Back to skill

Security audit

AI System Maintenance

Security checks for vulnerabilities and agentic risk

Overview

This skill is for system maintenance, but it can run an unreviewed local repair script automatically from broad troubleshooting requests.

Review this skill before installing. It should only be used in an environment where you trust and control /home/admin/.openclaw/workspace/scripts/system-maintenance.sh, understand what that script changes, and are comfortable with maintenance requests causing it to run. Prefer a version that bundles or verifies the script and asks for confirmation before repairs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Execution of an Unverified Mutable Script Outside the Skill Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-23
Vulnerability Type: Unverified external local script execution
Risk Level: Medium

Complete Code Snippet:

markdown
1. 运行维护脚本:
```bash
/home/admin/.openclaw/workspace/scripts/system-maintenance.sh
text

### Technical Analysis

The skill instructs the agent to execute `/home/admin/.openclaw/workspace/scripts/system-maintenance.sh`, an absolute host-local path outside the audited project. The referenced script is not included in the project, so its commands, integrity controls, required privileges, network behavior, file access, and potentially destructive maintenance actions cannot be reviewed.

Because the effective behavior is delegated to a mutable external file, the behavior observed when the skill is invoked may differ from the behavior originally intended or reviewed. If another user, process, or compromised component can modify or replace that script, it can cause attacker-controlled commands to execute under the identity and permissions of the agent or service invoking the skill. The absolute path also couples the skill to a particular administrator environment and provides no integrity verification before execution.

This finding does not establish that the referenced script is currently malicious. It identifies an insecure trust boundary: the project directs execution of code whose contents and provenance are unavailable for verification.

### Attack Path

1. An attacker first obtains write access to `/home/admin/.openclaw/workspace/scripts/system-maintenance.sh` or to a parent directory that permits replacing the file.
2. The attacker modifies or replaces the maintenance script with commands of their choice.
3. A user requests system maintenance or uses another trigger documented by the skill.
4. The agent follows the skill instructions and executes the external script without validating its ownership, permissions, integrity, or c
...[truncated 1172 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the maintenance script inside the audited skill package so its complete behavior can be reviewed and version-controlled.
  2. Invoke the script through a controlled project-relative path rather than a hardcoded administrator-specific absolute path.
  3. Verify the script's cryptographic hash or signature immediately before execution, using a trusted manifest that cannot be modified by the same account responsible for the script.
  4. Restrict ownership and permissions so the script and its parent directories are writable only by a trusted administrative identity and are not writable by the runtime account.
  5. Run diagnostics with a least-privileged service account. Isolate privileged repair operations and authorize them individually rather than granting the whole script elevated access.
  6. Separate read-only health checks from state-changing repairs. Require explicit user confirmation before destructive, privileged, or service-restarting operations.
  7. Validate the script as a regular file, reject symbolic links, and ensure its resolved path remains within an approved directory before execution.
  8. Document every command, external dependency, file accessed, network endpoint contacted, and privilege required by the maintenance process.
  9. Record integrity-check results and executed actions in protected audit logs while avoiding the storage of secrets or sensitive command output.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to execute a local maintenance script that may repair issues, but it provides no safety boundaries, no dry-run mode, no confirmation requirement, and no disclosure of system-altering behavior. In this context, automatic script execution is dangerous because the script path points to a privileged local workspace and any side effects, destructive actions, or abuse of the script would be triggered by natural-language requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad, generic troubleshooting language that could cause the skill to activate in many routine support conversations. Because activation leads directly to running a maintenance script, unintended invocation can result in unauthorized or unexpected system actions rather than a purely informational response.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language instructions, trigger phrases, and behavior descriptions are presented only in Chinese, which imposes a language choice on users without documenting it as optional or context-specific. Under the policy, forcing a specific language without user opt-in is a language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.