security(openclaw): enforce the XPR transfer cap centrally (0.8.4) - #85
Merged
Merged
Conversation
…ning layer (0.8.4) External report (skill tools bypass MAX_TRANSFER_AMOUNT): the documented cap was only enforced by core plugin tools. #64 added a per-skill check reading an undocumented MAX_TRANSFER_XPR, and it covered only some handlers: defi_create_otc, loan_supply/repay, xmd_mint and gov_post_proposal signed with no cap (repro: 9,999,999 XPR to an OTC escrow). Every signed transaction now passes assertTransferCap in createCliApi (all skills) and createCliSession (core tools): the total XPR the agent sends via eosio.token::transfer in one transaction is summed and refused above MAX_TRANSFER_AMOUNT (smallest units; default 1,000 XPR). An explicit plugin-config maxTransferAmount is passed through and becomes the process default so skills inherit it; legacy MAX_TRANSFER_XPR is still honored. Skills' early checks now read the documented variable. createCliSession's default RPC moves from greymass to Saltant. 8 new tests (openclaw 214).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes an external report: bundled skill tools could sign XPR transfers without the documented
MAX_TRANSFER_AMOUNTcap.Before: the cap was enforced only by the core plugin tools. The skill check added in #64 read an undocumented variable (
MAX_TRANSFER_XPR) and only covered some handlers.defi_create_otc,loan_supply,loan_repay,xmd_mintandgov_post_proposalhad no cap at all.After:
assertTransferCapruns in both signing paths:createCliApi, which every skill signs throughcreateCliSession, used by the core toolsIt totals every XPR transfer the agent sends in the transaction, so splitting a transfer doesn't get around it, and refuses anything above
MAX_TRANSFER_AMOUNT(default 1,000 XPR).maxTransferAmountset in plugin config is passed through, and skills inherit it.MAX_TRANSFER_XPRsettings still work.createCliSessionmoves from greymass to Saltant.Tests: 8 new, including the reporter's 9,999,999 XPR OTC case, which is now refused before it reaches the signer. openclaw passes 214. Plugin and skills build clean.