T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/monitor.cjs:189- Finding
Unnecessarily Broad Access to a Sensitive Environment File
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This security monitor is mostly aligned with its purpose, but it reads a root credential file, ignores the documented threat scoping option, and can run too aggressively in daemon mode due to broken interval parsing.
Review before installing. Run only under a tightly scoped account, avoid granting access to unrelated credential files, do not rely on --threats to limit what it checks, and avoid daemon mode until interval parsing and resource controls are fixed. Treat its logs and state files as sensitive security data.
scripts/monitor.cjs:189Unnecessarily Broad Access to a Sensitive Environment File
scripts/monitor.cjs:289Broken Interval Parsing Can Cause a Near-Continuous Monitoring Loop
scripts/monitor.cjs:225Threat Selection Is Ignored and All Monitoring Checks Always Execute
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
function checkFileChanges() {
// Check for unexpected file changes
const watchPaths = [
'/root/clawd/skills/.env',
'/root/clawd/config',
'/root/clawd/.env'
];
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
function checkFileChanges() {
// Check for unexpected file changes
const watchPaths = [
'/root/clawd/skills/.env',
'/root/clawd/config',
'/root/clawd/.env'
];
At this line the script directly reads /root/clawd/skills/.env, which is a credential-bearing file. Direct secret-file access by a continuously running monitor significantly increases the blast radius of any compromise of the monitor process and is especially concerning here because the stated purpose can be achieved without reading raw credentials.
// This is a simplified check - real implementation would need API integration
try {
const envContent = fs.readFileSync('/root/clawd/skills/.env', 'utf8');
if (envContent.includes('TWITTER') || envContent.includes('KAPSO')) {
log('INFO', 'API credentials present', {
The skill advertises Telegram alerts without warning that security event data may be sent to a third-party service. In a security-monitoring context, alerts can include sensitive metadata about hosts, credentials usage patterns, or incidents, so undisclosed external transmission increases privacy and operational security risk.
The manifest description promises detection of unusual API calls and credential usage patterns. In code, the only API-related logic reads an environment file and logs whether certain service names appear, which does not analyze API call behavior or usage patterns.
The monitor reads a sensitive .env file and inspects its contents to infer which credential-bearing services are configured. That exceeds simple health monitoring and unnecessarily accesses secrets, increasing exposure risk if the process, logs, state, or future code paths are compromised. In this skill context, a security monitor should minimize secret access, so this behavior is more dangerous than in a credential-management tool.
The script reads a sensitive credential file without any necessity visible to the user and without a clear disclosure or least-privilege boundary. Even though it currently only searches for service names, accessing secret-bearing files widens the trust boundary and can lead to accidental exposure through future debugging, crashes, or feature creep.
This markdown file states that JSON logs are written to /root/clawd/clawdbot-security/logs/alerts.log, which is a file write affecting local system state. Under the markdown criteria for missing user warnings, the description should explicitly warn users that monitoring results will be persisted on disk, especially at a privileged-looking path, rather than only listing it as output.
Detected: suspicious.dangerous_exec