Back to skill

Security audit

OpenClaw WhatsApp

Security checks for vulnerabilities and agentic risk

Overview

This WhatsApp auto-reply skill is purpose-aligned, but it needs review because it installs unverified remote code, runs persistently, and lets private messages drive a broadly capable agent.

Install only after reviewing and verifying the upstream installer and binary. Use a dedicated least-privileged OpenClaw agent for WhatsApp replies, restrict replies with an allowlist, avoid storing queues and logs in shared `/tmp`, tighten file permissions, and know how to stop and remove the user service before linking a real WhatsApp account.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:30
Finding

Unverified Mutable Remote Installer Is Executed Directly

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
SKILL.md:104
Finding

Unverified External Binary Is Installed as an Automatically Restarting Service

Content
View full analysis
~/.config/systemd/user/openclaw-whatsapp.service << 'EOF' [Unit] Description=OpenClaw WhatsApp Bridge After=network.target [Service] Type=simple ExecStart=/usr/local/bin/openclaw-whatsapp start -c %h/.openclaw-whatsapp/config.yaml Restart=always RestartSec=5 [Install] WantedBy=default.target EOF systemctl --user daemon-reload systemctl --user enable openclaw-whatsapp.service systemctl --user start openclaw-whatsapp.service ``` ### Technical Analysis The setup enables the externally installed `openclaw-whatsapp` binary as a persistent user service and configures systemd to restart it automatically. Long-running persistence is functionally relevant to a messaging bridge, but it substantially amplifies the risk created by installing a binary through an unverified mutable remote installer. The service definition contains no meaningful process sandboxing. It does not set options such as `NoNewPrivileges`, filesystem restrictions, private temporary storage, or system-call restrictions. The service therefore operates with the ordinary privileges and accessible data of the user account. ### Attack Path 1. A malicious or compromised binary is delivered through the remote installation mechanism. 2. The user creates and enables the documented systemd user service. 3. The malicious binary starts immediately and is registered for future user sessions. 4. If the process exits or is terminated, `Restart=always` starts it again. 5. The process retains continuing access to files, session material, messages, and network resources available to the user. ### Impact Assessment The component obtains durable execution in the user context. A compromised binary could repeatedly access or modify the user’s files, WhatsApp session state, message database, configur ...[truncated 253 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/wa-notify-worker.sh:58
Finding

Untrusted WhatsApp Content Is Passed to a Tool-Capable Agent Without an Enforced Trust Boundary

Content
View full analysis
" 3) After sending, stop. Do not call cron.add. Do not spawn background loops. EOF ) # Hard timeout avoids stuck workers. timeout 45s openclaw agent \ --agent main \ --session-id "$sid" \ --message "$prompt" \ --timeout 35 \ --json \ >>"$LOG_FILE" 2>&1 || echo "[$(date -Iseconds)] Agent failed for $jid" >> "$LOG_FILE" ``` ### Technical Analysis The sender-controlled name, JID, current message, and recent conversation history are interpolated directly into the instruction prompt supplied to the `main` OpenClaw agent. Quoting the message in natural language does not create an enforceable instruction/data boundary for a language model. A remote WhatsApp sender can submit content that tells the agent to disregard the enclosing task, disclose available information, invoke other tools, contact additional recipients, or perform unrelated actions. The statements forbidding `cron.add` and background loops are prompt-level requests rather than technical capability restrictions. The design also instructs the agent itself to execute `openclaw-whatsapp send`. The minimum privilege required is only the ability to generate reply text; trusted wrapper code could send the validated result without granting the model command or tool execution authority. ### Attack Path 1. A remote att ...[truncated 1195 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wa-notify.sh:14
Finding

Sensitive Message Queue Uses Predictable Temporary Paths Without Secure Permission or Symlink Controls

Content
View full analysis
/dev/null; then exit 0 fi echo "$MESSAGE_ID" >> "$SEEN_IDS" tail -n 5000 "$SEEN_IDS" > "$SEEN_IDS.tmp" && mv "$SEEN_IDS.tmp" "$SEEN_IDS" fi # Append one JSON event to queue. python3 - "$NAME" "$MSG" "$JID" "$MESSAGE_ID" "$SYSTEM_PROMPT" >> "$QUEUE" <<'PY' import json,sys,time name,msg,jid,message_id,system_prompt = sys.argv[1:] print(json.dumps({ "ts": int(time.time()), "name": name, "message": msg, "jid": jid, "message_id": message_id, "system_prompt": system_prompt, }, ensure_ascii=False)) PY ``` The worker uses the same predictable directory and files: ```bash DATA_DIR="${OC_WA_AGENT_DATA_DIR:-/tmp/openclaw-wa-agent}" QUEUE="$DATA_DIR/queue.jsonl" LOCK="$DATA_DIR/worker.lock" LOG_FILE="$DATA_DIR/worker.log" mkdir -p "$DATA_DIR" touch "$QUEUE" "$LOCK" "$LOG_FILE" ``` ### Technical Analysis WhatsApp contact identifiers, names, message contents, message IDs, system prompts, and agent output are stored under the predictable path `/tmp/openclaw-wa-agent`. The scripts do not establish a restrictive `umask`, explicitly set directory and file permissions, verify ownership, or reject symbolic links. Permissions therefore depend on the invoking environment’s umask and any pre-existing path objects. If another local account can prepare the directory or files before first use, or if the directory is otherwise writable, it may be able to read private messages, repla ...[truncated 1585 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (20)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping curl output directly into bash creates an immediate remote-code-execution chain with no inspection or integrity verification step. In the context of a skill that later installs binaries, scripts, background workers, and persistent services, this is especially dangerous because a compromised installer could establish durable access and process sensitive WhatsApp data.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Step 1: Install the binary

bash
curl -fsSL https://raw.githubusercontent.com/0xs4m1337/openclaw-whatsapp/main/install.sh | bash

Verify installation:

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/wa-notify-worker.sh (reported line 41)May include surrounding context.

sh
[ -z "$jid" ] && return 0

  local history
  history=$(curl -s "http://localhost:8555/chats/${jid}/messages?limit=10" | python3 - <<'PY'
import json,sys
try:
    data=json.loads(sys.stdin.read())

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents extensive shell-based capabilities, including installation, service creation, script copying, and background worker execution, but does not declare any explicit tool scope or permissions boundary. That omission reduces transparency and reviewability, making it easier for users or agent frameworks to invoke powerful local actions without clear consent expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables automatic AI replies to WhatsApp direct messages and processes chat history, contacts, and session data, but the introductory description does not prominently warn users about these privacy-sensitive behaviors. Users may enable it without understanding that inbound messages can be automatically processed by an AI agent and that message history and contacts may be stored or searched.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
78% confidence
Finding

This instruction tells the user to copy an executable script into /usr/local/bin using sudo, which requires elevated privileges and places a locally sourced script into a trusted execution path. If the skill directory or script contents are tampered with, this becomes a privilege-assisted persistence or execution vector.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

SKILL_DIR="$(dirname "$(realpath "$0")")" # or use absolute path to skill

Copy scripts

sudo cp "$SKILL_DIR/scripts/wa-notify.sh" /usr/local/bin/wa-notify.sh sudo cp "$SKILL_DIR/scripts/wa-notify-worker.sh" /usr/local/bin/wa-notify-worker.sh sudo chmod +x /usr/local/bin/wa-notify.sh /usr/local/bin/wa-notify-worker.sh

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
78% confidence
Finding

This line performs another privileged copy of an executable worker script into /usr/local/bin. Because the script is later used for background processing of messages, a compromised or modified script would gain trusted placement and be harder for users to notice.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Copy scripts

sudo cp "$SKILL_DIR/scripts/wa-notify.sh" /usr/local/bin/wa-notify.sh sudo cp "$SKILL_DIR/scripts/wa-notify-worker.sh" /usr/local/bin/wa-notify-worker.sh sudo chmod +x /usr/local/bin/wa-notify.sh /usr/local/bin/wa-notify-worker.sh

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
75% confidence
Finding

Using sudo chmod to make the copied scripts executable completes a privileged installation flow for code sourced from the skill directory. On its own chmod is not dangerous, but in this context it operationalizes code that may not have been independently verified.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

Copy scripts

sudo cp "$SKILL_DIR/scripts/wa-notify.sh" /usr/local/bin/wa-notify.sh sudo cp "$SKILL_DIR/scripts/wa-notify-worker.sh" /usr/local/bin/wa-notify-worker.sh sudo chmod +x /usr/local/bin/wa-notify.sh /usr/local/bin/wa-notify-worker.sh

text

Or if running as agent, use the skill directory path directly:

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The use of nohup to launch a worker script creates background execution detached from the initiating session, which is a persistence-adjacent behavior. In this skill, that worker handles queued message processing, so compromise or misuse could allow hidden long-running processing of private communications.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

Also update the worker script path in /usr/local/bin/wa-notify.sh:

bash
# Find this line near the bottom:
nohup /home/oussama/dev/openclaw-whatsapp/scripts/wa-notify-worker.sh

# Change to:
nohup /usr/local/bin/wa-notify-worker.sh

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

This line shows the replacement nohup command used to keep the worker running independently after invocation. That behavior is legitimate for queue processing, but it still creates a long-lived background component that may continue operating on messages without obvious user visibility.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

nohup /home/oussama/dev/openclaw-whatsapp/scripts/wa-notify-worker.sh

Change to:

nohup /usr/local/bin/wa-notify-worker.sh

text

### Step 5: Create config file

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

nohup /usr/local/bin/wa-notify-worker.sh

text

### Step 5: Create config file

```bash
mkdir -p ~/.openclaw-whatsapp

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The instructions create a user-level systemd service file that causes the WhatsApp bridge to run continuously in the background. In context this is functional persistence rather than overt malware behavior, but it still materially increases risk by maintaining long-lived access to chats, contacts, and session tokens.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

EOF

text

### Step 6: Create systemd service (recommended)

```bash
mkdir -p ~/.config/systemd/user

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

Enabling a user systemd service creates persistence so the bridge restarts automatically and continues processing WhatsApp messages in the background. Persistence is expected for a messaging bridge, but it also increases the impact of compromise because the service can survive reboots and continue accessing message/session data.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

EOF

systemctl --user daemon-reload systemctl --user enable openclaw-whatsapp.service systemctl --user start openclaw-whatsapp.service

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file describes endpoints that retrieve chat histories, synced contacts, and webhook payloads containing names, phone numbers, and message content, but it provides no user-facing warning about the privacy implications of accessing or transmitting that data. Under the markdown-file criteria, documentation should warn when behavior can affect user data or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The worker forwards WhatsApp message content, contact identifiers, and recent chat history into an external agent process, which expands the trust boundary and can expose sensitive user data to an LLM or downstream tooling without any enforcement of consent, minimization, or clear disclosure at this layer. In a messaging bridge with auto-replies, this is security-relevant because private conversations are being programmatically processed and could be logged, retained, or mishandled by the agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code creates a data directory and persistent queue/deduplication files, then stores chat message content and message IDs there. The file contains no confirmation, print/log disclosure, or comment warning users that message data will be retained on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script launches a background worker with nohup, causing additional processing outside the current shell invocation. Although there is an internal comment, there is no user-facing disclosure, prompt, or visible logging to inform users that a detached process will be started.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/wa-notify.sh (reported line 50)May include surrounding context.

sh
# Worker path: configurable via OC_WA_WORKER_PATH, or same directory as this script
WORKER_PATH="${OC_WA_WORKER_PATH:-$(dirname "$(realpath "$0")")/wa-notify-worker.sh}"
[ ! -x "$WORKER_PATH" ] && WORKER_PATH="/usr/local/bin/wa-notify-worker.sh"
nohup "$WORKER_PATH" >/dev/null 2>&1 &

exit 0

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The skill instructs users to fetch and execute an installation script directly from a remote GitHub URL. This bypasses normal package trust controls and exposes users to repository compromise, account takeover, DNS/TLS interception edge cases, or silent upstream script changes.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Step 1: Install the binary

bash
curl -fsSL https://raw.githubusercontent.com/0xs4m1337/openclaw-whatsapp/main/install.sh | bash

Verify installation:

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The API reference lists a POST /logout endpoint that unlinks the WhatsApp device, which is an integrity-affecting action, but the markdown gives no caution about its effect or reversibility. For markdown files, destructive or system-affecting behaviors should be accompanied by a clear warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The script reads OC_WA_SYSTEM_PROMPT from the environment and embeds it into queued event data, but there is no warning or comment explaining that environment-provided prompt content will be captured and forwarded for later processing. This is a form of sensitive configuration handling that lacks explicit disclosure in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.