Back to skill

Security audit

OpenClaw Safe Upgrade

Security checks for vulnerabilities and agentic risk

Overview

This upgrade skill is not evidently malicious, but it needs review because it can silently run workspace scripts and commit/push the whole workspace during an OpenClaw upgrade.

Install only after reviewing or removing the automatic workspace hook execution and git add/commit/push behavior. Prefer a pinned and verified OpenClaw version, require explicit confirmation before upgrade or rollback, and run only from a clean workspace where the configured git remote and local hook scripts are trusted.

Vulnerability Patterns
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/safe-upgrade.sh:497
Finding

Silent Whole-Workspace Commit and Push to a Configured Remote

Content
View full analysis
/dev/null || true git commit -m "upgrade: OpenClaw $current → $post_ver" 2>/dev/null || true git push 2>/dev/null || true fi ``` ### Technical Analysis After a successful upgrade, the script changes into the configured workspace and executes `git add -A`. This stages every modified, deleted, and untracked file in the repository rather than limiting the operation to files produced by the upgrade. The script then commits the staged content and invokes `git push` using the user's existing Git configuration and credentials. It does not: - Display the staged diff. - Restrict the files included in the commit. - Validate the destination remote. - Request confirmation before transmitting content. - Report failures, because command output and errors are suppressed and each operation ends with `|| true`. This Git behavior is not disclosed in `SKILL.md` and is unnecessary for the core OpenClaw upgrade operation. ### Attack Path 1. The workspace contains sensitive, unrelated, or attacker-induced changes, including potentially untracked files. 2. The workspace is a Git repository with a configured remote, and the user has credentials capable of pushing to it. 3. The user invokes the upgrade script. 4. Once the upgrade succeeds, `git add -A` stages all changes throughout the workspace. 5. The script creates a commit without presenting its contents to the user. 6. `git push` sends the commit to the configured remote using the user's credentials. 7. Because all output is suppressed, the user may not realize that unrelated con ...[truncated 908 chars]
Remediation
View remediation

T04 · Embedded Malicious Code

Error
Location
scripts/safe-upgrade.sh:463
Finding

Execution of Workspace-Controlled Hook Scripts

Content
View full analysis
/dev/null 2>&1; then log " ✅ Services: healthy" else warn " ⚠️ Services: issues (non-fatal)" fi fi ``` ```bash # ── Step 9: Optional golden snapshot ── if [ -n "$WORKSPACE" ] && [ -f "$WORKSPACE/scripts/golden-snapshot.sh" ]; then log "⑨ Taking golden snapshot..." local label="gold-$(date +%Y-%m-%d)" bash "$WORKSPACE/scripts/golden-snapshot.sh" "$label" 2>/dev/null || true log " Snapshot: $label" else log "⑨ Golden snapshot skipped (no snapshot script found)" fi ``` ### Technical Analysis The script automatically executes Python and shell files based solely on their names and presence under the selected workspace. It does not verify: - The canonical workspace path. - File ownership. - File or parent-directory permissions. - Whether a hook is a symbolic link. - Cryptographic integrity or an approved hash. - Whether the user explicitly authorized hook execution. `WORKSPACE` may be populated from `OPENCLAW_WORKSPACE`, the OpenClaw configuration file, or fallback directories. Consequently, anyone able to influence the environment, configuration, workspace path, or hook files can influence the code executed during an upgrade. The `golden-snapshot.sh` hook suppresses standard error and ignores failure with `|| true`, reducing visibility into malicious or unexpected behavior. Although `SKILL.md` mentions these optional hooks, their execution is implicit rather than based on explicit per-run ...[truncated 1361 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/safe-upgrade.sh:397
Finding

Unpinned Global Installation from a Mutable npm Tag

Content
View full analysis
&1 | tee -a "$UPGRADE_LOG"; then fail "npm install failed" do_rollback "npm install failed" UPGRADE_PHASE="complete" exit 1 fi ``` ### Technical Analysis The script globally installs `openclaw@latest`. The `latest` npm distribution tag is mutable and can resolve to different package contents over time, so the effective installed code is not fixed by the reviewed Skill. The script does not enforce: - An approved exact version. - A trusted npm registry URL. - A known package integrity hash. - Package provenance or signature verification. - An allowlist of acceptable releases. - Suppression or isolation of npm lifecycle scripts. It also passes `--no-audit`, disabling npm's dependency vulnerability audit during installation. Global npm installation may write to a system-wide package directory and execute package lifecycle scripts with the authority of the invoking account. Although the script queries `npm view openclaw version`, the returned version is obtained from the same remote package infrastructure and is not independently authenticated against a trusted release manifest. ### Attack Path 1. An attacker compromises the npm publisher account, package, registry resolution, or a transitive dependency used by the selected release. 2. A malicious package version is assigned to the mutable `latest` tag. 3. The user runs the upgrade script. 4. `npm i -g openclaw@latest` downloads the attacker-controlled package or dependency tree. 5. npm executes applicable lifecycle scripts during installation. 6. Malicious code runs with the permissions of the upgrade account and replaces or modifies the ...[truncated 892 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/safe-upgrade.sh:368
Finding

Rollback Deletes the Active Installation Before Validating Its Backup

Content
View full analysis
/dev/null || true cp "$OC_CONFIG" "$BACKUP_CURRENT/openclaw.json" ``` Rollback removes the live installation before validating the archive: ```bash log "Restoring installation ($from_ver)..." rm -rf "$OC_INSTALL" tar -xzf "$BACKUP_CURRENT/openclaw-install.tar.gz" -C /usr/lib/node_modules/ ``` ### Technical Analysis The installation archive is the critical artifact needed to restore the previous OpenClaw version. However, archive creation ends with `|| true`, causing the script to continue even when `tar` fails because of insufficient disk space, permissions, unavailable files, or another I/O error. The script does not subsequently verify that the archive: - Exists and is a regular file. - Is nonempty. - Can be read successfully. - Has a valid gzip and tar structure. - Contains the expected `openclaw` directory and files. - Matches a recorded checksum. During rollback, `rm -rf "$OC_INSTALL"` executes before archive validation or extraction. If the archive is missing, truncated, or corrupt, the currently installed package is deleted and cannot be restored by this workflow. This contradicts the documented claim that the operation automatically restores the exact previous state on any critical failure. ### Attack Path 1. Archive creation fails or produces an invalid archive. Possible causes include insufficient disk space, filesystem errors, permission problems, process interruption, or deliberate tampering with the backup directory. 2. Because archive ...[truncated 1258 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is described as a safe upgrade utility, but the documented behavior extends beyond a simple version update into rollback, restoration of configuration and cron files, execution of optional workspace hooks, and possibly repository operations. This mismatch can mislead users and policy layers about the real capabilities of the skill, causing high-risk side effects such as unintended config changes, code execution from workspace files, or source-control actions under the guise of a routine upgrade.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes shell commands that can perform privileged system changes, including package installation, service restarts, rollback, and execution of local scripts, but the manifest does not declare an explicit tool scope such as allowed-tools or permissions. Without scoped tool restrictions, an agent or orchestrator may permit broader shell usage than intended, increasing the blast radius if the skill is misused or if downstream script content is compromised.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/safe-upgrade.sh (reported line 42)May include surrounding context.

sh
export _UPGRADE_ESCAPED=1
        systemd-run --user --scope --unit="openclaw-upgrade-$$" \
            bash "$0" "$@" >"$LIVE_LOG" 2>&1 &
        disown
        echo "[upgrade] Launched in own scope. This shell will exit now."
        exit 0
    fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/safe-upgrade.sh (reported line 306)May include surrounding context.

sh
export _UPGRADE_ESCAPED=1
        systemd-run --user --scope --unit="openclaw-upgrade-$$" \
            bash "$0" "$@" >"$LIVE_LOG" 2>&1 &
        disown
        echo "[upgrade] Launched in own scope. This shell will exit now."
        exit 0
    fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The rollback routine removes the installed application directory and restores multiple config files from backup, which can overwrite current state. While log messages note progress, they do not clearly disclose that existing installation and configuration data will be deleted or replaced before the actions occur.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/safe-upgrade.sh (reported line 305)May include surrounding context.

sh
if systemctl --user start openclaw-gateway.service 2>/dev/null; then
        log "   Started via systemd"
    else
        nohup openclaw gateway start </dev/null >>/tmp/openclaw-upgrade-gateway.log 2>&1 &
        disown
        log "   Started via nohup (PID: $!)"
    fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/safe-upgrade.sh (reported line 307)May include surrounding context.

sh
if systemctl --user start openclaw-gateway.service 2>/dev/null; then
        log "   Started via systemd"
    else
        nohup openclaw gateway start </dev/null >>/tmp/openclaw-upgrade-gateway.log 2>&1 &
        disown
        log "   Started via nohup (PID: $!)"
    fi

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Although the manifest presents this as an OpenClaw upgrade, the script also restores ACPX customization state and interacts with workspace artifacts. That broader scope can unexpectedly alter adjacent components and makes the skill more dangerous because users invoking an upgrade may not realize external configs/plugins will also be changed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s stated purpose is upgrading OpenClaw, but it also executes unrelated workspace operations such as taking a golden snapshot and performing git add/commit/push. Those side effects can modify or exfiltrate workspace state beyond the requested upgrade, violating least surprise and expanding the blast radius if the workspace contains sensitive or unrelated data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Running the script with no arguments immediately enters the full upgrade path, which includes file deletion, package installation, service restart, rollback actions, and cleanup of backups. Although the header comments describe behavior, there is no interactive confirmation or explicit user-facing warning at the point of execution before these safety-critical operations begin.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.