T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/ws-client.js:319- Finding
Remote ClawdTalk Events Can Inject Instructions into the Fully Privileged Main Agent Session
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is disclosed as a voice/SMS bridge, but it gives remote call and message flows broad access to the user's main agent with weak approval boundaries.
Install only if you are comfortable letting ClawdTalk phone calls, SMS, and cloud events reach your main agent session and its connected tools. Before using it, restrict sessions_send to the narrowest possible scope, avoid storing live gateway tokens in skill-config.json, keep approval fail-closed, remove voice-only approval fallback for sensitive actions, and review update/dependency handling.
scripts/ws-client.js:319Remote ClawdTalk Events Can Inject Instructions into the Fully Privileged Main Agent Session
scripts/ws-client.js:426Sensitive Actions Fail Open When Approval Devices Are Unavailable
scripts/ws-client.js:356Remote WebSocket Messages Can Select Arbitrary Local Agent Sessions
setup.sh:176ClawdTalk and Gateway Bearer Tokens Are Duplicated into a Plaintext Configuration File
scripts/ws-client.js:1041WebSocket Client Installs a Mutable Dependency at Runtime Through a Shell
update.sh:33Self-Updater Retrieves and Installs Mutable Remote Code from a Single Trust Authority
SKILL.md:67Skill Instructions Mandate Excessive Local and Remote Persistence of Operational Data
The request destination is derived from environment/config-controlled BASE_URL and then used directly in urllib.request.urlopen while automatically attaching the Bearer API key. If an attacker can influence CLAWDTALK_API_URL or the skill-config server value, they can redirect authenticated requests to an attacker-controlled host and exfiltrate credentials and mission data.
req = urllib.request.Request(url, data=body, headers=headers, method=method)
try:
with urllib.request.urlopen(req, timeout=60) as response:
response_body = response.read().decode("utf-8")
if response_body:
return json.loads(response_body)
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- Call reports now appear in your Telegram/Discord/etc. session instead of ephemeral sessions
## 1.2.7
- **New**: `update.sh` script for easy self-updates from GitHub
- **New**: `dist/clawdtalk-client-latest.zip` in repo for direct downloads
- Run `./update.sh` to check for and install updates
The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.
The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.
The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.
The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.
The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.
The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.
The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.
The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.
The documentation indicates the skill can update its own configuration and references update behavior elsewhere, which is risky in combination with remote downloads and package installation. Self-modification or self-update mechanisms can be abused for persistence or supply-chain compromise if not strongly verified and user-approved.
## Troubleshooting
- **Auth failed**: Regenerate API key at clawdtalk.com
- **Gateway token/port changed**: Re-run `./setup.sh` to update skill-config.json with the new values
- **Empty responses**: Run `./setup.sh` and restart gateway
- **Slow responses**: Try a faster model in your gateway config
- **Debug mode**: `DEBUG=1 ./scripts/connect.sh restart`
The lockfile pins the project to ws 8.19.0, and the supplied advisory data indicates this version is affected by an uninitialized memory disclosure and a memory-exhaustion denial-of-service issue. Because this skill is a voice/SMS/WebSocket client, ws is likely used on a network-facing code path, which makes remotely triggered information leakage or service disruption more plausible and increases operational risk.
The allowed dependency range can resolve to ws 8.19.0, which is reported as affected by memory disclosure and memory-exhaustion denial-of-service vulnerabilities. In a voice/SMS client, WebSocket connectivity is likely network-facing or processes untrusted remote traffic, making crashes, resource exhaustion, or unintended data exposure more consequential.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Find .env files
local env_files=(
"$HOME/.openclaw/.env"
"$HOME/.clawdbot/.env"
"$SKILL_DIR/.env"
)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Find .env files
local env_files=(
"$HOME/.openclaw/.env"
"$HOME/.clawdbot/.env"
"$SKILL_DIR/.env"
)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Find .env files
local env_files=(
"$HOME/.openclaw/.env"
"$HOME/.clawdbot/.env"
"$SKILL_DIR/.env"
)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#
# Usage: ./connect.sh {start|stop|status|restart} [--server <url>]
#
# Env vars: via .env
# Endpoints: none (launches ws-client.js)
# Reads: skill-config.json, .env
# Writes: .connect.pid, .connect.log
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#
# Usage: ./connect.sh {start|stop|status|restart} [--server <url>]
#
# Env vars: via .env
# Endpoints: none (launches ws-client.js)
# Reads: skill-config.json, .env
# Writes: .connect.pid, .connect.log
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#
# Usage: ./connect.sh {start|stop|status|restart} [--server <url>]
#
# Env vars: via .env
# Endpoints: none (launches ws-client.js)
# Reads: skill-config.json, .env
# Writes: .connect.pid, .connect.log
The script sources $SKILL_DIR/.env directly with the shell '.' operator, which executes the file as shell code rather than safely parsing key-value pairs. If the .env file is modified by an attacker or contains unexpected shell syntax, arbitrary commands will run with the privileges of the user starting the connection.
echo "🚀 Starting WebSocket connection..."
# Source skill's own .env if it exists (for skill-specific env vars only)
[ -f "$SKILL_DIR/.env" ] && . "$SKILL_DIR/.env"
# Rotate log if it's too big (> 1MB)
This line is the same direct sourcing of the skill-local .env file and therefore enables arbitrary shell execution from what users may assume is passive configuration data. In an agent skill context, this is especially risky because setup artifacts and working directories may be writable by automation or other tools.
echo "🚀 Starting WebSocket connection..."
# Source skill's own .env if it exists (for skill-specific env vars only)
[ -f "$SKILL_DIR/.env" ] && . "$SKILL_DIR/.env"
# Rotate log if it's too big (> 1MB)
if [ -f "$LOG_FILE" ] && [ $(stat -f%z "$LOG_FILE" 2>/dev/null || stat -c%s "$LOG_FILE" 2>/dev/null || echo 0) -gt 1048576 ]; then
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
BASE_URL = _get_base_url()
def get_api_key():
"""Get API key from env var or skill-config.json."""
key = os.environ.get("CLAWDTALK_API_KEY")
if key:
return key
The header claims the script writes nothing, but the code later performs package installation that writes to disk and can alter the execution environment. This mismatch is security-relevant because operators may trust the file comment when evaluating whether the client is safe to run on a host.
The embedded approval narrative permits fallback from push approval to simple voice assent such as 'yes' or 'go ahead' for sensitive actions. In a voice channel, that weakens authentication and makes social engineering, spoofed callers, accidental assent, or STT transcription errors materially more likely to authorize destructive operations.
The injected voicePrefix tells the downstream agent not to request approval because it has 'already been handled' and to perform the action directly. Combined with the weak/skip approval branches, this suppresses downstream safeguards and can cause sensitive actions to execute even when robust authorization was never actually obtained.
Detected: suspicious.credential_exposure_instructions, suspicious.dangerous_exec, suspicious.env_credential_access (+1 more)