T09 · Insecure Skill Coding Practices
- Location
scripts/expnote.py:62- Finding
Potentially Sensitive Experiment Data Stored in Plaintext Without Enforced Access Controls
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently provides local experiment logging, but its plaintext persistent notes can expose secrets if users or agents record raw commands or errors.
Install only if you are comfortable keeping local plaintext experiment history. Configure agents and users to avoid logging secrets, tokens, credentials, private customer data, full auth headers, or raw dumps, and periodically delete or protect ~/.openclaw/memory/experiments/ if the machine or backups are shared.
scripts/expnote.py:62Potentially Sensitive Experiment Data Stored in Plaintext Without Enforced Access Controls
The skill clearly describes persistent local storage under ~/.openclaw/memory/experiments/ and references a Python CLI that reads and writes files, but it does not declare any tool scope such as permissions or allowed-tools. That creates a transparency and policy gap: an agent or reviewer cannot easily constrain or audit the file access the skill requires, increasing the chance of unintended writes or broader-than-expected local data access.
The skill advertises automatic logging of trial-and-error, commands, failures, and lessons learned, but provides no warning against recording secrets, tokens, credentials, personal data, or sensitive command output. In practice, experiment logs often contain raw CLI arguments, stack traces, URLs, headers, and environment-derived values, so persistent storage without caution can leak sensitive data into local memory files.
The installation section states that experiment records are stored persistently in ~/.openclaw/memory/experiments/ but omits any notice about privacy, retention, access control, or cleanup. Persistent local logs materially increase exposure because sensitive operational details can remain on disk indefinitely and be read later by other tools, users, backups, or processes.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
The agent guidance explicitly tells the agent to log every attempt, including executed commands and raw error output, regardless of success or failure. Commands and error output are high-risk fields for secret exposure because they frequently contain API keys, auth headers, internal hostnames, filesystem paths, customer data, or debug dumps; persisting them into local memory creates a durable exfiltration and privacy risk.
The skill persistently stores free-form experiment data under the user's home directory, including task descriptions, commands, errors, fixes, and lessons, without any notice, consent prompt, minimization, or retention controls. In an agent context, those fields can easily contain secrets, internal paths, tokens, proprietary prompts, or sensitive failure logs, so silent disk persistence increases the risk of privacy leakage and later compromise from local file access or backup/sync exposure.
No suspicious patterns detected.