Back to skill

Security audit

Session-logs

Security checks for vulnerabilities and agentic risk

Overview

This skill openly helps search local conversation history, but it is broad enough to expose unrelated private session logs without clear consent or minimization guidance.

Install only if you want agents to inspect local saved conversation logs. Before using it, specify the exact session, date, or phrase you authorize, and avoid broad all-session searches when logs may contain secrets, private messages, tool outputs, or content from other contexts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:9
Finding

Unrestricted Access to Cross-Session Conversation History

Content
View full analysis
/sessions/` (use the `agent=` value from the system prompt Runtime line). - **`sessions.json`** - Index mapping session keys to session IDs - **`.jsonl`** - Full conversation transcript per session ``` ```markdown ### Search across ALL sessions for a phrase ```bash rg -l "phrase" ~/.clawdbot/agents//sessions/*.jsonl ``` ``` ### Technical Analysis The skill directs the agent to access complete historical conversation transcripts and explicitly provides a command for searching every session belonging to an agent. Session files may contain user messages, assistant responses, tool results, tool calls, provider-linked session metadata, and sensitive information previously supplied during unrelated conversations. The access model does not require the requester to identify a specific authorized session. It also lacks consent verification, purpose limitation, field-level filtering, secret redaction, or controls preventing access to unrelated or deleted sessions. Consequently, a request for limited historical context can cause the agent to inspect a substantially broader collection of private data than is necessary. This violates least-privilege principles because the legitimate need to retrieve context from one referenced conversation does not inherently justify searching all stored sessions. The issue is limited to local information access: the audited file does not contain network transmission, code execution, persistence, or external payload retrieval behavior. ### Attack Path 1. An untrusted or insufficiently author ...[truncated 1757 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly directs the agent to access complete session logs containing historical conversation data, but it provides no warning, consent check, or limitation guidance before searching prior conversations. Because session logs may contain sensitive user content, secrets, or data from other contexts, this increases the risk of unintended privacy violations and overbroad data access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.