T09 · Insecure Skill Coding Practices
- Location
gateway_monitor.py:146- Finding
Overbroad Process Termination Can Disrupt Unrelated Applications
- Content
View full analysis
Vulnerability Details
File Location:
gateway_monitor.py:146-153
Vulnerability Type: Overbroad process termination
Risk Level: Highpython if system == "Windows": try: subprocess.run(["taskkill", "/F", "/IM", "node.exe"], capture_output=True, timeout=10) except Exception: pass else: # Linux/Mac try: # Kill all OpenClaw-related processes subprocess.run(["pkill", "-f", "openclaw"], capture_output=True, timeout=10) except Exception: passTechnical Analysis
When the health check fails, the watchdog attempts to remove existing Gateway processes before restarting the service. The process selection is not sufficiently scoped:
- On Windows,
taskkill /F /IM node.exeforcibly terminates every process namednode.exe, not only the OpenClaw Gateway. - On Linux and macOS,
pkill -f openclawterminates every process whose command line containsopenclaw, including unrelated OpenClaw components. - The code does not validate a PID, executable path, process owner, listening port, or service identity before termination.
- Exceptions and command output are discarded, preventing operators from identifying unintended termination or partial failures.
Because the watchdog is designed to run persistently, the destructive operation may be repeated whenever the health check continues to fail. A network error, incorrect
GATEWAY_URL, authentication response, transient startup delay, or legitimate non-200 response can therefore trigger termination of unrelated processes.Attack Path
- The watchdog starts and performs an HTTP request against the configured Gateway URL.
- The request fails or returns a status other than HTTP 200.
- The watchdog treats the result as a Gateway outage.
- On Windows, it invokes
taskkill /F /IM node.exe; on Unix-like systems, it invokes `pkill -f opencla ...[truncated 1055 chars]
- On Windows,
- Remediation
View remediation
Remediation Suggestions
- Use the official OpenClaw service-management or scoped restart interface instead of generic process-name termination.
- Record the PID when starting the Gateway and store it in a user-owned PID file.
- Before terminating a recorded PID, verify:
- The process belongs to the expected user.
- Its executable path matches the expected OpenClaw executable.
- Its command-line arguments identify the Gateway component.
- It is associated with the configured Gateway port where applicable.
- On Windows, terminate the validated PID rather than all
node.exeprocesses. - On Linux and macOS, avoid
pkill -f; use a validated PID or a dedicated service unit. - Require multiple consecutive health-check failures before taking destructive action.
- Distinguish transport failure from application health failure and support an explicit health endpoint.
- Log termination targets, command results, and errors instead of silently suppressing them.
- Run the watchdog as a dedicated unprivileged account whose process-control permissions are limited to the Gateway.
