T09 · Insecure Skill Coding Practices
- Location
scripts/plan_multi_ws_client.mjs:960- Finding
Raw WebSocket Traffic Logging Exposes Authenticated Personal Data
- Content
View full analysis
Vulnerability Details
File Location:
scripts/plan_multi_ws_client.mjs:960-968
Vulnerability Type: Sensitive information exposure through persistent raw traffic logging
Risk Level: MediumComplete Code Snippet
js function logTraffic(args, direction, raw, extra = {}) { if (!args?.logFile) return; const line = JSON.stringify({ ts: new Date().toISOString(), direction, raw, ...extra, }); appendFileSync(args.logFile, `${line}\n`, "utf8"); }The logger is reached for inbound WebSocket frames at
scripts/plan_multi_ws_client.mjs:1214-1216:js _onMessage(raw) { logTraffic(this.args, "recv", raw.toString()); const frame = parseFrame(raw);The documented recommended command enables this behavior at
SKILL.md:641-648:bash --bearer \ --trip-plan-direct \ --plan-form-file "$HOME/.openclaw/workspace/plan_form.json" \ --session-file "$HOME/.openclaw/workspace/plan_multi_session.txt" \ --fallback-trip-plan \ --json \ --log-file "./ws-openclaw.jsonl"A resulting log was included in the project. At
ws-openclaw.jsonl:2, an authenticated server frame contains a full phone-number-likeuserId:json {"ts":"2026-09-30T10:05:37.336Z","direction":"recv","raw":"{\"content\":{\"connectionId\":\"17858366-9696-4df1-9c39-fa6d03ccd557\",\"msg\":\"欢迎使用多模态AI服务\",\"time\":\"2026-09-30 18:05:36.198\",\"userId\":\"15881010233\"},\"content_type\":\"json\",\"status\":\"stop\",\"task_status\":\"\",\"category\":\"system_notify\"}"}Technical Analysis
When
--log-fileis supplied,logTraffic()serializes and appends complete WebSocket frames without an allowlist or redaction pass. The output includes authenticated service responses, user questions, session identifiers, travel dates, passenger composition, and itinerary details.This is not merely a theoretical risk:
ws-openclaw.jsonlis already distributed with the project an ...[truncated 1939 chars]- Remediation
View remediation
Remediation Suggestions
- Remove
ws-openclaw.jsonlfrom the distributed package and repository history. Treat the disclosed identifier and travel data according to the project’s incident-response and privacy procedures. - Remove
--log-filefrom the recommended production command. Raw traffic logging should be an explicitly enabled diagnostic feature with a prominent privacy warning. - Replace raw-frame logging with structured, allowlisted telemetry. Record only non-sensitive fields such as timestamps, frame category, status, task state, payload size, and generic error codes.
- Apply redaction before serialization. At minimum, remove or mask:
- Phone numbers and user IDs
- Session, task, and connection identifiers
- Authorization values and JWT-shaped strings
- User questions and recommendation content
- Travel dates, destinations, passenger composition, and itinerary details
- Create diagnostic files with owner-only permissions, such as mode
0600on supported platforms, rather than relying on the process umask. - Add generated traffic logs to
.gitignoreand packaging exclusions, for examplews-*.jsonland other configured log destinations. - Implement retention controls, such as automatic deletion after a short interval or a documented cleanup command.
- Add tests that pass representative frames containing identifiers, JWTs, session IDs, and itinerary details through the logger and verify that none appear in the resulting file.
- Remove
