T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/bin/claw-callback.py:212- Finding
Unauthenticated Callback Mutation and Wake-Route Replacement
- Content
View full analysis
bool: """Enforce that `actor` is the agent entitled to take `action` on this bottle. (T15) Returns True when the check was overridden with --force, so the caller can record an `authority-override` ledger event. Refuses (fail-closed, non-zero) otherwise. Comparison is on canonical names (T14): an agent that returns as `ECHO` when the envelope recorded `reviewer` is the same agent, and rejecting it would be a regression rather than a control. """ if agent_key(actor) == agent_key(expected): return False if force: return True die(f"{action} refused: --from '{actor}' is not the {role} of {env['id']} " f"(that is '{expected}'). If this is deliberate, re-run with --force; the " f"override is recorded in the ledger.") ``` The `--force` option bypasses the comparison without requiring a distinct administrative credential. More importantly, a caller can simply provide the expected agent name through `--from`, because no credential or cryptographic proof is bound to that identity. The routing registry is also writable without an administrator check. Registering an existing logical agent updates its `agentId` and optional `sessionKey`: ```python def cmd_register(args): """Register or update an agent's routing info in the registry. (T14)""" reg = load_registry() age ...[truncated 3221 chars]- Remediation
View remediation
