Back to skill

Security audit

Cc Session Bridge

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says as a Claude Code to AIMA session bridge, but it persistently records and shares very detailed session data with weak scoping and authorization controls.

Review before installing. Use only in workspaces where prompts, tool outputs, file-derived content, metadata, and task viewers are allowed to see the resulting session records. Prefer an explicit minimal --cwd, avoid sensitive directories, restrict AIMA CLI credentials, and do not rely on the supplied sender/task fields as verified identity without additional controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cc-session-bridge.py:253
Finding

Arbitrary Filesystem Access Through Unvalidated Agent Name

Content
View full analysis
str: sessions_dir = os.path.expanduser(f"~/.openclaw/agents/{agent_name}/sessions") return os.path.join(sessions_dir, MAP_FILE_NAME) ``` ```python def find_local_session(task_id: str, agent_name: str) -> tuple: """According to task_id find local session file, return (session_id, jsonl_path) or (None, None)""" mapping = load_task_session_map(agent_name) session_id = mapping.get(str(task_id)) if not session_id: return None, None sessions_dir = os.path.expanduser(f"~/.openclaw/agents/{agent_name}/sessions") jsonl_path = os.path.join(sessions_dir, f"{session_id}.jsonl") ``` ```python sessions_dir = os.path.expanduser(f"~/.openclaw/agents/{args.agent_name}/sessions") os.makedirs(sessions_dir, exist_ok=True) ``` ### Technical Analysis The caller-controlled `--agent-name` value is interpolated directly into filesystem paths. The code does not restrict the value to a safe agent-name syntax, resolve the resulting path to its canonical form, or verify that it remains beneath `~/.openclaw/agents`. An agent name containing traversal components such as `../` can therefore cause the session directory to resolve outside the intended agent storage hierarchy. The affected path is subsequently used for: - Directory creation through `os.makedirs`. - Reading and writing `task-session-map.json`. - Creating and appending session JSONL files. - Loading existing session mappings. - Following filesystem symbolic links without validation. Although generated session file names are UUID-based, an attacker can still direct their creation into an unintended directory. If the attacker can prepare a mapping file or symbolic link at the resolved location, the app ...[truncated 1463 chars]
Remediation
View remediation
str: if not AGENT_NAME_PATTERN.fullmatch(agent_name): raise ValueError("Invalid agent name") return agent_name ``` 2. Resolve and enforce canonical path containment: ```python base_dir = os.path.realpath(os.path.expanduser("~/.openclaw/agents")) sessions_dir = os.path.realpath( os.path.join(base_dir, validate_agent_name(agent_name), "sessions") ) if os.path.commonpath([base_dir, sessions_dir]) != base_dir: raise ValueError("Agent session path escapes the allowed directory") ``` 3. Reject symbolic links in sensitive path components and mapping/session files. Where supported, use file descriptors with `O_NOFOLLOW`. 4. Write mapping files atomically by creating a securely permissioned temporary file in the same directory, calling `fsync`, and replacing the destination with `os.replace`. 5. Create session directories and files with restrictive permissions, such as directory mode `0700` and file mode `0600`. 6. If the application has a registry of valid agents, require `--agent-name` to match an existing authorized agent rather than accepting arbitrary names. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cc-session-bridge.py:611
Finding

Caller-Controlled Identity Spoofing and Unauthorized Task Attribution

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/cc-session-bridge.py:369
Finding

Unredacted Persistence and Export of Sensitive Claude Code Telemetry

Content
View full analysis
Complete raw data\n\n```json\n{raw_text}\n```\n\n" ) record = {"type": "message", "id": msg_id, " ...[truncated 5031 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow says every raw CC event and the complete final text should be written to the session record for downstream collection/display. In context, this is dangerous because the bridge is specifically designed to transform one system's full interaction stream into another platform's persistent session store, magnifying exposure of sensitive interaction data.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly emphasizes preserving complete CC session contents, including internal reasoning, tool inputs, tool outputs, and unknown raw events, then exposing them to AIMA collection and display. This creates a high-risk data exfiltration path for secrets, proprietary code, credentials, personal data, and sensitive workspace contents that may appear in prompts, reasoning traces, or tool results.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs users to install and run a Python script, invoke shell commands, and let CC read/write session data, but it does not declare any explicit tool scope or permission boundaries. That omission can cause operators to invoke the skill without understanding it needs filesystem and shell access, increasing the chance of over-broad execution in sensitive environments.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The skill installs persistent scripts and configuration into global per-user OpenClaw directories and is designed to append and bind sessions across runs. Persistent installation and session retention increase the blast radius of misconfiguration or data leakage because sensitive session data can remain on disk and continue to be reused or exposed over time.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

bash
# 1. 解压技能包到 skills 目录
mkdir -p ~/.openclaw/skills
unzip -o <技能包路径>/cc-session-bridge.skill -d ~/.openclaw/skills/

# 2. 拷贝脚本和配置到全局目录

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Although the document notes that CC works in the specified or current directory, it does not present this as a prominent security warning. Users may overlook that running without --cwd defaults to the current directory, allowing CC to read unintended files from whatever location the command is launched in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script records the user query together with sender metadata and chat identifiers into persistent session files without any meaningful warning, consent flow, or minimization. Because these fields can contain personal or business-sensitive information, silent retention creates privacy, compliance, and insider-access risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/cc-session-bridge.py (reported line 310)May include surrounding context.

python
cmd = ["claude", "-p", "--output-format", "stream-json", "--verbose", "--model", model, query]
    print(f"🚀 启动 CC (流式): model={model}")

    proc = subprocess.Popen(
        cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True, bufsize=1,
        cwd=cc_cwd
    )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The raw-event persistence path writes complete CC events and later tool results to disk without clear disclosure, which can capture sensitive command output, file contents, credentials, and other high-value data. Because this logging is automatic and broad, it materially increases the chance of overcollection and unintended disclosure through the resulting session artifacts.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The bridge is designed to preserve and re-embed complete conversation content, sender metadata, and raw CC events into persistent records, creating a durable collection pipeline for untrusted and potentially sensitive content. In this skill context, that makes the data-handling semantics more dangerous because the tool is positioned as a bridge/display helper rather than an explicit archival or compliance logging system.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script persists full CC initialization metadata, including working directory, tools, MCP servers, memory paths, plugins, agents, API key source, and related environment details, to disk. In a bridge whose advertised role is session conversion/display, this broad collection meaningfully increases exposure of sensitive system and integration metadata that could aid lateral movement, reconnaissance, or privacy leakage if the session logs are accessed by others.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script stores raw assistant events, raw user/tool-result events, and tool outputs to disk, which can include prompts, model thinking, command output, file contents, secrets, tokens, and internal operational data. This exceeds normal session-format bridging and effectively creates an audit archive of potentially sensitive material, raising confidentiality and data-retention risk substantially.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Beyond local session bridging, the script automatically invokes the AIMA CLI to bind a session to a task, modifying external system state on every run. This creates a side-effecting integration action that may be unexpected, may associate logs with the wrong task if inputs are mistaken or abused, and increases the blast radius beyond local file generation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/cc-session-bridge.py (reported line 698)May include surrounding context.

python
# 绑定 AIMA 任务(每次调用都绑定,新建和追加均执行)
    try:
        bind_result = subprocess.run(
            ["aima", "workspace", "task", "bind-session", "--taskId", args.task_id, "--sessionId", session_id],
            capture_output=True, text=True, timeout=30
        )

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

All natural-language instructions, triggers, and examples are presented exclusively in Chinese, with no indication that users may interact in another language or that the skill is intentionally limited to a Chinese-language environment. Under the policy, forcing a specific language without opt-in or documented justification is a locale-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing natural-language documentation and CLI help text in this file are presented in Chinese, with no indication that other languages are supported or that the locale is intentionally restricted for a region-specific use case. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.