跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

Collection and exfiltration (AML.TA0009, AML.TA0010)

OpenClaw collection and exfiltration threats (AML.TA0009, AML.TA0010): T-EXFIL-001, T-EXFIL-002, T-EXFIL-003

Threats in the collection and exfiltration tactic (AML.TA0009, AML.TA0010) of the MITRE ATLAS framework. Each entry lists the ATLAS technique, attack vector, affected components, current mitigations, residual risk, and recommendations.

The trust boundaries and data flows these threats cross are defined in the threat model index, which also holds the risk matrix, the recommendations summary, and the ATLAS technique mapping.

T-EXFIL-001: Data theft via web_fetch

AttributeValue
ATLAS IDAML.T0009 - Collection
DescriptionAttacker exfiltrates data by instructing the agent to send it to an external URL
Attack vectorPrompt injection causing the agent to POST data to an attacker server
Affected componentsweb_fetch tool
Current mitigationsSSRF blocking for internal/private networks (DNS pinning + IP blocking)
Residual riskHigh - arbitrary external URLs remain permitted
RecommendationsURL allowlisting, data-classification awareness

T-EXFIL-002: Unauthorized message sending

AttributeValue
ATLAS IDAML.T0009 - Collection
DescriptionAttacker causes the agent to send messages containing sensitive data
Attack vectorPrompt injection causing the agent to message the attacker
Affected componentsMessage tool, channel integrations
Current mitigationsOutbound messaging gating
Residual riskMedium - gating may be bypassed
RecommendationsExplicit confirmation for new recipients

T-EXFIL-003: Credential harvesting

AttributeValue
ATLAS IDAML.T0009 - Collection
DescriptionMalicious skill harvests credentials from the agent context
Attack vectorSkill code reads environment variables, config files
Affected componentsSkill execution environment
Current mitigationsClawHub credential-pattern scanning (hardcoded secrets, credential env access paired with network sends); no execution sandboxing for skills at runtime
Residual riskCritical - skills run with agent privileges
RecommendationsSkill execution sandboxing, credential isolation