T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:26- Finding
Overbroad Access to Sensitive Agent State and Memory Files
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:26-36
Vulnerability Type: Excessive access to persistent agent state
Risk Level: MediumVulnerable Code
markdown ## Platform Detection Detect which platform(s) are present, then scan the corresponding constraint files. ```bash test -f CLAUDE.md && echo "CLAUDE_CODE" test -f openclaw.json && echo "OPENCLAW" test -f .cursorrules && echo "CURSOR" test -f .github/copilot-instructions.md && echo "COPILOT"Claude Code:
CLAUDE.md(monolithic),.claude/commands/*.mdOpenClaw:agents.md(priority 10),soul.md(20),identity.md(30),user.md(40),tools.md(50),bootstrap.md(60),memory.md(70). SkipSAFETY.md(hardcoded, read-only). Cursor:.cursorrulesCopilot:.github/copilot-instructions.mdGeneric:AGENT.md,SOUL.md,README.mdconventions sectionsRead ALL found files. Extract every rule, convention, and constraint.
text ### Technical Analysis The Skill explicitly directs the agent to read every detected OpenClaw context file, including `identity.md`, `user.md`, `bootstrap.md`, and `memory.md`. These files can contain persistent memories, personal preferences, identity constraints, operational details, or other sensitive state that is not necessarily required to convert coding conventions into automated tools. This violates least-privilege principles because access is mandatory rather than limited to files selected by the user or directly relevant to the requested rule conversion. The Skill also permits generated reports and tooling, creating a risk that sensitive content encountered during scanning could be reproduced in generated artifacts or conversation output. No network exfiltration, credential harvesting, or direct bypass of operating-system permissions was found. The risk is confined to unnecessary access through permissions already available to the ...[truncated 1215 chars]- Remediation
View remediation
Remediation Suggestions
- Default scanning to rule-oriented files such as
tools.md,CLAUDE.md, and explicitly selected project instruction files. - Require informed user confirmation before reading
identity.md,user.md,bootstrap.md, ormemory.md. - Display the exact proposed file list before any content is read.
- Add exclusion controls so users can omit sensitive state files or directories.
- Apply secret and personal-data redaction before including extracted rules in reports or generated artifacts.
- Prohibit copying memory, identity, or user-profile content into generated configurations unless the user explicitly approves the exact content.
- Preserve the existing prohibition against modifying
SAFETY.mdand extend it to prevent automatic rewriting of memory and identity files.
- Default scanning to rule-oriented files such as
