T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:9- Finding
Unrestricted Access to Complete Historical Session Transcripts
- Content
View full analysis
/sessions/` (use the `agent=` value from the system prompt Runtime line). - **`sessions.json`** - Index mapping session keys to session IDs - **`.jsonl`** - Full conversation transcript per session ``` The skill also provides commands for extracting and searching transcript content: ```bash jq -r 'select(.message.role == "user") | .message.content[]? | select(.type == "text") | .text' .jsonl ``` ```bash rg -l "phrase" ~/.openclaw/agents//sessions/*.jsonl ``` ```bash jq -r 'select(.type=="message") | .message.content[]? | select(.type=="text") | .text' ~/.openclaw/agents//sessions/.jsonl | rg 'keyword' ``` ### Technical Analysis The skill directs an agent to access and search complete OpenClaw conversation transcripts. These files can contain user messages, assistant responses, tool results, personal information, credentials, operational details, and other sensitive material unrelated to the current request. Access to session history is consistent with the skill's stated forensic purpose, and the reviewed file does not contain a network-based exfiltration mechanism. However, the instructio ...[truncated 2316 chars]- Remediation
View remediation
/sessions/*.jsonl ``` 5. Add filtering and redaction for credentials, API keys, authorization headers, cookies, personal data, and sensitive tool output before displaying results. 6. Apply filesystem permissions that isolate session data by agent, user, tenant, and communication channel. 7. Limit returned excerpts to the minimum context needed and avoid reproducing complete transcripts. 8. Record an audit trail containing the requesting identity, authorization basis, selected sessions, search terms, and accessed files. 9. Require additional confirmation before accessing deleted-session artifacts or sessions associated with unrelated providers. 10. Clearly document that historical session access must not be used merely because filesystem permissions happen to permit it; access must also be authorized for the specific task. ]]>
