T09 · Insecure Skill Coding Practices
- Location
SKILL.md:98- Finding
Unscoped Browser Tab Destruction in Shared OpenClaw Profile
- Content
View full analysis
" ``` ``` ### Technical Analysis The cleanup procedure instructs the agent to enumerate all tabs associated with the `openclaw` browser profile and close every tab other than a newly created blank tab. It does not restrict cleanup to the Facebook tab created by this skill. The browser profile is a shared resource that may contain tabs opened by users, other skills, or concurrent agent workflows. The skill already receives a unique `targetId` when it opens the Meta Business Suite page, so enumerating and closing unrelated targets is unnecessary and violates least-resource principles. This behavior does not grant operating-system privileges or access to additional accounts. However, it allows the skill to destructively modify browser state outside the legitimate scope of its Facebook inbox task. ### Attack Path 1. A user or another agent workflow opens one or more unrelated tabs in the `openclaw` browser profile. 2. The Facebook inbox skill is invoked to inspect or manage messages. 3. The skill opens its Meta Business Suite tab and performs the requested operation. 4. During cleanup, it opens a new `about:blank` tab. 5. It enumerates every tab in the shared profile. 6. Following the documented procedure, it closes all targets except the newest blank tab. 7. Unrelated tabs are destroyed, potentially interrupting other workflows and discarding unsaved browser state. No at ...[truncated 784 chars]- Remediation
View remediation
" ``` The skill should preserve every pre-existing tab and every tab whose ownership cannot be established. ]]>
