T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:12- Finding
Unnecessary Filesystem Permission Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-14
Vulnerability Type: Excessive tool permission
Risk Level: MediumComplete Code Snippet:
yaml openclaw: requires: tools: [filesystem]Technical Analysis
The skill declares access to the filesystem even though its documented functionality consists entirely of conversational mental-health guidance. No instruction in the skill requires reading, writing, or modifying local files.
Granting a capability that is unrelated to the declared task violates the principle of least privilege. Although the reviewed file does not contain an instruction that actively abuses this access, exposing the filesystem unnecessarily increases the consequences of a future malicious update, indirect prompt injection, or unintended agent behavior.
Attack Path
- A user installs or activates the skill.
- The hosting agent grants the declared filesystem tool to the skill context.
- A later malicious skill update, injected instruction, or unintended model action directs the agent to access local files.
- The agent may read or modify files allowed by the filesystem tool's effective sandbox and operating-system permissions.
- Retrieved information could subsequently be exposed through agent output or used to influence later actions.
The reviewed version does not implement steps 3-5; the finding concerns the unnecessary capability that makes such a path possible.
Impact Assessment
The maximum scope depends on the host's filesystem sandbox and the privileges of the process running the agent. Potentially exposed assets include files available within that scope, such as project data, configuration files, or user documents. If write access is included, files within the permitted scope could also be altered or deleted. This declaration does not itself grant operating-system privilege escalation beyond the host process.
- Remediation
View remediation
Remediation Suggestions
-
Remove the filesystem requirement because the current skill does not use it:
yaml openclaw: requires: tools: [] -
If the surrounding platform permits omission of the
requiresblock, remove the block entirely. -
If a future feature genuinely requires file access, request it only when needed and restrict it to explicitly approved paths and operations.
-
Prefer read-only access over read-write access where possible.
-
Enforce host-level sandboxing so skill permissions cannot exceed the minimum directories required for operation.
-
Add a review check that rejects tool declarations unsupported by documented skill behavior.
-
