Back to skill

Security audit

auto-updater-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill presents itself as an official auto-updater but asks users to run unverified privileged installers that create silent startup persistence.

Review this carefully before installing. Only proceed if you can independently verify the publisher, download source, signatures, and hashes, and if you intentionally want a persistent updater that can run silently at startup with elevated privileges. Prefer a manual or user-level updater unless the installer clearly documents exactly what it changes and how to remove every service, cron entry, log, and system dependency change.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:90
Finding

Persistent Auto-Start Daemon and Scheduled Update Mechanism

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 90; related persistence references at lines 26, 48, 127, and 133
Vulnerability Type: System persistence through an auto-start daemon and Linux crontab registration
Risk Level: High

Relevant documentation excerpt translated into English:

text
- After installation, a system daemon is automatically created to check the official update source every 30 minutes.

The document also states that the updater starts at boot and that Linux crontab startup configuration was added.

Technical Analysis

The recommended installation creates a persistent system daemon, while the changelog explicitly identifies Linux crontab as an auto-start mechanism. These mechanisms survive the original Skill run and subsequent user sessions.

Persistent execution is relevant to the declared automatic-update functionality, but it exceeds the minimum privileges and persistence required for manual update checks. The documentation does not make persistence clearly optional, identify the exact service or crontab entries, describe execution identities and permissions, or explain how update checks are isolated from privileged installation operations.

Because the daemon periodically contacts a remote update source and the updater is expected to modify dependencies, compromise of either the updater or its source could turn the legitimate startup mechanism into durable privileged execution.

Attack Path

  1. A user installs the updater and enables or accepts its documented startup behavior.
  2. The installer creates an auto-start daemon or Linux crontab entry.
  3. The persistent process starts automatically across reboots and checks a remote update source every 30 minutes.
  4. An attacker compromises or substitutes the updater, update source, or retrieved package.
  5. The persistent process retrieves or processes the attacker-controlled update.
  6. Malicious changes continue to exec ...[truncated 529 chars]
Remediation
View remediation

Remediation Suggestions

  • Make startup persistence explicitly opt-in rather than part of the default installation.
  • Default to user-initiated checks or a documented, user-level scheduler where automatic checks are required.
  • Run network checks and version comparisons as an unprivileged account.
  • Elevate only for the narrowly scoped file operations that genuinely require system privileges.
  • Document the exact Windows service, macOS launch item, Linux service, and crontab entries created.
  • Use restrictive service permissions and prevent unprivileged users from modifying executables, configuration, or update metadata used by the daemon.
  • Separate update download, signature verification, and privileged installation into distinct stages.
  • Provide commands for inspecting, disabling, and completely removing all persistence entries.
  • Record update origin, verified version, signature status, and installation result in an auditable log.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:38
Finding

Privileged Execution of Unverifiable External Installer Packages

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38-48; related offline installer instructions at lines 63-67
Vulnerability Type: Excessive privilege requirement and insecure software supply chain
Risk Level: High

Relevant documentation excerpt translated into English:

text
- Administrator/root privileges are required because system-level dependencies must be updated.

### Quick installation (recommended)

#### Windows

1. Download the official installer: AutoUpdater-v1.2.0-Win.exe

2. Double-click it and complete installation using the wizard, selecting "Start at boot."

The offline instructions additionally direct users to execute ./install_offline.sh or install_offline.bat.

Technical Analysis

The document asks users to execute externally obtained binaries or scripts with administrator or root privileges. However, the audited project contains only SKILL.md; it provides no installer source code, canonical download URL, publisher certificate identity, cryptographic checksum, public signature key, or reproducible build information.

The generic assertion that root access is required for all installation activity violates least-privilege principles. Checking versions, downloading packages, validating metadata, and monitoring network state do not ordinarily require administrator access. Only narrowly scoped installation changes might require elevation.

As a result, users cannot authenticate the referenced executable and offline installation scripts from the audited project. An attacker who substitutes a same-named package could obtain the full permissions granted by the user. Broad dependency version ranges documented at lines 107-110 also do not establish a reproducible or fully reviewed dependency set.

Attack Path

  1. A user relies on the Skill's claim that the updater is official.
  2. The user obtains AutoUpdater-v1.2.0-Win.exe, the offline ZIP, or an installation script fr ...[truncated 904 chars]
Remediation
View remediation

Remediation Suggestions

  • Publish canonical HTTPS download URLs under a verifiable project-controlled domain.
  • Sign every installer, offline archive, update manifest, and update payload using a documented release key.
  • Provide SHA-256 hashes through an independently authenticated channel and require verification before execution.
  • Identify the expected Windows publisher certificate and provide equivalent verification instructions for macOS and Linux.
  • Include auditable installer source code and reproducible build instructions in the project.
  • Pin dependencies to reviewed versions and use integrity hashes or a signed lock file.
  • Perform downloading, version comparison, and signature verification without elevated privileges.
  • Request elevation only immediately before specific system-level changes and clearly disclose each affected path.
  • Abort installation if signatures, hashes, package identity, version metadata, or destination permissions fail validation.
  • Ensure offline installers apply the same authenticity and integrity checks as online updates.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill promotes silent background updating, automatic startup persistence, and administrator/root execution, but does not provide a clear warning that it installs a persistent privileged process that modifies the system without interactive confirmation. In a skill context, this is dangerous because it normalizes behavior commonly associated with stealthy persistence and privileged software changes, increasing the risk of misuse or deceptive deployment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The security section makes a strong claim that the tool only reads basic system information and performs no sensitive data access or upload, while the dependency list later states that environment variables are read to determine installation paths. Even if this behavior is legitimate, the documentation is inconsistent and understates what system data may be accessed, which can mislead users evaluating the updater's trust and data exposure profile.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
- Windows: 控制面板 > 程序和功能 > 卸载 “OpenClaw Auto-Updater”

- macOS/Linux: 执行 `sudo autoupdater --uninstall`
> (注:文档部分内容可能由 AI 生成)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's natural-language instructions, warnings, installation steps, and usage guidance are all presented in Chinese, while no opt-in or language-selection mechanism is mentioned. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.