T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:21- Finding
Overbroad Access to Sensitive OpenClaw Session Logs
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 21–52
Vulnerability Type: Excessive local data access that violates least-privilege principles
Risk Level: MediumRelevant Code Snippet:
markdown Session logs are located at: `~/.openclaw/agents/{agent}/sessions/*.jsonl`markdown Read all `.jsonl` session files. Find every record with a `cost.total` field. Group costs by time period and by model.Technical Analysis
The skill instructs the agent to read all JSONL session files under an OpenClaw agent directory. Such files may contain complete prompts, assistant responses, tool activity, and other sensitive session metadata. The stated financial-governance functionality only requires a limited set of fields, such as
cost,model, timestamps, token counts, and a session identifier.Although the instructions later claim that processing is local and that data is not transmitted externally, they do not technically or procedurally prevent the agent from reading unrelated message bodies and tool payloads while parsing each record. This creates unnecessary exposure of private conversation data and breaks the principle of least privilege.
No instruction to exfiltrate the accessed data, execute code, obtain system-level privileges, or bypass access controls was identified. The risk is therefore limited to excessive read access within the permissions already available to the hosting agent.
Attack Path
- A user installs or loads the skill in an agent that can access
~/.openclaw. - The user invokes
/spend,/budget, or/trustlog. - The skill enumerates all matching files under
~/.openclaw/agents/{agent}/sessions/*.jsonl. - The agent reads complete JSONL records rather than retrieving only cost-accounting fields.
- Private prompts, responses, tool activity, or metadata from unrelated sessions become available in the active agent context.
- A compromised agent, unsa ...[truncated 615 chars]
- A user installs or loads the skill in an agent that can access
- Remediation
View remediation
Remediation Suggestions
- Replace full session-log scanning with a dedicated cost ledger containing only billing and usage metadata.
- If session logs must be processed, explicitly allowlist only required fields such as
cost.total, model, timestamp, token counts, and a non-sensitive session identifier. - Explicitly prohibit reading, retaining, displaying, or forwarding message bodies, tool arguments, tool results, attachments, and credentials.
- Restrict scanning to the agent, sessions, and time range selected by the user rather than reading every available session by default.
- Require informed user confirmation before scanning multiple agents or historical sessions.
- Process each JSONL record in a streaming parser and immediately discard fields outside the allowlist so sensitive content is not introduced into the model context.
- Apply restrictive filesystem permissions to the session directory and budget configuration file.
- Document the precise data fields accessed and add tests that fail if conversation content or tool payloads are loaded.
