T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:13- Finding
Unnecessary Filesystem Capability Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 13
Vulnerability Type: Excessive tool permission
Risk Level: MediumVulnerable Code Snippet:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install safe-exit-planner"Technical Analysis
The skill declares access to the
filesystemtool even though its documented behavior is limited to presenting safety-planning instructions, crisis contacts, and external resources. No described workflow requires reading, creating, modifying, or deleting local files.Granting a general filesystem capability violates the principle of least privilege. If untrusted conversation content, prompt injection, or subsequently modified skill instructions influence the agent, the unnecessary capability could be used to request access to files unrelated to the skill's legitimate purpose. This is especially sensitive because users invoking this skill may have safety plans, communications, or evidence of abuse stored on the device.
The declaration alone does not prove that files are currently accessed, but it creates an avoidable privilege boundary that can be exploited in a compromised execution context.
Attack Path
- A user installs or activates the skill.
- The runtime grants the agent the declared filesystem tool.
- Attacker-controlled conversation content, injected instructions, or a compromised future skill revision directs the agent to use that tool.
- The agent reads or modifies files outside any legitimate safety-planning workflow.
- Sensitive local information could be exposed, corrupted, or deleted, subject to the filesystem tool's actual sandbox and operating-system permissions.
Impact Assessment
Exploitation could provide access to files available to the agent process or filesystem sandbox. Potential effects include unauthorized disclosure of local documents, modification of user files, and exposure of h ...[truncated 168 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
filesystemfromopenclaw.requires.toolsbecause the documented skill functionality does not require local file access. - If future functionality legitimately requires storage, replace general filesystem access with a narrowly scoped interface restricted to a dedicated application directory.
- Require explicit user confirmation before reading or writing any file.
- Enforce canonical-path validation and deny path traversal, symbolic-link escapes, and access outside the approved directory.
- Separate read and write permissions and grant only the minimum operation required.
- Avoid persisting safety plans, abuse evidence, conversation transcripts, or other sensitive information unless the user explicitly requests it and secure storage is available.
- Remove
