Back to skill

Security audit

Openclaw History Viewer

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches a chat-history viewer, but it exposes sensitive local chat history and deletion actions through an unauthenticated web server that listens more broadly than documented.

Review before installing. Run it only on trusted machines and networks, avoid background mode unless needed, do not expose or forward the port, and treat all viewed or exported history as sensitive. The deletion feature can permanently remove chat history and backups, and the current server should be considered unsafe for shared hosts or reachable network environments without hardening.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/history_server.py:2321
Finding

Unauthenticated Network Exposure and Destructive Access to Sensitive Chat History

Content
View full analysis
Remediation
View remediation
MAX_BODY_SIZE: self.send_error(413, "Request body too large") return ``` 7. **Harden HTTP responses** - Return accurate sta ...[truncated 607 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch is more severe because the analysis indicates undeclared deletion and modification capabilities, including rewriting session indexes and removing history files. Users invoking a 'viewer' would not reasonably expect destructive operations, so this creates risk of silent data loss or tampering of sensitive audit/history data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch is more severe because the analysis indicates undeclared deletion and modification capabilities, including rewriting session indexes and removing history files. Users invoking a 'viewer' would not reasonably expect destructive operations, so this creates risk of silent data loss or tampering of sensitive audit/history data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is described as a history viewer/exporter, but it also exposes deletion of session and backup files through a POST API. This is a dangerous capability mismatch: users may invoke or trust the skill for read-only browsing, while the server can permanently destroy local conversation data if accessed by the UI or any local process able to reach the endpoint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code implements irreversible file deletion for active sessions, reset backups, and manual backups, which is not justified by the stated purpose of a history viewer. Even though deletion is keyed by session ID rather than arbitrary path input, exposing destructive actions over HTTP increases the chance of accidental data loss or abuse by other local software/users on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly documents API endpoints and curl commands to export complete session histories, but provides no warning that chat logs may contain secrets, personal data, tokens, or other sensitive content. In the context of a local history viewer that aggregates active sessions and backup/reset files, this omission increases the chance users will expose or mishandle highly sensitive conversation data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises capabilities that read local chat history, write backups, and launch a local web service, but it does not declare any explicit tool scope such as file or network permissions. That weakens user and platform visibility into what the skill can access and increases the chance of unintended exposure of sensitive conversation data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad trigger phrases like '查看历史' or '打开聊天记录' can cause accidental activation during ordinary conversation. Because this skill exposes sensitive chat history and may start a local service, unintended invocation increases privacy and data-exposure risk even without overtly malicious intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation does not warn users that browsing or exporting chat history may reveal sensitive prompts, secrets, tool outputs, or personal information. For a history viewer, omission of this warning materially increases the chance that users expose private data through the UI or API without realizing the risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description and invocation guidance are presented in Chinese, effectively imposing a specific language on users without stating that the skill is region-specific or offering an alternative language. Under the stated policy, forcing a language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language startup examples encourage ambiguous activation without making the privacy implications clear. In context, this is more dangerous because the skill targets historical conversations, which commonly contain credentials, personal data, and internal reasoning traces.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The documented use of nohup/background execution creates persistent local service behavior that may continue exposing chat history after the user forgets it is running. In a history-viewer context, persistence expands the window for unauthorized local access, stale data exposure, and unnoticed retention in log files such as /tmp/history.log.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

🔙 后台启动

bash
nohup python3 ~/.openclaw/skills/openclaw-history-viewer/scripts/history_server.py > /tmp/history.log 2>&1 &

功能特性

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and CLI usage text are written in Chinese, and later user-facing status/error messages are also emitted in Chinese only. This imposes a specific language on users without opt-in or justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This server exposes full chat history over HTTP from localhost bindings without any authentication, warning banner, or disclosure about the sensitivity of the data being served. In the context of chat/session archives, this can leak highly sensitive prompts, responses, tool outputs, or secrets to any local user/process, and potentially to a wider network if the service is reachable through host/network configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The deletion API relies mainly on browser-side confirmation and prints minimal console messages, but provides no robust server-side consent recording, authentication, or durable audit trail for destructive actions. That makes accidental or unauthorized local deletions harder to detect, investigate, or attribute after the fact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README presents all user-facing instructions in Chinese and does not offer an alternative language, opt-in, or justification for a locale-specific audience. This can be a natural-language policy issue when a skill effectively forces a specific language without documented user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest file contains a natural-language field that is only in Chinese, which can impose a specific language on users or maintainers without opt-in. The policy calls for flagging language or locale constraints when they are forced and not explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains extensive natural-language UI strings and comments in Chinese, and the generated HTML declares zh-CN as the page language. Because the skill does not offer any language selection or explain that it is intentionally region-specific, it violates the language/locale choice policy described for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's user-facing strings are written in Chinese, including startup and usage messages. This imposes a specific language on users without offering a language choice or documenting a locale-specific scope, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.