Back to skill

Security audit

Session Logs Forensics

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate session-log forensics helper, but it broadly directs agents to search full historical chat transcripts without built-in consent, scoping, or redaction safeguards.

Install this only for trusted operators who are authorized to inspect OpenClaw session history. Use it against a specific session, date range, or incident whenever possible, and redact secrets, tokens, personal data, and unrelated transcript content before sharing results.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:9
Finding

Unrestricted Access to Complete Historical Session Transcripts

Content
View full analysis
/sessions/` (use the `agent=` value from the system prompt Runtime line). - **`sessions.json`** - Index mapping session keys to session IDs - **`.jsonl`** - Full conversation transcript per session ``` The skill also provides commands for extracting and searching transcript content: ```bash jq -r 'select(.message.role == "user") | .message.content[]? | select(.type == "text") | .text' .jsonl ``` ```bash rg -l "phrase" ~/.openclaw/agents//sessions/*.jsonl ``` ```bash jq -r 'select(.type=="message") | .message.content[]? | select(.type=="text") | .text' ~/.openclaw/agents//sessions/.jsonl | rg 'keyword' ``` ### Technical Analysis The skill directs an agent to access and search complete OpenClaw conversation transcripts. These files can contain user messages, assistant responses, tool results, personal information, credentials, operational details, and other sensitive material unrelated to the current request. Access to session history is consistent with the skill's stated forensic purpose, and the reviewed file does not contain a network-based exfiltration mechanism. However, the instructio ...[truncated 2316 chars]
Remediation
View remediation
/sessions/*.jsonl ``` 5. Add filtering and redaction for credentials, API keys, authorization headers, cookies, personal data, and sensitive tool output before displaying results. 6. Apply filesystem permissions that isolate session data by agent, user, tenant, and communication channel. 7. Limit returned excerpts to the minimum context needed and avoid reproducing complete transcripts. 8. Record an audit trail containing the requesting identity, authorization basis, selected sessions, search terms, and accessed files. 9. Require additional confirmation before accessing deleted-session artifacts or sessions associated with unrelated providers. 10. Clearly document that historical session access must not be used merely because filesystem permissions happen to permit it; access must also be authorized for the specific task. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs operators to search complete conversation history and session transcripts, which are likely to contain sensitive user prompts, model outputs, tool results, and potentially secrets or personal data. It provides broad access patterns and operational guidance without any warning, minimization guidance, or safeguards around handling sensitive data, increasing the risk of over-collection, unnecessary exposure, and privacy violations during routine use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.