T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:33- Finding
Automatic Overcollection of Private Session Transcripts
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 33–43
Vulnerability Type: Excessive access to session history beyond least-privilege requirements
Risk Level: MediumVulnerable Code
markdown Before processing any manual input, automatically pull this week's activity from OpenClaw sessions. 1. Call `sessions_list` to get all sessions from the past 7 days. Filter by `activeMinutes` or check timestamps to scope to the current week (Monday–today). 2. For each session returned, call `sessions_history` with `includeTools: false` to get the conversation transcript. 3. Scan each transcript for: - Projects or codebases mentioned by name - Work described as completed ("shipped", "fixed", "merged", "deployed", "published", "resolved", "done") - Work described as in progress ("working on", "started", "investigating", "blocked on", "continuing") - Decisions made or conclusions reached 4. Build a raw activity list grouped by project. Ignore small talk, clarification exchanges, and meta-conversation about Claude itself. 5. If `sessions_list` or `sessions_history` are unavailable, skip this step silently and proceed with manual input only.Technical Analysis
The skill instructs the agent to enumerate all sessions from the relevant period and retrieve the complete conversation history of every returned session before considering whether the user supplied sufficient manual notes. This behavior violates the principle of least privilege because generating a weekly update does not inherently require unrestricted access to every recent conversation.
Setting
includeTools: falseexcludes tool-call details but does not prevent exposure of sensitive information contained in user and assistant messages. Retrieved transcripts may contain credentials, personal information, confidential project details, third-party data, or conversations unrelated to the requested update. The instruction to scan eve ...[truncated 2066 chars]- Remediation
View remediation
Remediation Suggestions
- Require explicit informed consent before accessing session history, clearly stating the time range and the type of content that will be read.
- Use manual notes as the default source. Access session history only when the user expressly requests automatic extraction.
- Present matching session metadata first and allow the user to select which sessions may be processed.
- Retrieve only the minimum required excerpts rather than complete transcripts whenever the host API supports scoped search or filtering.
- Exclude sessions unrelated to work activity through metadata-based filtering before calling
sessions_history. - Apply secret detection and redaction to credentials, tokens, personal data, and unrelated third-party information before generating the update.
- Prevent extracted details from appearing in output unless they are directly relevant to the requested report.
- Document retention behavior and ensure transcript content is not persisted beyond the active request.
- Replace silent fallback behavior with a clear statement identifying which data sources were used, allowing the user to verify the scope of access.
