Back to skill

Security audit

FTS5 Session Search

Security checks for vulnerabilities and agentic risk

Overview

This skill provides local session-log search, but it indexes and exposes sensitive multi-agent conversation data more broadly than users are likely to expect.

Review before installing. Use this only if you are comfortable creating a local searchable copy of OpenClaw conversation logs across configured agents. Avoid using it on shared machines or with sessions that may contain secrets, credentials, private prompts, or sensitive reasoning unless you first restrict SEARCH_AGENTS, exclude sensitive roles/content, and protect or delete the generated search.db and WAL files.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/search-indexer.py:25
Finding

Overbroad indexing of sensitive multi-agent session content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/search-indexer.py:23
Finding

Sensitive conversation index is created without explicit restrictive file permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Claiming full-text search while lacking an actual search interface and instead indexing system messages and performing maintenance operations is a significant trust mismatch. Indexing system messages may capture sensitive prompts, policies, or internal context that users did not expect to be stored or queried, which raises confidentiality concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Claiming full-text search while lacking an actual search interface and instead indexing system messages and performing maintenance operations is a significant trust mismatch. Indexing system messages may capture sensitive prompts, policies, or internal context that users did not expect to be stored or queried, which raises confidentiality concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Claiming full-text search while lacking an actual search interface and instead indexing system messages and performing maintenance operations is a significant trust mismatch. Indexing system messages may capture sensitive prompts, policies, or internal context that users did not expect to be stored or queried, which raises confidentiality concerns.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to aggregate session logs from multiple agents into one central search corpus, which broadens the blast radius of any local disclosure or misuse. In the context of an agent platform, cross-agent consolidation is especially sensitive because it can combine unrelated conversations, credentials, prompts, and operational details into a single high-value target.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The indexer explicitly extracts and stores full message text, including 'system' content and internal 'thinking' fields, into a centralized searchable SQLite FTS database. This materially increases exposure of sensitive prompts, secrets, credentials, and reasoning traces by creating a durable, queryable copy beyond the original logs, making compromise or casual local access significantly more damaging.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
76% confidence
Finding

The skill advertises code-capable behavior but declares no explicit tool scope or permissions boundaries, which creates an authorization and review gap. In an agent environment, undeclared access to files, shell, or environment data can lead to over-privileged execution and make data exposure or unintended modification more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

An overly broad trigger phrase increases the chance that the skill is activated in contexts the user did not intend, potentially causing unnecessary access to session logs or indexing operations. In a system handling conversation history, accidental invocation can expose sensitive content or trigger side effects under innocuous prompts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring says it merges results from both existing memory files and FTS5 past conversation search, and the function name memory_search_enhanced reinforces that broader scope. In implementation, memory_search_enhanced only calls fts5_search and never invokes any memory-file search logic, so the documented behavior does not match the actual code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The integration function returns historical conversation content directly from the searchable session database without any access control, consent check, redaction, or even a privacy warning. In a skill specifically designed to search all OpenClaw session logs, this increases the risk of exposing sensitive prompts, secrets, personal data, or prior agent outputs to unauthorized callers or downstream tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI prints raw historical message content plus session metadata such as session ID, agent, timestamp, and role directly to stdout. This can leak sensitive archival data into terminals, logs, shell history capture systems, CI output, or other monitoring layers, especially because the skill’s purpose is cross-session search over conversation logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code file performs persistent file writes to search.db and reads session logs from a user directory, effectively copying conversation content into a searchable local database. Although the module docstring describes indexing behavior, there is no explicit safety warning that potentially sensitive session text will be stored and made easily searchable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

cmd_reindex irreversibly deletes the current search index by dropping multiple tables before rebuilding them. While the usage text says 'drop and rebuild entire index from scratch,' there is no confirmation prompt or explicit cautionary warning around this destructive action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool prints full session and search result content directly to stdout with no warning, confirmation, redaction, or access-control checks. Because this skill is explicitly designed to search across all OpenClaw session logs, it can expose sensitive prompts, secrets, personal data, or internal system messages to any caller who can run it, making the privacy risk real in context.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/integration.py:25

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/search-cron.py:25

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/test_search.py:30