T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:11- Finding
Unnecessary Filesystem Capability Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 11-15
Vulnerability Type: Excessive tool permission
Risk Level: MediumVulnerable Code:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install water-safety-swimming"Technical Analysis
The skill declares the
filesystemtool as a required capability, but its documented water-safety workflow does not require reading, creating, modifying, or deleting local files. The remainder of the audited file consists of informational guidance, state definitions, and reminder conditions.Granting a filesystem capability without a demonstrated operational requirement violates the principle of least privilege. The precise exposure depends on the host platform's filesystem sandbox and tool policy. If the capability is broadly scoped, malicious instructions introduced through prompt injection or a compromised skill update could attempt to access files unrelated to water-safety guidance.
Attack Path
- A user installs and activates the skill.
- The host grants the declared
filesystemcapability. - Attacker-controlled content reaches the Agent through a later prompt, compromised update, or another untrusted context.
- The malicious instructions direct the Agent to invoke the filesystem tool.
- If host-level access controls permit the request, the Agent reads or modifies files within the capability's accessible scope.
This file does not itself contain instructions that perform such access; exploitation requires attacker-controlled instructions and a permissive host policy.
Impact Assessment
The capability could expose the confidentiality and integrity of files available through the host's filesystem tool. Potential impact includes reading local configuration or user data and modifying accessible files. It does not inherently provide operating-system administrator privileges, and the actual scope is bounde ...[truncated 57 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
filesystemfromopenclaw.requires.toolsbecause the documented workflow does not use it. - If future functionality genuinely requires file access, grant access only to a dedicated skill-owned directory.
- Enforce read-only access unless writes are explicitly necessary.
- Require user confirmation for sensitive file operations.
- Add runtime allowlists that prevent access to credentials, home-directory secrets, system configuration, and unrelated project files.
- Document each required tool and the exact operations for which it is needed.
- Remove
