Back to skill

Security audit

TrustLog Guard

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent cost-tracking software, but it asks to scan all OpenClaw session logs and persists a local budget file with imperfect disclosure.

Install only if you are comfortable with the skill reading your OpenClaw session logs to calculate spend. Prefer using it on a specific agent or time range if your environment supports that, and check or clear the local budgets.json file when you no longer want saved budget settings.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:21
Finding

Overbroad Access to Sensitive OpenClaw Session Logs

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21–52
Vulnerability Type: Excessive local data access that violates least-privilege principles
Risk Level: Medium

Relevant Code Snippet:

markdown
Session logs are located at: `~/.openclaw/agents/{agent}/sessions/*.jsonl`
markdown
Read all `.jsonl` session files. Find every record with a `cost.total` field. Group costs by time period and by model.

Technical Analysis

The skill instructs the agent to read all JSONL session files under an OpenClaw agent directory. Such files may contain complete prompts, assistant responses, tool activity, and other sensitive session metadata. The stated financial-governance functionality only requires a limited set of fields, such as cost, model, timestamps, token counts, and a session identifier.

Although the instructions later claim that processing is local and that data is not transmitted externally, they do not technically or procedurally prevent the agent from reading unrelated message bodies and tool payloads while parsing each record. This creates unnecessary exposure of private conversation data and breaks the principle of least privilege.

No instruction to exfiltrate the accessed data, execute code, obtain system-level privileges, or bypass access controls was identified. The risk is therefore limited to excessive read access within the permissions already available to the hosting agent.

Attack Path

  1. A user installs or loads the skill in an agent that can access ~/.openclaw.
  2. The user invokes /spend, /budget, or /trustlog.
  3. The skill enumerates all matching files under ~/.openclaw/agents/{agent}/sessions/*.jsonl.
  4. The agent reads complete JSONL records rather than retrieving only cost-accounting fields.
  5. Private prompts, responses, tool activity, or metadata from unrelated sessions become available in the active agent context.
  6. A compromised agent, unsa ...[truncated 615 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace full session-log scanning with a dedicated cost ledger containing only billing and usage metadata.
  2. If session logs must be processed, explicitly allowlist only required fields such as cost.total, model, timestamp, token counts, and a non-sensitive session identifier.
  3. Explicitly prohibit reading, retaining, displaying, or forwarding message bodies, tool arguments, tool results, attachments, and credentials.
  4. Restrict scanning to the agent, sessions, and time range selected by the user rather than reading every available session by default.
  5. Require informed user confirmation before scanning multiple agents or historical sessions.
  6. Process each JSONL record in a streaming parser and immediately discard fields outside the allowlist so sensitive content is not introduced into the model context.
  7. Apply restrictive filesystem permissions to the session directory and budget configuration file.
  8. Document the precise data fields accessed and add tests that fail if conversation content or tool payloads are loaded.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill persists user-provided budget settings to disk, creating a durable local state file. While this is expected for a budgeting feature and the stored data is low sensitivity, persistence can still surprise users, create stale policy state, or leak usage preferences to other local users/processes if file permissions are not constrained.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

}

text

If the file doesn't exist, create it. If it exists, update only the field being set.

**Checking budget status:**
User says: `/budget`

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims it is "Read-only" and "Never modifies" local data, but earlier instructions explicitly direct writing and updating ~/.openclaw/workspace/trustlog-guard/budgets.json. This is a security-relevant integrity/privacy mismatch because users may grant trust under false assumptions about filesystem behavior, even though the write is limited to a local config file rather than arbitrary data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.