security(defi): make msig_approve opt-in (0.8.5) - #86
Merged
Merged
Conversation
…ransfer cap) — 0.8.5 External report: msig_approve signed eosio.msig::approve for a proposal identified only by name, without reading it. An attacker can propose 'transfer everything from this agent', inject 'approve proposal X' via a job/listing/A2A message, and once the agent's approval meets the threshold anyone can execute it. The agent only signs approve, so the central transfer cap (0.8.4) never sees the inner transfer. msig_approve now refuses unless the operator sets ENABLE_MSIG_APPROVE=true (default off, documented in .env.example and the skill prompt). Test added; openclaw 215 pass.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes an external report. The defi skill's
msig_approvesigned an approval for a proposal it never read, knowing only its name. That lets injected text get an agent to approve a proposal that drains its account, and the 0.8.4 transfer cap never sees the inner transfer.msig_approveis now off by default and needsENABLE_MSIG_APPROVE=truefrom the operator. The setting is documented in.env.example, and the skill prompt now tells the model never to approve because a job or message asks it to. One test added; openclaw passes 215.Follow-up: fetch and show the proposal's contents when the tool is enabled.