T05 · Unauthorized Access and Privilege Escalation
- Location
references/direct-api.md:21- Finding
Unnecessary Access to Agent Identity Files During OAuth Device Registration
- Content
View full analysis
- # e.g. Max - Mac Mini; name from IDENTITY.md (OpenClaw) / ~/.hermes/SOUL.md (Hermes) ``` ### Technical Analysis The instructions direct the Agent to read a name from `IDENTITY.md` or `~/.hermes/SOUL.md` and include it in an outbound OAuth device-authorization request. These files may contain Agent identity, profile, behavioral, or other persistent configuration information. OAuth device registration only requires a descriptive device label. Reading persistent Agent identity files is therefore not necessary for the Skill’s shopping functionality and violates least-privilege principles. It also creates an avoidable path through which information derived from local Agent state is transmitted to an external service. The instructions specify use of the name rather than the entire file, which limits the likely disclosure. There is no evidence that arbitrary file contents or credentials are intentionally exfiltrated. ### Attack Path 1. The Skill is invoked while the Shop CLI is unavailable. 2. The Agent follows the manual device-authorization instructions. 3. The Agent opens `IDENTITY.md` or `~/.hermes/SOUL.md`. 4. It extracts identity information from that persistent file. 5. The extracted value is placed in the `device_name` parameter. 6. The value is transmitted to `https://accounts.shop.app/oauth/device`. ### Impact Assessment The behavior grants the Skill unnecessary read access to persistent Agent identity or profile state. Information derived from that state can be disclosed to Shopify’s account service. The confirm ...[truncated 251 chars]- Remediation
View remediation
