Back to skill

Security audit

Session Cleanup Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says: scan and help clean OpenClaw session files with user confirmation, though deletion commands need careful review.

Before installing or using it, review the scan report and confirm only exact files you intend to remove. Prefer archive or move behavior when possible, and avoid blindly pasting the rm template for filenames that are not clearly normal session .jsonl files under the OpenClaw sessions directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code reads OpenClaw session metadata and directory contents, classifies protected vs stale sessions using a 72-hour threshold, finds orphan .jsonl files, and prints a JSON report. This aligns partially with the analysis aspect of session cleanup, but not with the declared main capability of actually cleaning/deleting files or stale sessions. There is also no user confirmation mechanism at all. Because the description promises destructive cleanup behavior with safety confirmation, while the implementation is only a scanner/report generator, this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The skill includes a raw rm ~/.openclaw/agents/main/sessions/<orphan>.jsonl deletion pattern without showing any robust validation, quoting, canonicalization, or constrained execution wrapper. If an agent or user substitutes an attacker-influenced filename or misparses scan output, this can lead to unintended file deletion, especially because destructive shell commands in skill instructions are often copied or automated with minimal safeguards.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

在用户确认后删除孤儿文件:

bash
rm ~/.openclaw/agents/main/sessions/<orphan>.jsonl

B. 再处理过期会话(谨慎)

Static analysis

No suspicious patterns detected.