Back to skill

Security audit

ACP Transcript Sync

Security checks for vulnerabilities and agentic risk

Overview

This skill openly merges child-agent transcripts into the main session, but it does so with broad persistent transcript access and weak safeguards around sensitive data and target paths.

Install only if you intentionally want child-agent conversations copied into the main OpenClaw transcript for downstream collection. Do not use it for sessions that may contain credentials, private data, sensitive prompts, or untrusted tool output unless the script is changed to validate paths, preview the destination, redact sensitive content, and preserve imported content as untrusted provenance-marked data.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sync-acp-to-main.py:118
Finding

Path Traversal Through Unvalidated Session and Agent Identifiers

Content
View full analysis
3 else None main_agent = sys.argv[4] if len(sys.argv) > 4 else None success = sync_acp_to_main( acp_sid, acp_agent=acp_agent, main_agent=main_agent, main_session_id=main_sid ) ``` ### Technical Analysis The script embeds caller-controlled agent and session identifiers directly into filesystem paths. It does not validate identifiers as UUIDs or safe agent names, canonicalize the resulting paths, or verify that resolved paths remain beneath the intended `~/.openclaw/agents//sessions` directo ...[truncated 2248 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
scripts/sync-acp-to-main.py:175
Finding

Persistent Transcript Poisoning Through Untrusted Child-Session Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This instruction explicitly promotes copying all ACP sub-session content into the main transcript so another platform can observe the full reasoning chain. That can exfiltrate sensitive prompts, user data, secrets, and chain-of-thought-like internal reasoning into a broader-access log, increasing disclosure and retention risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill context makes this more dangerous, not less, because the stated purpose is to make the complete interaction chain visible to an external collection platform. In a transcript-management skill, broad replication of sub-session contents is the core behavior, so the privacy and data-leak risk is direct and intentional rather than incidental.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented format explicitly copies both sub-session user inputs and assistant replies into the main transcript. This broad duplication can leak personal data, credentials, proprietary prompts, or internal reasoning artifacts into a second log location with different access, retention, and monitoring properties.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes reading and writing session transcript files and invoking a Python script, but it does not declare any tool/permission scope. That creates an authorization and transparency gap: operators cannot easily constrain file access or understand that the skill can modify transcripts under user home directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the skill syncs child-session content into the main transcript for AIMA collection, but it omits a clear warning that this may expose user inputs, model outputs, and possibly sensitive reasoning or secrets to broader retention and downstream collection. This is dangerous because users may trigger the skill without informed consent about expanded data exposure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Mandating that write-back must always occur removes discretion and safety checks, making accidental over-collection more likely. A compulsory sync behavior is especially risky when the destination is intended for platform collection, because it normalizes copying sensitive child-session data even when unnecessary.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script is explicitly designed to copy a full child-session transcript into the main session so downstream collectors can see the child agent's complete reasoning and work record. That creates a real cross-session disclosure path: secrets, prompts, tool outputs, or sensitive user data present in the ACP transcript will be duplicated into another log and potentially exposed to broader retention, indexing, or monitoring systems.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code extracts all user and assistant message text from the ACP session and serializes it back into another session log, including tool-result snippets. Because there is no classification, consent, or sanitization step, any sensitive material in the sub-session can be semantically exfiltrated into the main session and then into whatever systems consume that main log.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

At the write stage, the script appends reconstructed ACP transcript entries directly into the main session JSONL, turning an isolated sub-session into content visible through the primary session's collection path. In this skill context, that is more dangerous because the description explicitly targets AIMA/platform collection of the combined transcript, increasing the likelihood of wider disclosure and retention of sensitive child-session content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script performs a file write that alters the main session jsonl by appending reconstructed messages from another session. Although the script has a general docstring describing its purpose, there is no confirmation step or explicit user-facing warning at the point of execution that conversation history will be modified and merged automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script uses AGENT_ID or OPENCLAW_AGENT_ID to infer the target main agent, which can affect which session transcript is later modified. While this is functional behavior, the usage/help text does not warn users that environment variables can silently determine the destination when main_agent is omitted.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.