T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:58- Finding
Overbroad Access to Shared Persistent Agent Memory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58–60
Vulnerability Type: Excessive access to shared agent memory
Risk Level: Mediummarkdown - 使用 OpenClaw 原生能力(无需第三方 API) - 读取 memory/ 目录中用户偏好设置 - 记录生成历史到 memory/cross-border-history.mdThe cited instructions state that the Skill uses native OpenClaw capabilities without third-party APIs, reads user preferences from the
memory/directory, and records generation history inmemory/cross-border-history.md.Technical Analysis
The Skill requests directory-wide access to
memory/rather than identifying a dedicated preference file owned by the Skill. A shared memory directory may contain unrelated user information or state created by other Skills. Reading it broadly violates the principle of least privilege because product-title generation only requires narrowly scoped preferences.The Skill also persists generation history without defining user consent, permitted fields, retention limits, deletion behavior, or isolation from other Skills. The destination file is specified, so the write scope is narrower than the read scope; however, requests and generated titles may still contain product, business, or user information that persists across sessions.
No evidence indicates external transmission, executable payloads, shell execution, credential theft, or malicious rules being written into memory. The issue is therefore excessive local memory access and insufficiently controlled persistence, not confirmed exfiltration or memory poisoning.
Attack Path
- A user invokes the title-generation Skill.
- The agent follows the instruction to inspect the shared
memory/directory for user preferences. - Unrelated memory files may be read into the agent context because no file allowlist or ownership boundary is defined.
- Information from those files may inadvertently influence or appear in generated output.
- The Skill writes the user's req ...[truncated 837 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace directory-wide reads with an explicit Skill-owned file, such as
memory/cross-border-title-generator/preferences.json. - Enforce an allowlist that prevents access to unrelated files under
memory/. - Ask for explicit user consent before saving generation history, with persistence disabled by default.
- Store only fields required for title generation and exclude credentials, personal information, raw conversations, and unrelated memory content.
- Define retention limits and provide commands to inspect, clear, or disable stored history.
- Apply restrictive file permissions and prevent other Skills from reading the Skill-owned storage unless the user explicitly authorizes it.
- Document precisely which preference fields are read and which history fields are written.
- If history is unnecessary, keep it in ephemeral session state rather than persistent shared memory.
- Replace directory-wide reads with an explicit Skill-owned file, such as
