Back to skill

Security audit

session-logs1

Security checks for vulnerabilities and agentic risk

Overview

The skill openly helps search prior session transcripts, but its all-session examples can expose unrelated historical conversations unless the user tightly scopes use.

Install only if you are comfortable letting the agent read and search older OpenClaw session transcripts. Use it with narrow requests such as a specific session, date, or keyword, and avoid broad searches when prior conversations may include secrets, personal information, customer data, or unrelated private work.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:98
Finding

Unrestricted Cross-Session Conversation Log Search

Content
View full analysis
/sessions/*.jsonl ``` ``` Supporting instructions also state that the skill can search the user's “complete conversation history” and identify the session directory containing full conversation transcripts. ### Technical Analysis The skill explicitly instructs the agent to search every JSONL transcript under the agent's session directory. This operation is not limited to the particular historical conversation relevant to the user's request. No instructions require: - Explicit authorization before accessing historical logs. - Restriction to a user-selected session. - Validation that discovered sessions belong to the requesting user or context. - Exclusion of unrelated conversations or tool results. - Redaction of credentials, personal information, or other sensitive content. - Minimization of excerpts returned to the current conversation. Session transcripts can contain user messages, assistant responses, tool calls, tool results, operational metadata, and potentially secrets exposed during earlier tasks. Although the skill does not bypass operating-system permissions, it encourages using the agent's existing filesystem privileges beyond the minimum scope ordinarily necessary to answer a targeted historical-context request. This violates least-privilege and purpose-limitation principles. The provided command only returns matching file names, but it acts as a discovery step. Other commands documented in the same skill can subsequently extract full text from any discovered transcript. ### Attack Path 1. An attacker or untrusted participant asks the agent to recall historical information or search prior conversations for a broad phrase. 2. The request triggers t ...[truncated 1475 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to search complete session logs containing prior conversations, but it provides no guardrails around consent, minimization, or warnings that these logs may contain sensitive user data. This creates a privacy exposure risk because an agent could retrieve and surface historical content beyond the user's current request or expectations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is designed to read and search the agent's complete conversation history across session JSONL files, which can expose user-provided content from older or parent conversations outside the current context window. In context, this makes the issue more dangerous because the skill normalizes broad historical access as a default troubleshooting step rather than a tightly scoped, user-authorized action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.