T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:351- Finding
Unrestricted Access to Agent Memory for Financial Analysis
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:351
Vulnerability Type: Unrestricted access to Agent memory
Risk Level: MediumVulnerable Code Snippet
markdown - **OpenClaw / VPS** — historical data from memory/ агента → trends and forecastsEnglish translation:
text OpenClaw / VPS — historical data from the Agent's memory/ → trends and forecastsTechnical Analysis
The Skill instructs the Agent to use historical data from the general
memory/area when producing trends and forecasts. It does not:- restrict access to a Skill-specific directory;
- identify the records that may be read;
- require explicit user authorization;
- limit retrieval to the current company or conversation;
- exclude credentials, unrelated conversations, or other sensitive records.
A shared Agent memory may contain information from unrelated sessions, users, companies, or tasks. Treating that entire location as an analytics data source violates least-privilege principles. The legitimate task only requires financial records explicitly supplied by the user or stored in a dedicated, scoped dataset.
The repository does not include code that independently reads this directory, so exploitation depends on the host Agent interpreting and acting on the Skill instruction. No network exfiltration mechanism was identified.
Attack Path
- A user or operator installs and loads the Skill in an OpenClaw/VPS Agent that has access to persistent memory.
- The Agent's
memory/area contains historical information from other conversations or business activities. - A user requests a trend analysis or forecast.
- Following
SKILL.md:351, the Agent searches or reads the general memory area as a historical data source. - Unrelated sensitive information is incorporated into calculations, summaries, assumptions, or generated reports.
- The requesting user may infer or directly receive information that was not intended for the current analysis.
Impact
...[truncated 583 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the instruction to access the general Agent
memory/directory implicitly. -
Require explicit user consent before reading persistent historical information.
-
Store Skill data in a dedicated location, such as:
text memory/business-analyst-pro/<tenant-or-company-id>/ -
Enforce tenant, company, and user ownership checks before every read.
-
Allow users to select or approve the exact files and periods used for analysis.
-
Restrict retrieval to an allowlist of financial data types required for the requested report.
-
Exclude credentials, tokens, integration configuration, unrelated conversations, and free-form Agent state.
-
Record data provenance in generated reports so users can verify which records were used.
-
Prefer current-session data or explicitly uploaded datasets when persistent history is unnecessary.
-
Add host-level permission controls so the Skill cannot access memory belonging to another user or company.
-
