T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/search-indexer.py:25- Finding
Overbroad indexing of sensitive multi-agent session content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill provides local session-log search, but it indexes and exposes sensitive multi-agent conversation data more broadly than users are likely to expect.
Review before installing. Use this only if you are comfortable creating a local searchable copy of OpenClaw conversation logs across configured agents. Avoid using it on shared machines or with sessions that may contain secrets, credentials, private prompts, or sensitive reasoning unless you first restrict SEARCH_AGENTS, exclude sensitive roles/content, and protect or delete the generated search.db and WAL files.
scripts/search-indexer.py:25Overbroad indexing of sensitive multi-agent session content
scripts/search-indexer.py:23Sensitive conversation index is created without explicit restrictive file permissions
Claiming full-text search while lacking an actual search interface and instead indexing system messages and performing maintenance operations is a significant trust mismatch. Indexing system messages may capture sensitive prompts, policies, or internal context that users did not expect to be stored or queried, which raises confidentiality concerns.
Claiming full-text search while lacking an actual search interface and instead indexing system messages and performing maintenance operations is a significant trust mismatch. Indexing system messages may capture sensitive prompts, policies, or internal context that users did not expect to be stored or queried, which raises confidentiality concerns.
Claiming full-text search while lacking an actual search interface and instead indexing system messages and performing maintenance operations is a significant trust mismatch. Indexing system messages may capture sensitive prompts, policies, or internal context that users did not expect to be stored or queried, which raises confidentiality concerns.
The skill is designed to aggregate session logs from multiple agents into one central search corpus, which broadens the blast radius of any local disclosure or misuse. In the context of an agent platform, cross-agent consolidation is especially sensitive because it can combine unrelated conversations, credentials, prompts, and operational details into a single high-value target.
The indexer explicitly extracts and stores full message text, including 'system' content and internal 'thinking' fields, into a centralized searchable SQLite FTS database. This materially increases exposure of sensitive prompts, secrets, credentials, and reasoning traces by creating a durable, queryable copy beyond the original logs, making compromise or casual local access significantly more damaging.
The skill advertises code-capable behavior but declares no explicit tool scope or permissions boundaries, which creates an authorization and review gap. In an agent environment, undeclared access to files, shell, or environment data can lead to over-privileged execution and make data exposure or unintended modification more likely.
An overly broad trigger phrase increases the chance that the skill is activated in contexts the user did not intend, potentially causing unnecessary access to session logs or indexing operations. In a system handling conversation history, accidental invocation can expose sensitive content or trigger side effects under innocuous prompts.
The module docstring says it merges results from both existing memory files and FTS5 past conversation search, and the function name memory_search_enhanced reinforces that broader scope. In implementation, memory_search_enhanced only calls fts5_search and never invokes any memory-file search logic, so the documented behavior does not match the actual code.
The integration function returns historical conversation content directly from the searchable session database without any access control, consent check, redaction, or even a privacy warning. In a skill specifically designed to search all OpenClaw session logs, this increases the risk of exposing sensitive prompts, secrets, personal data, or prior agent outputs to unauthorized callers or downstream tools.
The CLI prints raw historical message content plus session metadata such as session ID, agent, timestamp, and role directly to stdout. This can leak sensitive archival data into terminals, logs, shell history capture systems, CI output, or other monitoring layers, especially because the skill’s purpose is cross-session search over conversation logs.
This code file performs persistent file writes to search.db and reads session logs from a user directory, effectively copying conversation content into a searchable local database. Although the module docstring describes indexing behavior, there is no explicit safety warning that potentially sensitive session text will be stored and made easily searchable.
cmd_reindex irreversibly deletes the current search index by dropping multiple tables before rebuilding them. While the usage text says 'drop and rebuild entire index from scratch,' there is no confirmation prompt or explicit cautionary warning around this destructive action.
The tool prints full session and search result content directly to stdout with no warning, confirmation, redaction, or access-control checks. Because this skill is explicitly designed to search across all OpenClaw session logs, it can expose sensitive prompts, secrets, personal data, or internal system messages to any caller who can run it, making the privacy risk real in context.
Detected: suspicious.dynamic_code_execution