T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/compress.py:127- Finding
Document Scope Restrictions Are Not Enforced by the Compression Workflow
- Content
View full analysis
[--dry-run]", file=sys.stderr) sys.exit(1) filepath = sys.argv[1] dry_run = "--dry-run" in sys.argv # Check feature flags if "AGENTS.md" in filepath and not os.environ.get("CAVEMAN_COMPRESS_AGENTS"): print("⚠️ AGENTS.md compression disabled (set CAVEMAN_COMPRESS_AGENTS=1)") sys.exit(0) if "HEARTBEAT.md" in filepath and not os.environ.get("CAVEMAN_COMPRESS_HEARTBEAT"): print("⚠️ HEARTBEAT.md compression disabled (set CAVEMAN_COMPRESS_HEARTBEAT=1)") sys.exit(0) if "MEMORY.md" in filepath and not os.environ.get("CAVEMAN_COMPRESS_MEMORY"): print("⚠️ MEMORY.md compression disabled (set CAVEMAN_COMPRESS_MEMORY=1)") sys.exit(0) try: content = read_file(filepath) compressed = compress(content, dry_run=dry_run) if not dry_run: if not is_technically_intact(content, compressed): print("[ERROR] Validation failed — compression may have lost content") return write_backup(filepath, content) Path(filepath).write_text(compressed, encoding="utf-8") print(f"✓ Compressed: {filepath}") except Exception as e: print(f"✗ Error: {e}", file=sys.stderr) sys.exit(1) ``` ### Technical Analysis The executable workflow accepts an arbitrary path from `sys.argv[1]` and immediately passes it to `read_file()`. Although `scripts/detect.py` defines `is_safe_to_compress()`, the compression workflow never calls it. The feature checks are substring comparisons for only three filenames. They do not enforce: - Containment under `~/.openclaw/workspace` - A Markdown extension - The documented ...[truncated 1205 chars]- Remediation
View remediation
