T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:13- Finding
Unnecessary Filesystem Permission Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13-15
Vulnerability Type: Excessive tool permission
Risk Level: HighVulnerable Code:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install textile-clothing-repair"Technical Analysis
The skill explicitly requests access to the filesystem, but its documented functionality consists of providing textile-repair instructions and maintaining simple repair-related state. No operation described in the skill requires reading, creating, modifying, or deleting local files.
Granting an agent a filesystem capability that is not necessary for its stated purpose violates the principle of least privilege. If the skill's instructions, runtime state, or execution context were subsequently manipulated, the unnecessary capability could provide a path to access files outside the legitimate clothing-repair workflow.
Attack Path
- A user installs or activates the skill.
- The agent runtime processes the
requires.toolsdeclaration. - The runtime grants the skill filesystem access.
- A maliciously modified skill version, injected instruction, or compromised execution context directs the agent to invoke the filesystem tool.
- The agent reads or modifies files unrelated to clothing repair, subject to the filesystem tool's sandbox and operating-system permissions.
Impact Assessment
The accessible scope depends on restrictions enforced by the host runtime. In an insufficiently sandboxed environment, the capability could expose user documents, application configuration, source code, cached data, or other files available to the agent process. If write operations are permitted, it could also enable unauthorized file modification or deletion.
The reviewed skill does not itself contain instructions to access such files; the risk arises from granting an unnecessary high-impact capability that could be abused ...[truncated 30 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
filesystemfrom the skill's required tools because the documented workflow does not need file access. - If a future feature legitimately requires file operations, request access only when that feature is invoked and after explicit user approval.
- Restrict any necessary access to a dedicated application directory rather than the user's general filesystem.
- Enforce read-only access unless writes are essential.
- Add runtime policy checks that reject undeclared paths, traversal sequences, symbolic-link escapes, and access to credentials or configuration directories.
- Document each requested capability and its concrete functional justification.
- Remove
