
- **`<session-id>.jsonl`** - Full conversation transcript per session
bash
AGENT_ID="<agentId>"
SESSION_DIR="${OPENCLAW_STATE_DIR:-$HOME/.openclaw}/agents/$AGENT_ID/sessions"
rg -l "phrase" "$SESSION_DIR"/*.jsonl
bash
AGENT_ID="<agentId>"
SESSION_DIR="${OPENCLAW_STATE_DIR:-$HOME/.openclaw}/agents/$AGENT_ID/sessions"
jq -r 'select(.type=="message") | .message.content[]? | select(.type=="text") | .text' "$SESSION_DIR"/<id>.jsonl | rg 'keyword'

Technical Analysis

The skill instructs the agent to derive the session-storage path from runtime information and search complete historical transcript files. In particular, the documented command at lines 105–110 searches every JSONL transcript belonging to the selected agent rather than limiting access to the conversation explicitly referenced by the user.

Session transcripts can contain private user messages, assistant responses, tool results, personal information, credentials accidentally included in conversations, and context from unrelated providers or sessions. The skill does not require:

  • Explicit authorization before reading historical logs.
  • Restriction to a specifically identified session.
  • Validation that the current requester owns the selected historical session.
  • Redaction of secrets or personal information.
  • Exclusion of tool results and unrelated provider conversations.
  • Confirm ...[truncated 1726 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit user confirmation before accessing any historical session transcript.
  2. Default to the single session explicitly identified by the requester; do not search *.jsonl unless the requester separately authorizes a global search.
  3. Verify that the requester is authorized to access the target session, especially where one agent handles multiple users or providers.
  4. Resolve session identifiers through an access-controlled index rather than accepting arbitrary agent or session identifiers.
  5. Restrict paths to the canonical session directory and reject traversal, symlinks, or paths outside the expected agent scope.
  6. Extract only the minimum fields necessary and exclude tool results, hidden reasoning, metadata, and unrelated messages by default.
  7. Redact credentials, API keys, authentication tokens, personal information, and other sensitive values before placing excerpts in the active conversation.
  8. Present file names or match counts first and request confirmation before displaying transcript contents.
  9. Record auditable metadata for historical-log access, including the requesting session, target session, reason, and files read.
  10. Document that broad cross-session searches are prohibited unless they are necessary, explicitly authorized, and limited to the requesting user's sessions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs searching complete historical session logs and transcripts but provides no privacy warning, consent check, or minimization guidance before accessing potentially sensitive prior conversations. In this context, the omission increases the likelihood that an agent will retrieve personal, confidential, or unrelated historical data beyond what is necessary for the current task.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill normalizes access to complete prior conversation history, including raw user messages, from local session files outside the current conversational context. That creates a clear data-exposure risk because the agent may surface sensitive information from older chats that the user did not intend to re-disclose in the present interaction.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These examples show direct extraction and keyword searching of raw user and assistant transcript text, which makes sensitive content easy to enumerate and disclose verbatim. Because the examples are operational and low-friction, they materially increase the chance of over-collection and accidental leakage of historical private data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cross-session phrase search example enables sweeping searches across all stored conversations, which can surface unrelated confidential material from many sessions at once. Broad retrospective search is especially risky here because the skill is designed to mine historical logs, so an imprecise query can expose data far beyond the user's immediate request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.