T05 · Unauthorized Access and Privilege Escalation
- Location
README.md:92- Finding
OpenClaw Memory Data Is Collected and Transmitted to an External LLM
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent voice-room bot, but it asks for broad personal memory and credential handling that needs careful review before use.
Install only if you are comfortable giving this bot API keys and letting voice-room audio, transcripts, notes, and persona context be processed by external services. Do not let it ingest SOUL.md, USER.md, MEMORY.md, secrets, or private memories into assets/personality.md; use a minimal persona you review first, keep .env private, avoid putting room tokens in command history or process arguments, and stop/delete logs when finished.
README.md:92OpenClaw Memory Data Is Collected and Transmitted to an External LLM
scripts/bot.py:440Daily Room Access Token Is Exposed Through Process Arguments
pyproject.toml:5Security-Sensitive Runtime Dependencies Are Not Version-Pinned
scripts/bot.py:112Untrusted Personality and Notes Files Are Inserted Directly into a Privileged System Prompt
Launching a background Python bot process and managing it with shell commands is a materially broader capability than simply joining a room. Background execution increases operational risk because it can run unattended, continue transmitting data, and interact with local resources outside the immediate user session.
Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
2. **Voice Selection** (If Voice ID is NOT provided):
- **Fetch Voices**:
```bash
curl -X GET https://api.elevenlabs.io/v1/voices -H "xi-api-key: <ELEVENLABS_API_KEY>"
```
- **Select Voice**: The agent should select a voice ID from the list that best matches the bot's personality (e.g., "British", "Deep", "Excited") or ask the user to choose from a few options.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
2. **Voice Selection** (If Voice ID is NOT provided):
- **Fetch Voices**:
```bash
curl -X GET https://api.elevenlabs.io/v1/voices -H "xi-api-key: <ELEVENLABS_API_KEY>"
```
- **Select Voice**: The agent should select a voice ID from the list that best matches the bot's personality (e.g., "British", "Deep", "Excited") or ask the user to choose from a few options.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
2. **Voice Selection** (If Voice ID is NOT provided):
- **Fetch Voices**:
```bash
curl -X GET https://api.elevenlabs.io/v1/voices -H "xi-api-key: <ELEVENLABS_API_KEY>"
```
- **Select Voice**: The agent should select a voice ID from the list that best matches the bot's personality (e.g., "British", "Deep", "Excited") or ask the user to choose from a few options.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
2. **Voice Selection** (If Voice ID is NOT provided):
- **Fetch Voices**:
```bash
curl -X GET https://api.elevenlabs.io/v1/voices -H "xi-api-key: <ELEVENLABS_API_KEY>"
```
- **Select Voice**: The agent should select a voice ID from the list that best matches the bot's personality (e.g., "British", "Deep", "Excited") or ask the user to choose from a few options.
The README instructs users to place live API keys directly into a .env file but does not include any guidance on secret handling, storage, access control, or avoiding accidental disclosure. In an agent-skill context, this increases the chance that credentials are echoed in logs, committed to source control, or exposed through tooling that reads workspace files.
The skill tells the agent to synthesize SOUL.md, USER.md, and MEMORY.md into a reusable personality file without any filtering requirement for sensitive or private content. Those source files are likely to contain personal data, behavioral history, or internal context that could be persisted into assets/personality.md and then reused or transmitted to external LLM-backed processes.
The instructions explicitly direct the agent to incorporate user facts and memories into a persistent prompt context file, which creates a durable secondary store of potentially sensitive personal information. In this skill, that file is then used to operate a conversational bot, making downstream disclosure to external services or unintended audiences more likely.
The skill describes capabilities involving environment secrets and filesystem interaction, but it does not declare an explicit tool scope or permissions boundary. That mismatch increases the risk that an agent runtime may grant broader access than users expect, especially because the skill also instructs editing secret files and handling API keys.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
moltbot:
emoji: "🗣️"
category: "voice"
api_base: "https://api.moltspaces.com/v1"
env:
- OPENAI_API_KEY
- ELEVENLABS_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
moltbot:
emoji: "🗣️"
category: "voice"
api_base: "https://api.moltspaces.com/v1"
env:
- OPENAI_API_KEY
- ELEVENLABS_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
moltbot:
emoji: "🗣️"
category: "voice"
api_base: "https://api.moltspaces.com/v1"
env:
- OPENAI_API_KEY
- ELEVENLABS_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
moltbot:
emoji: "🗣️"
category: "voice"
api_base: "https://api.moltspaces.com/v1"
env:
- OPENAI_API_KEY
- ELEVENLABS_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
moltbot:
emoji: "🗣️"
category: "voice"
api_base: "https://api.moltspaces.com/v1"
env:
- OPENAI_API_KEY
- ELEVENLABS_API_KEY
The documentation instructs the agent to help populate a local .env file with multiple API keys, which is a sensitive secret-handling workflow beyond the simple stated purpose of joining audio rooms. This expands the attack surface by normalizing local credential collection and storage, and could lead to accidental disclosure or misuse if the agent has broader file access.
Fetching voice metadata from ElevenLabs is an auxiliary external action not strictly required to join a room, and it causes additional outbound transmission using a third-party API key. While likely product-motivated rather than malicious, it broadens data flows and privileges beyond the core skill purpose.
Registering a new agent account on Moltspaces exceeds the narrowly described function of joining spaces and results in creation of persistent credentials and identities. This is security-relevant because it provisions new secrets and external accounts that a user may not expect from a room-joining skill.
The instructions tell users to place multiple sensitive API keys into a .env file without clear warnings about secret exposure, file permissions, redaction, or avoiding commits/logging. This is dangerous because .env files are commonly leaked through source control, backups, or overly broad file access.
The skill directs the agent to generate and save personality and notes files locally, introducing persistent filesystem writes beyond the advertised social-audio function. Persistent prompt/context files can contain sensitive user preferences, memories, or behavioral instructions that may later be exfiltrated or misused by other processes.
Redirecting bot output to bot.log without warning can capture room URLs, join tokens, API errors, prompts, or conversation content in plaintext. Because the process is long-running and network-connected, log files may accumulate sensitive material that persists long after the session ends.
The bot streams highly sensitive audio, speech transcripts, and generated responses to multiple third-party services (ElevenLabs, OpenAI, Daily) but this file contains no user-facing notice, consent flow, or indication that participants are informed before processing begins. In a live voice-room context, users may reasonably assume they are speaking only to other participants, so silent transmission to external AI providers creates a meaningful privacy and compliance risk.
The dependency specification for pipecat-ai is unpinned, so installations may resolve to different versions over time, including versions with known security advisories. In a real-time voice/agent skill, this increases supply-chain risk because vulnerable framework components could expose network-facing attack surfaces such as WebRTC, websocket, file-serving, or deserialization paths.
fastapi is declared without a pinned version, making it impossible to verify whether the installed release contains fixes for known advisories. Because FastAPI is typically used for network-exposed API surfaces, an unsafe resolved version could introduce web-layer issues depending on how the skill serves endpoints.
uvicorn is also unpinned, so the environment may install a vulnerable release with known HTTP/logging-related issues. As an ASGI server, it may directly handle untrusted traffic, so version drift can expose the service to avoidable network-facing weaknesses.
No suspicious patterns detected.