Back to skill

Security audit

session-logs

Security checks for vulnerabilities and agentic risk

Overview

The skill is for searching conversation history, but it broadly directs agents to search reset and deleted transcripts without clear user confirmation or scoping.

Install only if you want agents to inspect your stored OpenClaw conversation logs. Before using it, ask the agent to limit searches to specific sessions, dates, or phrases, and require explicit confirmation before reading reset or deleted transcript archives.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:39
Finding

Unrestricted Retrieval of Active, Reset, and Deleted Conversation Transcripts

Content
View full analysis
/sessions/` (default: `~/.openclaw/agents//sessions/`). Use the `agent=` value from the system prompt Runtime line. - **`sessions.json`** - Index mapping session keys to session IDs - **`.jsonl`** - Full conversation transcript per session - **`.jsonl.reset.Z`** - Transcript archived by `/new` or `/reset` - **`.jsonl.deleted.Z`** - Transcript archived when a session was deleted When searching history, include the archived (`.reset.*`, `.deleted.*`) variants too — they still contain real conversation content. The plain-glob examples below only catch the active `*.jsonl` files; use the "Include archived transcripts" snippet when you need full recall. ``` Additional affected instructions include user-message extraction at lines 116–123 and searches across all active and archived sessions at lines 174–185. ### Technical Analysis The skill directs the agent to access the complete session storage directory and explicitly encourages searching transcripts archived after a reset or deletion. These files can contain sensitive personal information, authentication material pasted into conversations, proprietary data, and contextual information unrelated to the current request. This design does not exploit an operating-system permission vulnerability; it relies on whatever filesystem access the agent already possesses. However, it breaks least-privilege boundaries at the application level by defaulting to broad historical access rather than limiting retrieval to a specifically identified session, date range, or conversation. Deleted and reset records are especially sensitive because users m ...[truncated 1909 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to search complete conversation history, including archived reset and deleted transcripts, but provides no warning, consent requirement, or access-control boundary around highly sensitive historical content. This is dangerous because deleted/reset logs may contain information the user expected to be inaccessible in normal operation, so using them can violate privacy expectations and leak retained secrets from prior sessions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger guidance is broad enough to invoke this skill whenever a user mentions prior chats or historical context, without requiring confirmation that searching stored logs is necessary or appropriate. In this context, accidental invocation can expose sensitive historical transcript data beyond the current conversation scope, especially because the skill explicitly targets complete session history.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.