T05 · Unauthorized Access and Privilege Escalation
- Location
package.json:12- Finding
Overly Broad Home-Directory Access Creates Sensitive-File Indexing Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This local memory skill is purpose-aligned, but it asks to index the user's home directory and persist agent-operating instructions with limited scoping and rollback controls.
Install only if you intend this skill to build a persistent local memory index over broad parts of your home environment. Before approving setup, narrow the filesystem scope to specific project folders, review exclusions for secrets and private data, avoid symlink-based indexing unless deliberate, and treat the dependency install, gateway restart, config changes, and HEARTBEAT.md append as persistent changes you may need to undo manually.
package.json:12Overly Broad Home-Directory Access Creates Sensitive-File Indexing Risk
SKILL.md:50Unpinned Native Dependency Installation Executes Mutable Supply-Chain Code
SKILL.md:71Skill Appends Persistent Operational Directives to Shared Agent Heartbeat
Referenced artifact was not completely inspected
* **`SKILL.md`**: (Above) Includes the documentation and the master install script.
These instructions describe system-level and runtime-modifying actions such as installing packages, changing provider configuration, appending monitoring components, restarting services, and triggering indexing. Such actions can affect system integrity, availability, and trust settings, especially when initiated from a skill install path without a narrowly scoped, transparent permission model.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"**/.ssh/**",
"**/.aws/**",
"**/.gnupg/**",
"**/.env",
"**/config/google-chrome/**",
"**/.mozilla/**"
],
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"**/.ssh/**",
"**/.aws/**",
"**/.gnupg/**",
"**/.env",
"**/config/google-chrome/**",
"**/.mozilla/**"
],
The skill presents itself as operating without external dependencies and as 'sovereign local memory', yet its install/config flow fetches a model from Hugging Face and uses an hf: remote model reference. This is a misleading security/privacy claim that can cause users to underestimate network access, supply-chain exposure, and data governance implications during installation or model resolution.
The skill promotes indexing ~/ and other broad filesystem paths while only lightly mentioning customization, without a strong warning that personal documents, tokens, private project data, and unrelated files may be embedded and searchable. In the context of a memory/indexing skill, broad home-directory coverage substantially increases accidental data collection and later retrieval risk, even if some secret paths are excluded.
The script appends skill-controlled content into ~/.openclaw/workspace/HEARTBEAT.md, which extends beyond memory engine setup into persistent modification of workspace behavior/content. Because the injected file contents are not shown here and the action is only loosely justified as a 'heartbeat monitor', this creates an unnecessary trust boundary crossing and a potential persistence or prompt-injection surface.
The document claims that no context or embeddings are ever sent to external APIs, but later describes contacting a registry and downloading models or packages. That contradiction is dangerous because it can cause users to make trust decisions based on false assumptions about network isolation and data exposure.
Automatically following symlinks into external directories creates persistent cross-boundary memory ingestion beyond the normal workspace, which can retain sensitive information in logs, embeddings, or indexes long after initial access. In the context of a memory skill, this is particularly risky because persistence is the product's core behavior, so accidental over-collection is more dangerous than in a transient tool.
| **Skills Directory** | `/home/$USER/.openclaw/skills` |
| **Main Config** | `/home/$USER/.openclaw/openclaw.json` |
> **💡 NOTE ON EXTERNAL DIRECTORIES:** > If you have infrastructure or data outside of the standard workspace that you want the AI to "remember," create a manual symbolic link inside `~/.openclaw/workspace/` pointing to that directory. The memory engine will automatically follow the link and index the external data.
> **Example:** `ln -s /path/to/my-external-data ~/.openclaw/workspace/external-data`
---
The template encourages users to symlink arbitrary external directories into the indexed workspace so the memory engine will automatically follow and ingest them, but it does not warn about indexing sensitive files, personal data, secrets, or regulated information. This can unintentionally broaden the skill's data collection scope and cause sensitive local content to become persistently searchable by the agent.
The template is presented as a memory manifest, but it also instructs users that installation will trigger broad system and application changes including package deployment, provider reconfiguration, loop-protection changes, heartbeat injection, gateway restart, and initial indexing. That scope expansion is dangerous because users may consent to a seemingly documentation-only skill without understanding it can alter runtime behavior and system state well beyond local memory configuration.
The file describes reaching out to a registry and downloading a bundle as part of using a skill whose stated value proposition is sovereign local memory with no external dependency. Even if this is normal package retrieval, the mismatch between claimed isolation and actual network activity can mislead users and creates supply-chain and trust-boundary risk.
The installation/update guidance tells users to approve an install script that performs multiple system and application modifications, but it does not provide a concise warning summary of side effects, persistence, network use, or rollback implications. This undermines informed consent and increases the likelihood of users authorizing changes they do not fully understand.
No suspicious patterns detected.