Back to skill

Security audit

Alvis Security Auditor

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only OpenClaw security audit helper, but it includes broad host-enumeration checks that can expose unrelated system details.

Install only if you want a security-audit skill that may inspect host-level metadata. Run it as an unprivileged user, review commands before execution, keep secret contents redacted, and treat broad host checks such as all-port, SUID, and cron enumeration as opt-in unless you explicitly want a wider host audit.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:43
Finding

Overbroad System-Wide Reconnaissance Beyond OpenClaw-Specific Scope

Content
View full analysis
/dev/null | head -n 50` 3. Report only **paths**, never contents. ### 8) File Permissions & Privilege Escalation Risks 1. Check for risky permissions on key dirs: - `ls -ld ~/.openclaw` - `ls -l ~/.openclaw | head -n 50` 2. Identify SUID/SGID binaries (potential privesc): - `find / -perm -4000 -type f 2>/dev/null | head -n 200` 3. Flag if OpenClaw runs as root or with unnecessary sudo. ### 9) Process & Persistence Indicators 1. Check for unexpected cron jobs: - `crontab -l` - `ls -la /etc/cron.* 2>/dev/null` 2. Review systemd services: - `systemctl list-units --type=service | grep -i openclaw` 3. Flag unknown services related to OpenClaw or skills. ...[truncated 3327 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (6)

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
entify world‑readable or group‑readable secret files:
   - `find ~/.openclaw -type f -perm -o+r -maxdepth 4 2>/dev/null | head -n 50`
3. Report only **paths**, never contents.

### 8) File Permissions & Privilege Escalation Risks
1. Check for risky permissions on key dirs:
   - `ls -ld ~/.openclaw`
   - `ls -l ~/.openclaw | head -n 50`
2. Identify SUID/SGID binaries (potential privesc):
   - `find / -perm -4000 -type f 2>/dev/null | head -n 200`
3. Flag if OpenClaw runs as root or with unnecessary sudo.

### 9) Process & Persistence Indicators
1. Check for unexpected cron jobs:
   - `crontab -l`
   - `ls -la /etc/cron.* 2>/dev/null`
2. Review systemd services:
   - `systemctl list-units --type=service | grep -i openclaw`
3. Flag unknown services related to OpenClaw or skills.

### 10) Logs & Audit Trails
1. Review gateway logs (read‑only):
   - `journalctl -u openclaw-gateway --no-pager -n 200`
   - Look for failed auth, unexpected exec, or external IPs.

## Common Findings & Fix

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
- **Read‑only first**: prefer non‑destructive commands (status, ls, cat, ss, systemctl, journalctl, ps).
- **No exfiltration**: never send secrets off the host. If you detect secrets, **redact** them in your report.
- **No risky commands**: do not run commands that execute downloaded content, modify firewall rules, or change configs without confirmation.
- **Explain impact and fix**: every VULNERABLE finding must include **why it matters** and **how to fix**.

## Required Output Format

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
- Is `exec` enabled? Is approval required?
   - Are dangerous tools enabled (shell, browser, file I/O) without prompts?
2. Flag if:
   - `exec` runs without approvals in main session.
   - Tools can run on gateway/host with high privileges.

### 6) Skills & Supply‑Chain Risk Review

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
### 8) File Permissions & Privilege Escalation Risks
1. Check for risky permissions on key dirs:
   - `ls -ld ~/.openclaw`
   - `ls -l ~/.openclaw | head -n 50`
2. Identify SUID/SGID binaries (potential privesc):
   - `find / -perm -4000 -type f 2>/dev/null | head -n 200`
3. Flag if OpenClaw runs as root or with unnecessary sudo.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
### 9) Process & Persistence Indicators
1. Check for unexpected cron jobs:
   - `crontab -l`
   - `ls -la /etc/cron.* 2>/dev/null`
2. Review systemd services:
   - `systemctl list-units --type=service | grep -i openclaw`

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
- **Publicly exposed gateway/UI** �?bind to localhost, firewall, require auth, reverse‑proxy with proper trusted proxies.
- **Old vulnerable versions** �?upgrade to latest release, rotate tokens, invalidate sessions.
- **Unsafe exec policy** �?require approvals, limit tools to sandbox, drop root privileges.
- **Plaintext secrets** �?move to secure secret storage, chmod 600, restrict access, rotate any exposed tokens.
- **Untrusted skills** �?remove, audit contents, only install from trusted authors.

## Report Completion

Static analysis

No suspicious patterns detected.