T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:29- Finding
Overbroad Access to Recent Phone Notifications
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:29andSKILL.md:130-175
Vulnerability Type: Excessive notification access and violation of least privilege
Risk Level: HighRelevant instruction excerpt, translated into English:
text If notification context is needed, query recent notifications without restricting the group or application scope. If a user request involves notifications, fan groups, viewing groups, phone reminders, or notification-derived discussion material, notifications must be queried before generating the notification-related module. Use exec to run openclaw ntf search. If the user does not provide a time range, query from yesterday at 00:00 local time through the current time. command: openclaw ntf search --from START_TIME --to END_TIME yieldMs: 30000Technical Analysis
The Skill performs a broad notification query when notification context is requested but the user has not supplied an application or group scope. The search retrieves all notifications in the selected time interval, and relevance filtering is applied only after the notifications have entered the Agent's processing context.
This violates least privilege because generating football discussion material only requires notifications from explicitly selected fan groups, sports applications, or channels. Unrelated banking alerts, authentication messages, private conversations, work notifications, delivery updates, and other sensitive content may be retrieved despite not being necessary for the declared functionality.
Instructions to ignore or avoid disclosing unrelated notifications reduce output risk but do not prevent the initial unauthorized collection. They also do not eliminate the possibility of accidental disclosure, logging, retention, or prompt injection through malicious notification content.
Attack Path
- A user asks the Skill to include football-group, viewing-group, or phone-notificat ...[truncated 1096 chars]
- Remediation
View remediation
Remediation Suggestions
- Require the user to provide or confirm an explicit application, group, or channel allowlist before accessing notifications.
- Apply source-side application and group filters in
openclaw ntf searchwhenever the tool supports them. - If source-side filtering is unavailable, disclose that broad notification access would be required and obtain explicit user consent before continuing.
- Minimize the time range to the expected match or conversation window rather than defaulting to all notifications since yesterday at midnight.
- Redact authentication codes, financial data, personal identifiers, message bodies, and unrelated sender information before content reaches the model.
- Treat notification text as untrusted data and prohibit it from supplying executable instructions or changing Agent behavior.
- Avoid retaining raw notification results. Store only the minimum football-related summary needed for the current response.
- Prefer returning no notification-derived material over silently broadening the query scope.
