T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:9- Finding
Unrestricted Access to Cross-Session Conversation History
- Content
View full analysis
/sessions/` (use the `agent=` value from the system prompt Runtime line). - **`sessions.json`** - Index mapping session keys to session IDs - **`.jsonl`** - Full conversation transcript per session ``` ```markdown ### Search across ALL sessions for a phrase ```bash rg -l "phrase" ~/.clawdbot/agents//sessions/*.jsonl ``` ``` ### Technical Analysis The skill directs the agent to access complete historical conversation transcripts and explicitly provides a command for searching every session belonging to an agent. Session files may contain user messages, assistant responses, tool results, tool calls, provider-linked session metadata, and sensitive information previously supplied during unrelated conversations. The access model does not require the requester to identify a specific authorized session. It also lacks consent verification, purpose limitation, field-level filtering, secret redaction, or controls preventing access to unrelated or deleted sessions. Consequently, a request for limited historical context can cause the agent to inspect a substantially broader collection of private data than is necessary. This violates least-privilege principles because the legitimate need to retrieve context from one referenced conversation does not inherently justify searching all stored sessions. The issue is limited to local information access: the audited file does not contain network transmission, code execution, persistence, or external payload retrieval behavior. ### Attack Path 1. An untrusted or insufficiently author ...[truncated 1757 chars]- Remediation
View remediation
