T05 · Unauthorized Access and Privilege Escalation
- Location
hooks/dual-brain/handler.js:141- Finding
Undisclosed Collection and External Transmission of Session Transcripts and Memory Context
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a real multi-LLM perspective tool, but it can automatically read local agent transcripts and memory, send them to LLM providers, inject provider output into agent context, and run persistently beyond the documented keyword trigger.
Review carefully before installing. Use it only if you are comfortable with agent messages and memory/context snippets being sent to configured LLM providers and then reintroduced into agent context. Prefer local Ollama, set owner/session scoping, avoid the daemon unless you need continuous monitoring, restrict credential file permissions, and do not rely on the documented mb keyword unless the implementation is fixed to enforce it.
hooks/dual-brain/handler.js:141Undisclosed Collection and External Transmission of Session Transcripts and Memory Context
hooks/dual-brain/handler.js:158Untrusted External LLM Output Injected into Privileged Agent Bootstrap Context
src/cli.js:207Boot and Login Persistence for a Continuous Transcript-Monitoring Service
src/config.js:35Provider API Keys Stored in Plaintext Without Enforced Restrictive Permissions
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
**Daemon won't start:**
- Check if already running: `dual-brain status`
- Clean up stale PID: `rm ~/.dual-brain/dual-brain.pid`
- Check config is valid: `cat ~/.dual-brain/config.json`
## Files & Directories
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# Remove LaunchAgent (macOS)
launchctl unload ~/Library/LaunchAgents/com.dual-brain.plist
rm ~/Library/LaunchAgents/com.dual-brain.plist
# Remove systemd service (Linux)
sudo systemctl stop dual-brain
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# Remove systemd service (Linux)
sudo systemctl stop dual-brain
sudo systemctl disable dual-brain
sudo rm /etc/systemd/system/dual-brain.service
sudo systemctl daemon-reload
# Uninstall package
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
npm uninstall -g openclaw-dual-brain
rm -rf ~/.dual-brain
## Development
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
npm uninstall -g openclaw-dual-brain
rm -rf ~/.dual-brain
## Development
The code automatically forwards user conversations plus local memory-derived context to a second model, then writes the resulting perspective to a shared location consumed by other agents. This creates both external disclosure risk and cross-agent information propagation, allowing potentially sensitive or untrusted content to spread beyond the original session boundary.
User messages and local business context are automatically transmitted to a third-party model API with no user-facing notice, consent, or approval step. In an agent environment, this creates a clear confidentiality and privacy risk because sensitive prompts, internal instructions, or regulated data may be exfiltrated off-system transparently.
The prompt instruction 'Never refuse or say you need more context' attempts to suppress normal safety and uncertainty behaviors of the external model. In this context, it increases the likelihood of overconfident, unsafe, or privacy-invasive outputs being generated from incomplete or sensitive user messages and then propagated to other agents.
- What might ${agentId} miss?
- What's a different angle?
- What should be verified?
Be direct. Never refuse or say you need more context.
Business context: ${context.slice(0, 1000)}`
},
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
return true;
});
for (const k of staleKeys) {
delete state.offsets[k];
delete state.lastProcessed[k];
}
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
return true;
});
for (const k of staleKeys) {
delete state.offsets[k];
delete state.lastProcessed[k];
}
The code sends the user's last message and local memory context to an external API with no user-facing notice, consent, or opt-in. Because this occurs during bootstrap, users and operators may not realize their content is being exported to a third party, raising privacy, compliance, and data handling risks.
The prompt explicitly embeds user-provided content and slices of a local memory file into a request sent to a third-party model. This is a direct silent data disclosure path that can expose sensitive conversation details and internal notes outside the local environment.
The system prompt includes 'Never refuse,' which pressures the external model to produce output regardless of safety, appropriateness, or uncertainty. In a security-sensitive augmentation path, this increases the chance of low-integrity, policy-bypassing, or manipulative content being injected into the agent's context.
- What might the agent miss?
- What's a different angle or risk?
- What should be verified?
Be direct and concise. Never refuse.
Context: ${context.slice(0, 1000)}`
},
The hook reads sensitive local data from the agent transcript and a local memory file, then sends that content to a third-party API during bootstrap. In this context, the behavior is more dangerous because it happens automatically and covertly as part of agent startup, with no visible consent, filtering, or minimization beyond truncation.
The hook frames disclosure of user messages and local memory as a harmless 'second perspective' feature, but it silently relays both to a secondary model. This is dangerous because the framing can mask a substantive data-sharing and trust-boundary change, especially in a bootstrap hook that runs automatically.
The explicit anti-refusal instruction 'Never refuse' is a strong signal that the secondary model is being pushed to answer regardless of safety concerns. This is dangerous because the resulting output is later fed into the agent bootstrap context, potentially introducing unsafe, low-integrity, or manipulative recommendations.
- What might the agent miss?
- What's a different angle or risk?
- What should be verified?
Be direct and concise. Never refuse.
Context: ${context.slice(0, 1000)}`
},
The daemon enumerates local agent session directories, reads recent .jsonl session files, parses user messages, and processes them automatically. This is a surveillance-style capability over local conversation history; even though it appears to support the feature's design, it exposes sensitive user content at scale without strong authorization, notice, or narrow scoping.
The system prompt explicitly instructs the model to 'Never refuse or say you need more context,' which weakens safety behavior and encourages the model to answer even when the request is unsafe, ambiguous, or missing critical information. In a second-opinion agent workflow, this can produce overconfident harmful guidance and undermine guardrails that would normally block dangerous or policy-violating output.
- What might ${agentId} miss?
- What's a different angle?
- What should be verified?
Be direct. Never refuse or say you need more context.
${context ? `Context: ${context.slice(0, 1000)}` : ''}`;
The system prompt explicitly instructs the external model to 'Never refuse or say you need more context,' which weakens safety behavior and pressures the model to answer even when the request is unsafe, uncertain, or lacks sufficient context. In a decision-support agent, this can increase the chance of harmful, misleading, or overconfident output being returned to the primary agent.
- What might ${agentId} miss?
- What's a different angle?
- What should be verified?
Be direct. Never refuse or say you need more context.
${context ? `Business context: ${context.slice(0, 1000)}` : ''}`;
The system prompt explicitly instructs the model to 'Never refuse or say you need more context,' which weakens safety behavior and encourages the model to answer even when the request is unsafe, ambiguous, or lacks sufficient information. In a 'second perspective' component, this can amplify harmful guidance, reduce appropriate uncertainty signaling, and make downstream agents more likely to act on low-quality or unsafe advice.
- What might ${agentId} miss?
- What's a different angle?
- What should be verified?
Be direct. Never refuse or say you need more context.
${context ? `Context: ${context.slice(0, 1000)}` : ''}`;
The system prompt instructs the model to 'Never refuse or say you need more context,' which suppresses normal safety behavior and encourages confident answers even when the request is unsafe, ambiguous, or lacks necessary information. In a security-sensitive agent workflow, this increases the chance of harmful guidance, hallucinated assertions, or bypass of provider-side safety norms.
- What might ${agentId} miss?
- What's a different angle?
- What should be verified?
Be direct. Never refuse or say you need more context.
${context ? `Context: ${context.slice(0, 1000)}` : ''}`;
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
│ └── ollama.js # Local Ollama models └── daemon/ ├── install.sh # Shell installer (macOS/Linux) ├── com.dual-brain.plist # macOS LaunchAgent template └── dual-brain.service # Linux systemd unit template
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
│ └── ollama.js # Local Ollama models └── daemon/ ├── install.sh # Shell installer (macOS/Linux) ├── com.dual-brain.plist # macOS LaunchAgent template └── dual-brain.service # Linux systemd unit template
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
│ └── ollama.js # Local Ollama models └── daemon/ ├── install.sh # Shell installer (macOS/Linux) ├── com.dual-brain.plist # macOS LaunchAgent template └── dual-brain.service # Linux systemd unit template
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
│ └── ollama.js # Local Ollama models └── daemon/ ├── install.sh # Shell installer (macOS/Linux) ├── com.dual-brain.plist # macOS LaunchAgent template └── dual-brain.service # Linux systemd unit template
Detected: suspicious.dangerous_exec