Back to skill

Security audit

Weekly Update

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to generate weekly updates, but it automatically reads all recent session transcripts without a per-use confirmation.

Review before installing. Use this only if you are comfortable with the agent reading this week's OpenClaw conversation transcripts to build the update. Prefer manual notes or a revised version that asks permission, shows candidate sessions, and states whether session history was used.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:33
Finding

Automatic Overcollection of Private Session Transcripts

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 33–43
Vulnerability Type: Excessive access to session history beyond least-privilege requirements
Risk Level: Medium

Vulnerable Code

markdown
Before processing any manual input, automatically pull this week's activity from OpenClaw sessions.

1. Call `sessions_list` to get all sessions from the past 7 days. Filter by `activeMinutes` or check timestamps to scope to the current week (Monday–today).
2. For each session returned, call `sessions_history` with `includeTools: false` to get the conversation transcript.
3. Scan each transcript for:
   - Projects or codebases mentioned by name
   - Work described as completed ("shipped", "fixed", "merged", "deployed", "published", "resolved", "done")
   - Work described as in progress ("working on", "started", "investigating", "blocked on", "continuing")
   - Decisions made or conclusions reached
4. Build a raw activity list grouped by project. Ignore small talk, clarification exchanges, and meta-conversation about Claude itself.
5. If `sessions_list` or `sessions_history` are unavailable, skip this step silently and proceed with manual input only.

Technical Analysis

The skill instructs the agent to enumerate all sessions from the relevant period and retrieve the complete conversation history of every returned session before considering whether the user supplied sufficient manual notes. This behavior violates the principle of least privilege because generating a weekly update does not inherently require unrestricted access to every recent conversation.

Setting includeTools: false excludes tool-call details but does not prevent exposure of sensitive information contained in user and assistant messages. Retrieved transcripts may contain credentials, personal information, confidential project details, third-party data, or conversations unrelated to the requested update. The instruction to scan eve ...[truncated 2066 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit informed consent before accessing session history, clearly stating the time range and the type of content that will be read.
  2. Use manual notes as the default source. Access session history only when the user expressly requests automatic extraction.
  3. Present matching session metadata first and allow the user to select which sessions may be processed.
  4. Retrieve only the minimum required excerpts rather than complete transcripts whenever the host API supports scoped search or filtering.
  5. Exclude sessions unrelated to work activity through metadata-based filtering before calling sessions_history.
  6. Apply secret detection and redaction to credentials, tokens, personal data, and unrelated third-party information before generating the update.
  7. Prevent extracted details from appearing in output unless they are directly relevant to the requested report.
  8. Document retention behavior and ensure transcript content is not persisted beyond the active request.
  9. Replace silent fallback behavior with a clear statement identifying which data sources were used, allowing the user to verify the scope of access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to automatically read prior session logs and transcripts without any explicit user-facing consent, notice, or confirmation at the point of use. Because weekly summaries can be invoked by broad prompts, this creates a real privacy risk: sensitive content from unrelated past conversations may be ingested and surfaced unexpectedly.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to scan full session transcripts and extract project activity, which can pull sensitive user-provided information from prior conversations into a new summary context. Even with includeTools: false, the conversational content itself may contain secrets, personal data, confidential project names, or incidental details that the user did not intend to reuse or disclose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest-style JSON file includes the prompt "Generate my weekly update," which is a common natural-language phrase rather than a narrowly scoped invocation. Without any documented trigger constraints or exclusion conditions, the phrase could overlap with ordinary user requests and create ambiguity about when the skill should activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The phrase "Weekly update time" is informal and broad, and the file does not define whether this is an activation trigger or merely test input. In a manifest-like eval file, such broad phrasing can contribute to unclear invocation boundaries if reused as trigger guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The prompt "generate my weekly update" is still a generic everyday request and lacks contextual constraints or exclusions. Because the file provides no negative examples or scope limits, it could be interpreted as a trigger that is too broad for reliable skill routing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instruction to 'skip this step silently' hides whether historical session data was accessed or unavailable, reducing transparency about what sources were used to generate the output. This can mislead users about completeness and provenance, especially when summaries appear authoritative despite missing or partial inputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.