T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/setup.mjs:380- Finding
Cross-Agent Memory Collection Violates Agent Isolation Boundaries
- Content
View full analysis
只有固化到系统文件时需要确认,其他全自动。 --- ## [P-001] 添加 Cron 定时任务 - **来源:** self-improve 安装 - **建议修改:** 在 openclaw.json 的 cron 中添加: \`\`\`json { "name": "self-improve", "schedule": { "kind": "cron", "expr": "${CRON_EXPR}", "tz": "${OWNER_TZ}" }, "sessionTarget": "isolated", "payload": { "kind": "agentTurn", "message": "你是 Self-Improve 系统的执行者。请按以下步骤执行:\\n1. 读取 ${ROOT.replace(/\\/g, '\\\\\\\\')}\\\\ENGINE.md 了解完整流程\\n2. 读取 ${ROOT.replace(/\\/g, '\\\\\\\\')}\\\\config.yaml 了解模块配置\\n3. ${workspaceScanInstruction}\\n4. 按执行顺序运行所有已启用模块\\n5. ${notificationInstruction}\\n6. 记录运行日志到 run-log.jsonl", "model": "${CRON_MODEL}" } } \`\`\` `; ``` The associated documentation explicitly establishes the shared-access behavior: ```markdown **All agents share this system.** When self-improve runs: 1. Scan `/path/to/self-improve/` (system-level, shared by all agents) 2. Read each agent's session logs (if accessible) 3. Write results to shared location, readable by all agents ``` ### Technical Analysis The setup script generates a recurring Agent task whose instructions direct the executing Agent to scan every Agent memory directory under the configured workspace. The results are intended to be written into a shared location readable by all Agents. Filesystem accessib ...[truncated 1657 chars]- Remediation
View remediation
