T09 · Insecure Skill Coding Practices
- Location
scripts/audit.py:107- Finding
Audit History Deletion and Truncation Can Pass Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local audit logger, but it overstates the strength of its audit trail and may store sensitive activity details in mutable plaintext files.
Install only if you treat this as a convenience activity log, not as a reliable compliance, incident-response, or tamper-proof audit system. Avoid logging secrets, tokens, personal data, or detailed financial/account information unless filesystem permissions and retention are managed separately.
scripts/audit.py:107Audit History Deletion and Truncation Can Pass Integrity Verification
scripts/audit.py:29Malformed Audit Files Are Silently Discarded and Overwritten
scripts/audit.py:15Audit Records Are Stored in Plaintext Without Enforced Private Permissions
The skill documents commands that write persistent audit logs to ~/.openclaw/audit/, which is a file-write capability, but it does not declare any tool scope such as permissions or allowed-tools. This creates a transparency and least-privilege gap: an agent or reviewer may invoke the skill without an explicit understanding that it can modify local state and persist potentially sensitive operational data.
The skill advertises an 'immutable' audit trail, but the implementation only maintains a locally stored hash chain over mutable JSON files. This mismatch is dangerous because operators may rely on the logs for governance or incident response, even though a local attacker can edit history and preserve internal consistency by recalculating hashes.
The code rewrites the entire audit file with normal local file permissions in a user-writable directory, so any process with the same user privileges can alter, truncate, or replace the log and then recompute the hash chain. Because there is no append-only storage, external anchoring, signature, or protected write path, the claimed tamper-evidence is weak and can be bypassed by an attacker who can modify local files.
No suspicious patterns detected.