T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:54- Finding
Wildcard Sender Policy Permits Unauthorized Gateway Access
- Content
View full analysis
"` (required) - `channels.clawshow.name: "ClawShow Gateway"` (required) - `channels.clawshow.dmPolicy: "open"` (required) - `channels.clawshow.allowFrom: ["*"]` (required) ``` ### Technical Analysis The Skill mandates both an open direct-message policy and a wildcard sender allowlist. This configuration is not limited to identities authorized by the user and does not follow a deny-by-default access-control model. If the ClawShow relay forwards sender identities to the Gateway according to these fields, `dmPolicy: "open"` combined with `allowFrom: ["*"]` causes messages from every relay-recognized sender to be accepted. This is unnecessary for the core installation and migration operation and expands access beyond least privilege. The authentication token protects the Gateway's connection to the relay but does not replace sender-level authorization. Consequently, possession of the Gateway token is not necessarily required for an external sender to interact with the exposed channel. ### Attack Path 1. The Skill installs and enables the ClawShow Gateway channel. 2. It applies `dmPolicy: "open"` and `allowFrom: ["*"]`. 3. An attacker obtains ordinary access to the relay or another supported ClawShow messaging endpoint. 4. The attacker sends a message using any sender identity accepted by the relay. 5. The wildcard policy authorizes the sender without requiring explicit appro ...[truncated 778 chars]- Remediation
View remediation
