T09 · Insecure Skill Coding Practices
- Location
SKILL.md:346- Finding
Unauthenticated Disclosure of OpenClaw Memory Contents
- Content
View full analysis
f.endsWith('.md'))) { const content = await fs.readFile(path.join(memoryDir, file), 'utf-8'); memories.push({ id: file, title: file.replace('.md', ''), content: content.slice(0, 500) + '...', createdAt: new Date().toISOString(), }); } return NextResponse.json(memories); } catch (error) { return NextResponse.json([]); } } ``` ### Technical Analysis The generated `/api/sync` GET handler accesses every Markdown file in the OpenClaw memory directory under the server account's home directory. It then returns filenames and the first 500 characters of each file in an HTTP response. The route contains no authentication or authorization check. Although reading OpenClaw memories is necessary for the declared memory-browser feature, exposing those memories to every caller capable of reaching the endpoint exceeds minimum safe privilege. The later documentation acknowledges that authentication is absent and recommends running locally or behind a VPN, but this warning does not protect the generated implementation. The fixed directory and `.md` filter reduce arbitrary-file-read risk, but they do not prevent disclosure of sensitive information legitimately stored in OpenClaw memory files. The application also returns all available memory excerpts rather than requiring the user to select individual records. ### Attack Path 1. A user implements and starts the dashboard as instructed. 2. The application becomes reachable by an ...[truncated 1235 chars]- Remediation
View remediation
