T09 · Insecure Skill Coding Practices
- Location
lib/mailbox.js:220- Finding
Arbitrary Local File Read Through Mailbox Path Traversal
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
ClawLink is a real encrypted-messaging skill, but verified flaws could expose local message/key files and feed untrusted remote messages into the agent heartbeat.
Install only after review or fixes. Treat ClawLink messages as untrusted remote content, confirm the exact recipient and text before sending, avoid sensitive conversations until mailbox path validation and cryptographic verification are fixed, and protect or regularly delete ~/.openclaw/clawlink because decrypted messages and shared secrets can remain there.
lib/mailbox.js:220Arbitrary Local File Read Through Mailbox Path Traversal
heartbeat.js:87Untrusted Remote Messages Are Injected Directly Into Agent Heartbeat Output
lib/requests.js:191Incoming Friend Acceptance Does Not Cryptographically Bind the Claimed Identity to the Key-Exchange Key
lib/mailbox.js:57Shared Secrets and Plaintext Mailbox Files Are Created Without Restrictive Permissions
If the implementation reads identity material from disk and prints request, signature, or key-related metadata for debugging, that creates a genuine security risk for a cryptographic messaging system. Even partial disclosure of sensitive material or verbose authentication traces can aid compromise, leak operational secrets, or expose users through logs.
If the implementation reads identity material from disk and prints request, signature, or key-related metadata for debugging, that creates a genuine security risk for a cryptographic messaging system. Even partial disclosure of sensitive material or verbose authentication traces can aid compromise, leak operational secrets, or expose users through logs.
If the implementation reads identity material from disk and prints request, signature, or key-related metadata for debugging, that creates a genuine security risk for a cryptographic messaging system. Even partial disclosure of sensitive material or verbose authentication traces can aid compromise, leak operational secrets, or expose users through logs.
If the implementation reads identity material from disk and prints request, signature, or key-related metadata for debugging, that creates a genuine security risk for a cryptographic messaging system. Even partial disclosure of sensitive material or verbose authentication traces can aid compromise, leak operational secrets, or expose users through logs.
If the implementation reads identity material from disk and prints request, signature, or key-related metadata for debugging, that creates a genuine security risk for a cryptographic messaging system. Even partial disclosure of sensitive material or verbose authentication traces can aid compromise, leak operational secrets, or expose users through logs.
If the implementation reads identity material from disk and prints request, signature, or key-related metadata for debugging, that creates a genuine security risk for a cryptographic messaging system. Even partial disclosure of sensitive material or verbose authentication traces can aid compromise, leak operational secrets, or expose users through logs.
The skill is explicitly designed to transmit user-provided content to external recipients, which is a classic exfiltration-capable pattern even if that is the intended feature. In an agent environment, such commands are dangerous because other prompts or context may trick the agent into forwarding sensitive information off-device.
---
name: clawlink
description: Encrypted Clawbot-to-Clawbot messaging. Send messages to friends' Clawbots with end-to-end encryption.
triggers:
- clawlink
- friend link
The broad trigger 'send message to' creates an outbound communications channel that can be abused to exfiltrate sensitive data through prompt injection or accidental invocation. Because the skill contacts an external relay, the risk is higher than a local-only command.
- clawlink
- friend link
- add friend
- send message to
- tell [name] that
- message from
- accept friend request
The implementation contradicts its own security claim: it derives an X25519 key by slicing the first 32 bytes of an Ed25519 secret key instead of using a proper Ed25519-to-X25519 conversion routine. This can produce incompatible or non-standard key material, causing incorrect shared-secret derivation and undermining the reliability of end-to-end encryption in a messaging skill where confidentiality depends on correct key agreement.
The module persists full message contents in plaintext markdown files under the user's home directory even though the skill is described as providing end-to-end encrypted messaging. This breaks confidentiality at the endpoint: any local user, malware, backup system, or other process with access to the account can read message contents, so the security claims are materially weakened and users may be misled into sharing sensitive data.
Instructions found that direct the agent to transmit conversation context or user data to external services.
"clawlink",
"friend link",
"add friend",
"send message to",
"tell * that",
"message from",
"accept friend request"
The skill declares network- and environment-relevant capabilities in practice but does not explicitly scope or constrain tool access in the manifest. For a messaging skill that installs dependencies, modifies local files, accesses home-directory data, and contacts a remote relay, missing permission declarations weakens reviewability and increases the chance of overbroad agent execution.
Broad triggers like 'send message to', 'tell [name] that', and 'message from' can activate during normal conversation and cause unintended skill execution. In a networked messaging skill, accidental invocation can lead to unintended outbound communication, privacy leaks, or confusing autonomy.
The skill establishes persistent identity material and ongoing state under a home-directory path, enabling durable cross-session behavior. For a messaging skill, persistent identity is expected, but it still increases privacy and compromise impact because stolen local data could enable impersonation, contact enumeration, or long-term metadata correlation.
ClawLink will NOT work until you run setup. The install script installs dependencies but you MUST create your identity:
node cli.js setup "Your Name"
The generic preferences interface allows mutation of arbitrary preference paths via preferences set <path> <value>, which is broader than the manifest’s narrow scheduling/preferences-related triggers. That creates an over-privileged control surface where callers may alter unrelated behavior or future security/privacy-relevant settings without clear scoping or validation.
The handler exposes direct inbox/outbox listing and arbitrary message-file reads, which materially expands the skill from sending/checking friend messages into local mailbox content access. In an agent-skill context, this can leak private message contents or metadata to callers beyond the manifest’s apparent user expectation, especially because filenames are accepted from arguments and no higher-level authorization or scope checks are visible here.
Incoming message contents are automatically persisted to the local inbox, including text and metadata, without any indication in this layer that the user has consented to storage or understands retention behavior. In a messaging skill handling potentially sensitive end-to-end encrypted communications, silent local persistence increases privacy risk if the host device, profile directory, or backups are later accessed by another party.
Outgoing messages are saved to a local outbox after transmission, preserving plaintext message text and associated metadata without any explicit disclosure in this code path. Because this skill is specifically for private friend-to-friend messaging, undisclosed local retention weakens the user's privacy expectations and creates an additional source of sensitive data exposure on disk.
This code generates an identity keypair and returns the private key as a base64 string, which is a safety-sensitive credential operation. Although the function has a technical docstring, there is no user-facing warning, confirmation, or disclosure about the creation and exposure of a long-term secret key.
The createInvite flow sends the user's public key, X25519 public key, display name, timestamp, and signature to a network endpoint. This network transmission of identity-related data has no visible confirmation prompt or user-facing disclosure in the code, so users may not realize what information is being shared externally.
The claimInvite flow posts the invite token plus the claimer's public key, X25519 public key, display name, timestamp, and signature to the relay. Because there is no prompt, warning, or user-visible message explaining this transmission, the file lacks disclosure for a privacy-relevant network operation.
When an invite is approved, the code persists a new friend record containing public keys and a derived shared secret to ~/.openclaw/clawlink/friends.json. Although the operation is commented for developers, there is no confirmation prompt, user-facing log, or warning in this file to disclose that sensitive relationship and cryptographic material is being stored locally.
Sent message content is written to disk persistently without any user-facing notice, opt-in, or indication that 'encrypted' messages will be retained locally in readable form. In a messaging skill, users may reasonably expect confidentiality, so silent retention increases privacy risk and can expose sensitive content through local compromise, shared accounts, backups, or forensic collection.
Received messages are also stored persistently on disk without warning or consent, creating a privacy exposure for inbound content that may be especially sensitive because it originates from other parties who may assume end-to-end encrypted handling. The skill context makes this more dangerous because the product branding and description can cause users to overtrust the confidentiality of locally retained data.
The code forces the 'en-US' locale when computing quiet-hours time strings. This is a natural-language/locale policy issue because it imposes a specific locale choice rather than using the user's locale or documenting why that locale is required.
Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal