T09 · Insecure Skill Coding Practices
- Location
references/backup.md:207- Finding
Automatic plaintext upload of private conversations, memory, and workspace state to IPFS
- Content
View full analysis
Vulnerability Details
File Location:
references/backup.md:3-7, 207-250, 329-335;references/config.md:16-37, 139-143;SKILL.md:191-209, 234-235
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: CriticalVulnerable Snippets
From
references/backup.md:3-7:text ## First-time - `backup init` — register the agent on SoulRegistry (if not yet registered), run a first **full** backup, write `~/.coc-backup/latest-recovery.json` with the decryption material + manifest CID. - `backup register` — register on-chain only, do not run a backup. ## Periodic - `backup create` — incremental (default); `--full` forces a full backup regardless of chain length. - `backup.autoBackup: true` + `backup.autoBackupIntervalMs` runs this on a timer inside the OpenClaw plugin. - `backup.backupOnSessionEnd: true` + a `session_end` hook from OpenClaw also triggers `backup create` when the agent's session closes.From
references/backup.md:214-250:text ### Memory (markdowns; root **or** `workspace/`; not encrypted) - `MEMORY.md` - `USER.md` - `RECOVERY_CONTEXT.md` (regenerated on restore) - everything under `memory/*.md` **or** `workspace/memory/*.md` (1.2.9+) — daily / per-topic notes (`workspace/memory/2026-04-27.md`, `workspace/memory/topic-foo.md`, etc.) ### Workspace (markdowns + state; root **or** `workspace/`; not encrypted) - `AGENTS.md` - `TOOLS.md` — tools manifest (1.2.9+) - `HEARTBEAT.md` — soul's own heartbeat file (1.2.9+; soul writes it, soul backs it up) - `workspace-state.json` (root location, legacy) - `workspace/.openclaw/workspace-state.json` (current OpenClaw layout, 1.2.9+) ### Identity / config (fixed paths) - `identity/device.json` (config, **encrypted**) - `identity/device-auth.json` (config, **encrypted**, 1.2.9+ — paired with device.json for cross-device auth) - `auth.json` (config, **encrypted**) - `openclaw.json` (config, **encrypted** ...[truncated 4247 chars]- Remediation
View remediation
Remediation Suggestions
- Require authenticated encryption for every remotely stored file and manifest; do not permit plaintext IPFS uploads in normal operation.
- Change
encryptMemorytotrueby default and extend encryption to chat, identity Markdown, workspace data, plugin metadata, and semantic snapshots. - Disable
autoBackup,backupOnSessionEnd, semantic snapshots, and every data category by default. - Require explicit informed consent for each category before its first upload, with a preview of files, total size, destination, encryption mode, and retention implications.
- Separate DID registration from backup initialization so registering an identity never implicitly uploads local data.
- Use envelope encryption with per-backup data keys and a hardware-backed, KMS-backed, or user-controlled key-encryption mechanism.
- Add a strict secret scanner and redaction stage before packaging. Block uploads containing private keys, API tokens, OAuth profiles, session cookies, or authentication material.
- Avoid placing manifest CIDs directly on a public chain when doing so increases discoverability; use encrypted indirection or a privacy-preserving registry design.
- Add remote unpinning, retention policies, tombstone handling, and clear warnings that third-party IPFS replication may prevent complete deletion.
- Require a successful local encryption and restore test before enabling periodic backups.
