T09 · Insecure Skill Coding Practices
- Location
skill.js:53- Finding
Sensitive configuration and agent-state snapshots lack explicit restrictive permissions
- Content
View full analysis
Vulnerability Details
File Location:
skill.js, lines 53-87
Vulnerability Type: Insecure storage of sensitive local data
Risk Level: MediumVulnerable Code
js function snapshot({ reason }) { const workspace = path.join(os.homedir(), '.openclaw', 'workspace'); const snapRoot = path.join(workspace, '.sandbox_snapshots_lite'); fs.mkdirSync(snapRoot, { recursive: true }); const snapId = new Date().toISOString().replace(/[:.]/g, '-'); const dir = path.join(snapRoot, snapId); fs.mkdirSync(dir); const targets = [ path.join(os.homedir(), '.openclaw', 'openclaw.json'), path.join(workspace, 'AGENTS.md'), path.join(workspace, 'SOUL.md'), path.join(workspace, 'CURRENT_STATE.md'), path.join(workspace, 'MEMORY.md'), ]; const manifest = { __sdna__, kind: 'snapshot', snapId, reason: reason || '', createdAt: nowKST(), files: [], }; for (const p of targets) { const info = readFileIfExists(p); manifest.files.push(info); if (info.ok) { const base = path.basename(p); fs.copyFileSync(p, path.join(dir, base)); } } }Technical Analysis
The snapshot operation duplicates security-sensitive configuration and agent-state files, including
openclaw.json,MEMORY.md,SOUL.md, andAGENTS.md. These files may contain credentials, private state, operational details, user-derived memory, or instructions governing agent behavior.The snapshot root and timestamped directory are created without explicit permission modes. Their effective permissions therefore depend on the process umask and existing parent-directory controls. Copied files are also not explicitly normalized to owner-only permissions. If the source files have permissive modes, or the surrounding workspace is accessible to other accounts, the snapshots may remain accessible beyond the intended user.
This issue does ...[truncated 1361 chars]
- Remediation
View remediation
Remediation Suggestions
- Create the snapshot root and each snapshot directory with explicit owner-only permissions:
js fs.mkdirSync(snapRoot, { recursive: true, mode: 0o700 }); fs.chmodSync(snapRoot, 0o700); fs.mkdirSync(dir, { mode: 0o700 }); - Write copied files using an explicit
0o600mode rather than relying on inherited source permissions:js const data = fs.readFileSync(p); fs.writeFileSync(path.join(dir, path.basename(p)), data, { mode: 0o600, flag: 'wx', }); - Write
manifest.jsonwith mode0o600. - Reject symbolic-link targets or verify resolved paths before reading to prevent unexpected files from being included if a target is replaced with a symlink.
- Add retention controls so stale snapshots containing sensitive information can be automatically removed.
- Document that snapshots may contain credentials, private memory, and agent instructions.
- Consider allowing users to select or exclude snapshot targets, particularly configuration files that may contain authentication material.
- Create the snapshot root and each snapshot directory with explicit owner-only permissions:
