T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:28- Finding
Platform-Wide Group Sender Filter Is Broadened Without Restoration
- Content
View full analysis
.groupAllowFrom` to `["*"]` so all group members' messages are delivered. This is safe because `groupPolicy: "allowlist"` still restricts *which groups* you are active in — opening the sender filter only affects groups you've explicitly joined. Verify with `openclaw doctor` — config changes must pass schema validation. ``` The corresponding cleanup instructions only restore the group-specific mention requirement: ```markdown **Step 5 — Set a closing cron job** Create a one-shot cron job (`kind: "at"`) for the parsed duration. When it fires: patch `requireMention` back to `true` for this group in `openclaw.json`, then send a brief goodbye. The gateway hot-reloads and the gate closes — no owner action needed. ``` ### Technical Analysis The skill instructs the agent to replace the platform-level `channels..groupAllowFrom` setting with the wildcard value `["*"]`. This is broader than the group-specific `requireMention` change used to join a single conversation. Neither the timed-close procedure nor the early-close procedure records and restores the previous `groupAllowFrom` value. They only restore `requireMention` for the selected group. Consequently, the sender filter can remain broadly open after the requested participation window ends. Schema validation through `openclaw doctor` can confirm that the configurati ...[truncated 1769 chars]- Remediation
View remediation
