T09 · Insecure Skill Coding Practices
- Location
scripts/archive_sessions.py:53- Finding
Non-Atomic and Unlocked Modification of the Live Session Store
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent cleanup purpose, but it schedules automatic changes to live session data using a script that can rewrite or delete records without enough safety controls.
Install only if you are comfortable letting a scheduled job modify your OpenClaw session store. Before enabling the cron, run with --dry-run, make a backup of sessions.json and sessions-archive, set an explicit --sessions-path, and review or fix the script's atomic-write, locking, and retention handling.
scripts/archive_sessions.py:53Non-Atomic and Unlocked Modification of the Live Session Store
scripts/archive_sessions.py:70Archive Retention Bypass for Sessions Without Valid Timestamps
The skill claims it 'sets up a cron,' but the content only tells the user to manually create a cron entry and run a script. This mismatch can mislead operators about what automation is actually being installed, reducing review quality and increasing the risk that a destructive maintenance action is scheduled without proper understanding.
The skill clearly instructs users to run a maintenance script that will modify session storage and create/delete archive files, yet the skill metadata declares no explicit tool scope or permissions boundary. That omission increases the chance of unintended file modification or overbroad execution in environments that rely on metadata to constrain skill behavior.
Because this is a markdown file, vague trigger guidance applies. The phrase covers very broad conditions and does not clearly distinguish when the skill should or should not be invoked, increasing the chance of unintended use outside truly necessary maintenance scenarios.
The instructions encourage automated archival and retention-based deletion of session data without a prominent warning that sessions.json will be rewritten and archive files will later be deleted. In operational environments, hidden data-destruction semantics can lead to accidental loss of forensic or audit history and make rollback harder after a mistake.
No suspicious patterns detected.