T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:9- Finding
Overbroad Access to Private Mobile Notifications
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 9-15 and 27-40
Vulnerability Type: Excessive access to private notification data
Risk Level: HighVulnerable Code Snippet
The following is an English translation of the complete relevant instruction segment:
text - Internal signals: Notifications on the user's mobile phone (content-platform pushes, industry group chats, team discussions, and fan feedback). Users configure three areas of interest through the installation prompt: - Whom to follow: benchmark bloggers, peer accounts, competitor creators, brand accounts, or content sources explicitly selected by the user. - What to follow: account vertical, content positioning, audience profile, and industry keywords. - Which groups and applications to follow: monitored source platforms and groups, such as Xiaohongshu, Bilibili, Jike, official accounts, WeChat industry groups, creator groups, and internal team discussion groups. 1. Query notifications for the specified time range by executing: command: openclaw ntf search --from START_TIME --to END_TIME yieldMs: 30000 2. Tasks involving "yesterday," "recently," "just now," or "latest notifications" must always perform a new query and must not reuse old results. 3. Read the user's configured people, topics, groups, and applications. If the user did not provide them, infer the most likely filtering direction from the current request and notification context. 4. Filter notifications for content-platform pushes, creator-related group chats, benchmark-blogger updates, industry keyword matches, and fan feedback.Technical Analysis
The Skill directs the agent to execute a time-range-wide notification search and subsequently inspect notifications originating from personal applications, industry groups, creator communities, and internal team discussions. The documented command does not include an app ...[truncated 2256 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user consent before the first notification query and clearly identify the applications, groups, time interval, and data fields that will be accessed.
- If configuration is missing, ask the user to select permitted sources instead of inferring authorization from notification contents.
- Apply an application, group, or sender allowlist inside the notification query so excluded data is never returned to the agent.
- Retrieve only the minimum required fields, such as source, timestamp, and a locally generated topic label. Avoid returning full message bodies by default.
- Exclude personal applications and sensitive notification categories unless separately authorized.
- Redact contact identities, message contents, project names, authentication data, and other sensitive values before they enter the model context.
- Display a confirmation prompt before expanding the time range or adding another notification source.
- Document retention rules and ensure raw notification data is discarded immediately after local filtering.
- Maintain an auditable record of the approved scope without storing notification contents.
