Back to skill

Security audit

OpenClaw Session Log Forensics

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent session-log forensics helper, but it can search complete cross-session conversation history with broad triggers and no clear confirmation, scoping, or redaction controls.

Install only if operators are allowed to inspect the selected agent's historical session logs. Before use, require an explicit scope such as a session ID, date range, or incident window, and avoid returning unrelated transcript content or secrets from prior conversations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:9
Finding

Unrestricted Cross-Session Conversation History Access

Content
View full analysis
/sessions/` (use the `agent=` value from the system prompt Runtime line). - **`sessions.json`** - Index mapping session keys to session IDs - **`.jsonl`** - Full conversation transcript per session ``` ```markdown ### Search across ALL sessions for a phrase ```bash rg -l "phrase" ~/.openclaw/agents//sessions/*.jsonl ``` ``` ### Technical Analysis The skill instructs the agent to access complete historical conversation transcripts and provides a wildcard command for searching every session belonging to an agent. Session JSONL files may contain user and assistant messages, tool calls, tool results, identifiers, operational details, and other sensitive information. The instructions do not establish authorization boundaries such as requiring an explicitly identified session, confirming that the requester is entitled to access the selected history, limiting searches to the minimum necessary scope, or redacting unrelated sensitive data before returning results. A request for historical context can therefore cause the agent to inspect sessions unrelated to the current request. This violates least-privilege and data-minimization principles. The issue concerns access to data already readable by the ...[truncated 1425 chars]
Remediation
View remediation
" SESSION_FILE="$HOME/.openclaw/agents//sessions/${SESSION_ID}.jsonl" jq -r ' select(.type == "message") | select(.message.role == "user" or .message.role == "assistant") | .message.content[]? | select(.type == "text") | .text ' "$SESSION_FILE" | rg -i --fixed-strings -- "" ``` 10. Validate `SESSION_ID` against a strict identifier format and verify the resolved path remains inside the authorized session directory before reading it. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directly instructs access to complete conversation history in local session logs but does not prominently warn that it may search data outside the current conversation context. Users may not realize that invoking the skill exposes prior sessions, potentially including sensitive prompts, tool outputs, or personal data, making this a transparency and privacy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger is broad enough to activate on ordinary references to prior conversation, which can cause the agent to search complete local session history without a clearly narrow user request. Because this skill operates over all stored session logs, over-triggering increases the chance of unnecessary access to sensitive historical data and privacy leakage beyond user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.