Back to skill

Security audit

Session Hygiene

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent cleanup purpose, but it schedules automatic changes to live session data using a script that can rewrite or delete records without enough safety controls.

Install only if you are comfortable letting a scheduled job modify your OpenClaw session store. Before enabling the cron, run with --dry-run, make a backup of sessions.json and sessions-archive, set an explicit --sessions-path, and review or fix the script's atomic-write, locking, and retention handling.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/archive_sessions.py:53
Finding

Non-Atomic and Unlocked Modification of the Live Session Store

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/archive_sessions.py:70
Finding

Archive Retention Bypass for Sessions Without Valid Timestamps

Content
View full analysis
0: date_str = datetime.fromtimestamp(updated / 1000).strftime("%Y-%m-%d") else: date_str = "unknown" archive.setdefault(date_str, []).append((key, sess)) else: keep[key] = sess ``` ```python # Rotate old archives retention_cutoff = datetime.now() - timedelta(days=args.archive_retention_days) rotated = 0 if archive_dir.exists(): for archive_file in archive_dir.glob("*.jsonl"): try: file_date = datetime.strptime(archive_file.stem, "%Y-%m-%d") if file_date < retention_cutoff: archive_file.unlink() rotated += 1 except ValueError: continue ``` ### Technical Analysis A session with an absent, zero, or negative `updatedAt` value is considered stale and assigned the archive group `"unknown"`. These records are appended to `sessions-archive/unknown.jsonl`. Archive rotation only handles filenames whose stems parse as `%Y-%m-%d`. Parsing `unknown` raises `ValueError`, and the exception handler unconditionally skips the file. As a result, `unknown.jsonl` is never deleted by the configured retention mechanism. This behavior conflicts with the documented archive-retention guarantee. It can retain potentially sensitive session data indefinitely and allows the unrotated archive to grow continuously if malformed or legacy entries recur. ### Attack Path 1. A session record exists with no `updatedAt` field or with a value less than or equal to zero. 2. The cleanup script treats that record as stale because its effective timestamp is older than the cutoff. 3. The record is appended to `sessions-arc ...[truncated 1125 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill claims it 'sets up a cron,' but the content only tells the user to manually create a cron entry and run a script. This mismatch can mislead operators about what automation is actually being installed, reducing review quality and increasing the risk that a destructive maintenance action is scheduled without proper understanding.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill clearly instructs users to run a maintenance script that will modify session storage and create/delete archive files, yet the skill metadata declares no explicit tool scope or permissions boundary. That omission increases the chance of unintended file modification or overbroad execution in environments that rely on metadata to constrain skill behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Because this is a markdown file, vague trigger guidance applies. The phrase covers very broad conditions and does not clearly distinguish when the skill should or should not be invoked, increasing the chance of unintended use outside truly necessary maintenance scenarios.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions encourage automated archival and retention-based deletion of session data without a prominent warning that sessions.json will be rewritten and archive files will later be deleted. In operational environments, hidden data-destruction semantics can lead to accidental loss of forensic or audit history and make rollback harder after a mistake.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.