T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:10- Finding
Excessive Privileged Permissions Declared Without Functional Need
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 10
Vulnerability Type: Excessive permission declaration and violation of least privilege
Risk Level: MediumComplete Code Snippet:
yaml metadata: openclaw: permissions: [accessibility, notification, auto-task]Technical Analysis
The skill requests
accessibility,notification, andauto-taskpermissions. However, the reviewed implementation inindex.jsonly processes command-line arguments, generates random values, waits using timers, and writes simulated status messages to standard output.No code was found that uses accessibility services, reads or sends notifications, or creates automatic tasks. The requested permissions therefore exceed the capabilities needed by the current implementation and violate the principle of least privilege.
Accessibility permission is particularly sensitive because, depending on the host platform's permission model, it may allow observation or control of user-interface interactions. Notification access may expose notification content or permit notification actions, while automatic-task access may allow privileged background automation. The exact scope depends on how the OpenClaw host interprets and enforces these permission identifiers.
The current
index.jsdoes not actively exercise or abuse these permissions. The risk arises from granting unnecessary capabilities to the skill package, making future malicious modifications, compromised updates, or host-integrated code substantially more capable than the present functionality requires.Attack Path
- A user installs or enables the skill based on its advertised marketplace automation functionality.
- The host reads the permission declaration from
SKILL.md. - If the host grants the declared permissions, the skill receives accessibility, notification, and automatic-task capabilities despite the current implementation not requiring them ...[truncated 1209 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove all currently unused permissions from the metadata:
yaml metadata: openclaw: permissions: []If the platform permits it, omit the
permissionsfield entirely when no privileged capability is required. -
Add permissions individually only after implementing functionality that demonstrably requires them.
-
Document the exact operation requiring each permission, the data it exposes, and whether access is continuous or limited to an explicit user action.
-
Prefer narrowly scoped platform capabilities over broad accessibility access. Marketplace operations should use an authorized, purpose-specific API where available rather than UI-wide automation privileges.
-
Require explicit user approval when introducing a new permission in a later release, rather than carrying forward unnecessary preauthorization.
-
Add a release-time check that compares declared permissions with actual API usage and rejects unused or undocumented privileged permissions.
-
