T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/sync-server.mjs:47- Finding
Symlink-Based Workspace Escape Permits Access Outside Allowed Directories
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it says, but its sync server has a real file-containment flaw and optional boot persistence that users should review before installing.
Review before installing. Use only with trusted clients and a strong token, keep the bind address on localhost unless you understand the exposure, avoid syncing directories containing symlinks, keep backups of notes, and prefer running the service under a dedicated low-privilege account. Do not enable the systemd linger service unless you want the sync server to keep running after logout and at boot.
scripts/sync-server.mjs:47Symlink-Based Workspace Escape Permits Access Outside Allowed Directories
scripts/sync-server.mjs:223Unbounded Request Buffering and File Writes Enable Resource Exhaustion
Referenced artifact was not completely inspected
SYNC_TOKEN="your-gateway-token" node scripts/sync-server.mjs
The skill exposes capabilities that rely on environment variables and network access, but it does not declare any tool scope or permissions boundaries. That makes the operational trust assumptions implicit, increases the chance of over-broad execution in agent frameworks, and can mislead users about what the skill is allowed to do.
The skill describes two-way synchronization and write operations against workspace files, but it does not prominently warn users that enabling the service can modify or overwrite notes and agent workspace data. In this context, the server is specifically designed to read and write files, so missing risk disclosure can lead to unintended data loss, corruption, or unsafe deployment assumptions.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.config/systemd/user
cat > ~/.config/systemd/user/openclaw-sync.service << 'EOF'
[Unit]
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
EOF
systemctl --user daemon-reload systemctl --user enable --now openclaw-sync loginctl enable-linger $USER # Start on boot
No suspicious patterns detected.