T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:15- Finding
Overprivileged API Credential Required for Routine Operations
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15-21andREADME.md:15-17
Vulnerability Type: Excessive API permissions and violation of least privilege
Risk Level: HighVulnerable Code Snippet:
markdown | Variable | Description | |---|---| | `AI_SAAS_API_KEY` | Your API key from the portal (Settings → API Keys). Needs `all` permission. | | `AI_SAAS_AGENT_ID` | The agent ID to route all messages to (copy from the OpenClaw Integration page). | | `AI_SAAS_BASE_URL` | Base URL of your AI SaaS instance. Default: `https://saas.salesbay.ai` |The README separately instructs users to create the same broadly privileged credential:
markdown 1. Open **Settings → API Keys** and create a key with **All** permissions. Copy the key. 2. Open the **Chatbots** page and copy the ID of the chatbot you want to route messages to.Technical Analysis
The skill requires an API key with
allpermissions even though its documented routine operations are limited to sending chat messages, retrieving agent status, deleting conversation state, and handling selected AutoPilot requests. This violates the principle of least privilege.If the key is exposed through configuration disclosure, endpoint redirection, logs, backups, or another local compromise, an attacker may be able to invoke API functionality unrelated to the skill's legitimate purpose. The precise set of additional privileges depends on the server-side meaning of
all, but the documentation explicitly establishes that the credential is not narrowly scoped.Attack Path
- A user follows the installation instructions and stores an API key with
allpermissions in~/.openclaw/openclaw.json. - An attacker obtains the configuration through local compromise, an exposed backup, accidental logging, or endpoint redirection.
- The attacker extracts the bearer token.
- The attacker submits authenticated requests directly to other API o ...[truncated 523 chars]
- A user follows the installation instructions and stores an API key with
- Remediation
View remediation
Remediation Suggestions
- Introduce a dedicated integration token restricted to the selected agent.
- Grant only the exact permissions required for chat submission, status retrieval, and conversation reset.
- Use a separate, explicitly enabled credential for campaign deployment or pause operations.
- Ensure server-side authorization validates both the token scope and requested agent or tenant.
- Support token expiration, rotation, and immediate revocation.
- Update the README and skill instructions so they no longer request an
all-permissions key.
