T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:79- Finding
Overbroad Collection of Sensitive Session History
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a clear error-review purpose, but it tells the agent to read detailed session tool history and automatically modify persistent agent guidance and skills without confirmation.
Install only if you are comfortable with a skill that can inspect detailed current-session tool failures and automatically write to user skill files and TOOLS.md. Prefer revising it to show a proposed diff, redact sensitive details, restrict exact target paths, and require explicit approval before any persistent change.
SKILL.md:79Overbroad Collection of Sensitive Session History
SKILL.md:101Unconfirmed Persistent Memory and Skill Modification Enables Durable Instruction Poisoning
The instruction to 'directly execute modifications' without user confirmation is a strong unsafe-action pattern because it permits persistent state changes from a conversational trigger alone. In practice, this can silently rewrite documentation or skills, propagating mistakes or attacker-influenced content into future sessions.
The skill explicitly gathers all current-session tool errors, including prior tool-call arguments and error contents, then persists summaries into TOOLS.md. Tool arguments and error messages often contain secrets, internal paths, tokens, or sensitive operational context; retaining them without minimization or consent creates a data exposure and long-term privacy risk.
The execution flow and report template instruct the agent to surface and store error-derived information but do not require any redaction or sensitivity filtering. Even summarized entries can leak confidential filenames, environment details, credentials embedded in errors, or operational mistakes back to the user and into persistent files.
The skill’s stated purpose is to review session errors, but it authorizes persistent modification of SKILL.md and TOOLS.md based on inferred root causes, without any approval gate. This creates an integrity risk: transient tool failures, model misclassification, or adversarially induced errors could cause durable changes to operational documentation that affect future behavior.
The skill includes filesystem discovery of skills under ~/.openclaw/skills and maintenance of persistent documentation, which exceeds what is necessary for a simple 'error review' capability. Broad discovery plus write behavior expands attack surface and can be abused to alter unrelated skills or environment documentation based on untrusted session content.
The instruction requires the final reply to be presented in Chinese, but the file does not indicate that the user can choose another language or opt in to this locale constraint. This is a natural-language policy issue because it forces a specific language regardless of user preference.
No suspicious patterns detected.