T05 · Unauthorized Access and Privilege Escalation
- Location
configs/feishu-ming/openclaw.json:59- Finding
Open Group Access Exposes Unsandboxed Agents to Untrusted Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent multi-agent OpenClaw configuration package, but its default templates expose powerful agents to open chat channels with weak scoping and broad logging.
Review before installing. Use this only in trusted Feishu or Discord spaces, restrict group and DM access, avoid @everyone/@here triggers, run the gateway under a low-privilege account, enable sandboxing or per-agent tool limits, protect ~/.openclaw/openclaw.json as a secrets file, and disable or scope archival for sensitive work.
configs/feishu-ming/openclaw.json:59Open Group Access Exposes Unsandboxed Agents to Untrusted Instructions
The setup instructions direct users to place Feishu application credentials directly into a local JSON config file under the user's home directory, but provide no guidance on secret handling, file permissions, rotation, or safer alternatives such as environment variables or a secrets manager. In a multi-agent framework that may run persistently on a server, this increases the chance of credential exposure through backups, repo commits, logs, shared home directories, or overly permissive filesystem access.
The comment text is written in Chinese and labels the configuration as a Ming-dynasty-themed Feishu setup, but the file provides no indication that users may choose another language or locale. Under the stated policy, language or locale constraints should be optional or explicitly justified when they are imposed.
The comment text is written entirely in Chinese, and the bot names in the account configuration are also fixed to Chinese labels. In a general-purpose skill/configuration context, this imposes a specific language presentation without any documented user choice or opt-in, which matches the locale-policy concern for natural-language content.
This JSON file contains natural-language strings in Chinese, including a comment describing the setup and a bot name, with no indication that users may choose another language or that the configuration is intended only for a Chinese-language deployment. That creates a locale/language policy concern under the rule for forced language without opt-in.
司礼监的身份说明多次明确要求使用 message 工具在“当前 Discord 频道”发消息并公开流转,但本文件实际只配置了 feishu 频道、账号和绑定,没有任何 Discord 渠道配置。这不是简单的文档不完整,而是操作媒介被写成了另一套平台,与实际配置直接矛盾。
Several natural-language instructions explicitly require responses in Chinese, such as "回答用中文", but the configuration does not offer users a language choice or opt-in mechanism. This is a language-policy constraint embedded in the skill behavior and applies across multiple agent definitions.
都察院说明中写明 GitHub webhook 触发后会“将审查报告发送到 Discord 频道”,但本配置的 channels 和 bindings 仅覆盖 feishu 账户,没有 Discord 通道。该注释性说明对外宣称的输出位置与实际可用渠道不一致,属于意图与实现的直接冲突。
The chronicle agent is instructed to comprehensively record tasks, discussions, outputs, decisions, and anomalies, creating a broad retention pipeline for potentially sensitive operational and user data. In a multi-agent environment with several unsandboxed roles and public workflow messaging, this increases the chance of over-collection, secondary disclosure, and long-lived storage of secrets, business data, or private conversations beyond what is necessary.
Allowing broad mention patterns like '@everyone' and '@here' can cause the system to react to common mass-mention text without strong scoping to a specific bot identity or trusted sender. In a group chat environment, this increases the risk of accidental triggering, prompt injection through ambient conversation, or abusive invocation by any participant who can send messages in the channel.
The bindings reference agent IDs such as "clo" and "cos" that are not defined in the agent list, creating configuration inconsistency between exposed Feishu accounts and actual internal agent identities. In a multi-agent messaging system this can cause misrouting, failed authorization assumptions, or fallback behavior that may expose conversations to the wrong agent or leave externally reachable accounts unmanaged.
This JSON manifest contains repeated natural-language instructions such as “回答用中文” that require agents to respond in Chinese. The file does not offer users a language choice or explain that the skill is intentionally limited to a Chinese-only regional/compliance context, which is a locale policy violation under the stated rules.
The bindings section maps several Feishu accounts to agent IDs such as "zhongshu", "menxia", "shangshu", "yushitai", and "shiguan", but those agent IDs are not defined under agents.list. This creates broken or ambiguous routing for inbound messages, which can lead to dropped requests, fallback behavior, or misdelivery if the framework resolves unknown IDs unsafely; in a multi-agent orchestration system with some agents running sandbox=off, that is a meaningful security and reliability risk.
The skill hard-codes an imperial Chinese address style ('皇帝/陛下', '臣') without any user opt-in or fallback. This can reduce user agency, create exclusion or discomfort for users who do not want roleplay, and may cause downstream agents to prioritize stylistic compliance over the user's actual preferences.
The file prescribes fixed Chinese phrasing and rigid report templates across workflow outputs, with no language-choice or accessibility alternative. While not a classic security flaw, this is a genuine prompt-quality and policy risk because it can force inappropriate output formats, impair clarity for non-Chinese users, and make the system less responsive to user intent and context.
This JSON manifest contains several natural-language instructions such as “回答用中文” that require the agents to always respond in Chinese. Because the file does not offer user opt-in or a language choice, this violates the stated language/locale policy for natural-language content.
The '庶吉士' agent's identity explicitly says it should only perform information retrieval and must not modify files, but its configuration grants an 'all' sandbox scoped to the agent plus a writable workspace. That creates a privilege mismatch: prompt instructions are not a security boundary, so prompt injection, model error, or task confusion could cause the agent to write, alter, or stage data despite its documented read-only role.
The configuration instructs the logging/record-keeping agent to record 'all important events' and outputs, generate daily summaries, and archive them to the workspace, while other workflow instructions require work to occur publicly in channel. In a multi-agent system handling code, operations, legal, health, and user-provided content, this creates a realistic risk of sensitive prompts, secrets, internal discussions, or personal data being copied into chat logs and persistent archives without minimization or consent.
Lines L050-L053 prescribe fixed address terms such as '皇帝/陛下' for the user and '臣/臣等' for self-reference, and the entire skill is written as a Chinese-only interaction pattern. This imposes a specific language and locale style without opt-in or user choice, which is a natural-language policy violation under the language/locale rule.
The rule '频道公开 — 一切工作流转在频道内可见' creates a default requirement to expose all workflow content publicly, which can cause prompts, credentials, incident details, legal discussions, or other sensitive project data to be shared too broadly. In an agent skill that coordinates coding, security review, deployment, and compliance work, this increases the chance of confidential information leakage across routine operations.
This JSON manifest contains repeated natural-language instructions such as "回答用中文" that require agents to respond in Chinese. Because the configuration does not offer a language choice or explain a region-specific necessity, it violates the locale-policy rule for forced language selection.
The '起居注官' role is instructed to record all important events, discussions, outputs, and anomalies and archive daily summaries to a workspace. In this multi-agent system with open Discord DM/group policies and cross-department task routing, that broad logging scope can capture sensitive user prompts, secrets, internal decisions, or regulated data in natural-language archives, increasing exposure and retention risk.
The statement 'All communication is in English by default' imposes a language preference as a default behavior. Under the policy, language constraints should either be user-selectable or clearly justified as region-specific; here, no opt-in or alternative is provided.
Multiple agent themes prescribe English role instructions and fixed English output labels such as "Board Decision", "CEO Update", and similar formats, while the surrounding file metadata is partly Chinese. This creates a language-policy concern because the configuration appears to enforce a specific language without documenting user opt-in or offering locale choice.
This manifest exposes many user-facing messaging endpoints and bot accounts but provides no visible user notice, consent boundary, or data-handling guidance about what messages may be processed or what actions agents may take. That creates risk of users sharing sensitive data with multiple agents under unclear expectations, especially in an enterprise-style multi-agent setup spanning leadership, legal, HR, and data roles.
The manifest enables both direct messages and group interactions with an "open" policy, which broadens who can activate these agents and increases the chance of unintended disclosure, prompt abuse, or social-engineering-driven misuse. In this file's context, many agents are user-facing and several run without sandboxing, so overly permissive activation scope materially increases exposure.
No suspicious patterns detected.