T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:93- Finding
Sensitive Transcript Database Access Through Crash-Recovery Instructions
- Content
View full analysis
/agents//agent/openclaw-agent.sqlite* /tmp/db-inspect/ ``` The exact path depends on the OpenClaw version and agent layout — look under your host's OpenClaw state directory (commonly `~/.openclaw/`), find the agent's `agent/` folder, and copy every `*.sqlite*` file. The schema is `transcript_events` with `session_id`, `seq`, `created_at`, and an `event_json` payload column. 3. **Convert the wall-clock window to epoch milliseconds** (use the host's timezone; `+0300` in this example): ```bash date -d "YYYY-MM-DD HH:MM:SS +0300" +%s%3N # repeat for start and end ``` 4. **Locate the user messages in the window** (`event_json` holds `{"message":{"role":"user","content":...}}`): ```bash sqlite3 /tmp/db-inspect/openclaw-agent.sqlite \ "SELECT seq, created_at, substr(event_json,1,400) FROM transcript_events \ WHERE session_id='' AND created_at BETWEEN AND \ AND event_json LIKE '%\"role\":\"user\"%' ORDER BY seq;" ``` 5. **Dump the full window and parse it** into readable dialogue: ```bash sqlite3 /tmp/db-inspect/openclaw-agent.sqlite \ "SELECT event_json FROM transcript_events WHERE sessi ...[truncated 2913 chars]- Remediation
View remediation
