T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:16- Finding
Overly Broad Tool Permissions Violate Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 16
Vulnerability Type:T05: Unauthorized Access and Privilege Escalation
Risk Level: MediumVulnerable Code:
text openclaw config set tools.allow '["browser","group:runtime","group:fs","group:web"]'Technical Analysis
The Skill directs users to enable broad browser, runtime, filesystem, and web tool groups. The documented workflow only requires browser automation and execution of a specific local helper, so unrestricted filesystem and web capabilities are not adequately justified.
This configuration breaks the principle of least privilege by combining capabilities that can read local data, execute commands, and communicate with external systems. If malicious or attacker-controlled content later influences the Agent, these permissions could be chained to perform actions beyond native file-dialog handling. Because the instruction modifies the OpenClaw configuration rather than describing a narrowly scoped, one-time grant, the enlarged permission boundary may also remain available after the immediate workflow unless explicitly reverted.
Attack Path
- A user installs or follows the Skill and executes the documented
tools.allowconfiguration command. - The Agent gains access to broad runtime, filesystem, browser, and web tool groups.
- Attacker-controlled web content, a malicious prompt, or another untrusted task influences the Agent while those permissions are enabled.
- The influenced Agent uses filesystem access to inspect files beyond the intended upload target.
- Runtime access is used to execute additional local commands, or web access is used to transmit collected information to an external endpoint.
- The unintended access can continue in subsequent operations if the configuration remains enabled.
Impact Assessment
Successful exploitation could provide access to files available under the Agent's operating-system ...[truncated 393 chars]
- A user installs or follows the Skill and executes the documented
- Remediation
View remediation
Remediation Suggestions
- Replace broad tool-group grants with an allowlist containing only the exact browser operation and executable required by this workflow.
- Remove
group:webunless an explicit, documented network operation is necessary. - Restrict filesystem access to the intended upload file or a dedicated upload directory.
- Restrict runtime execution to the exact PowerShell executable and a reviewed helper script with fixed arguments.
- Require explicit user confirmation before running the helper command and before publishing content.
- Save the prior tool configuration and restore it immediately after the workflow completes.
- Include the referenced helper script in the audited package, pin its path, and validate or safely quote all filename arguments before passing them to PowerShell.
- Document the minimum required permissions and fail closed when those scoped permissions are unavailable.
