Back to skill

Security audit

SolCal Recovery

Security checks for vulnerabilities and agentic risk

Overview

This OpenClaw recovery skill is mostly purpose-aligned, but it includes high-impact repair actions, unsafe remote installers, plaintext credential backup, and destructive restore/reset behavior without enough safeguards.

Review this skill carefully before installing. It is not clearly malicious, but it can change local OpenClaw state, overwrite or delete sessions, copy a GitHub token into backups, install software from live external sources, and advise disabling the firewall. Only use it after removing the curl-to-shell paths, adding explicit confirmations and rollback steps, protecting or excluding secrets from backups, validating restore sources, and replacing broad reset/firewall guidance with scoped diagnostics.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (7)

T03 · Remote Payload Retrieval and Execution

Error
Location
SolCal-Recovery.sh:163
Finding

Unverified Remote Installer Is Downloaded and Executed

Content
View full analysis
/dev/null; then log_warn "Ollama not installed" log_info "Installing Ollama..." if command -v brew &> /dev/null; then brew install ollama else curl -fsSL https://ollama.ai/install | sh fi fi ``` `ai-repair.sh:11-15`: ```bash if ! command -v ollama &> /dev/null; then echo "Installing Ollama..." curl -fsSL https://ollama.ai/install | sh fi ``` `README.md:39-43`: ```bash 2. **Ollama (optional, for AI repair)** ```bash curl -fsSL https://ollama.ai/install | sh ``` ``` ### Technical Analysis The downloaded response is piped directly into `sh` without first saving it for inspection or verifying a pinned checksum, digital signature, release version, or artifact provenance. Consequently, the effective code executed by the Skill can change after the reviewed package has been published. TLS protects the connection in transit under normal conditions, but it does not protect against an upstream compromise, malicious installer change, compromised distribution infrastructure, or issuance of an unauthorized certificate. The same unsafe command is both executed automatically by two scripts and recommended in the documentation. The AI functionality is optional, and installing it through an immediately executed mutable response is not the minimum privilege or minimum-risk mechanism necessary for diagnostics and recovery. ### Attack Path 1. An attacker compromises or gains control over the remote installer endpoint or its distribution infrastructure. 2. The attacker modifies the response served by `https://ollama.ai/install`. 3. A user invokes `ai-repair.sh` or the Ollama action in `SolCal-Recovery.sh ...[truncated 879 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
README.md:145
Finding

Troubleshooting Instructions Disable the Host Firewall Globally

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
save-sol.sh:35
Finding

GitHub Token Is Copied into an Unencrypted Backup

Content
View full analysis
/dev/null || true echo "✓ GitHub token saved" fi ``` ### Technical Analysis The backup process deliberately copies a live GitHub token into a regular timestamped directory. The destination is not encrypted, and neither the backup directory nor the copied file is assigned explicit restrictive permissions. Their resulting accessibility depends on the user's current `umask`. The README also encourages keeping the backup directory elsewhere, which can cause the plaintext token to enter cloud synchronization, removable media, archives, or shared backup systems. Authentication secrets do not need to be duplicated to satisfy ordinary workspace and session backup functionality. The use of `|| true` suppresses copy failures, preventing reliable security and completeness reporting. ### Attack Path 1. A user runs `save-sol.sh`. 2. The GitHub token is copied into `~/SolCal-Backups//secrets/`. 3. The directory is read by another local account under permissive permissions, synchronized to an insufficiently protected service, or included in a shared archive. 4. An attacker obtains the token. 5. The attacker authenticates to GitHub using the token and exercises every permission granted to it until it expires or is revoked. ### Impact Assessment The attacker can obtain the GitHub privileges represented by the token. Depending on its scope, this may include reading private repositories, modifying repository content, accessing organization resources, or interacting with workflows and releases. The exact impact is bounded by the token's scopes, repository restr ...[truncated 49 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
emergency-repair.sh:22
Finding

Emergency Repair Installs an Unpinned Global npm Package

Content
View full analysis
/dev/null; then echo "Installing OpenClaw..." brew install openclaw 2>/dev/null || npm install -g openclaw fi ``` ### Technical Analysis If Homebrew installation fails, the script silently falls back to `npm install -g openclaw`. The package is not pinned to a reviewed version and no lockfile, expected integrity digest, provenance attestation, or signature is supplied. npm packages may execute lifecycle scripts during installation. A compromised package account, malicious release, registry compromise, or unexpected upstream version could therefore execute code during a recovery operation. Global installation also has broader scope than a project-local dependency and can replace or introduce commands available outside this Skill. The fallback changes both the source and installation mechanism without obtaining user confirmation. ### Attack Path 1. OpenClaw is absent. 2. The Homebrew installation command fails or is unavailable. 3. The script invokes `npm install -g openclaw`. 4. npm resolves the current registry package version rather than an audited pinned artifact. 5. A compromised or malicious package version is downloaded. 6. Package lifecycle code executes under the privileges of the npm invocation. 7. The globally installed executable remains available to the user and may affect later OpenClaw commands. ### Impact Assessment A malicious dependency can execute arbitrary code with the invoking user's privileges and access user-readable OpenClaw data, credentials, workspace files, and sessions. The global install can also affect commands outside the current recovery run. If npm is configured or invoked with administrative privileges, the affected scope may extend to ...[truncated 36 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
restore-sol.sh:7
Finding

Restore Deletes Existing Sessions Before Validating Backup Content

Content
View full analysis
/dev/null | head -1)}" if [ -z "$BACKUP_DIR" ] || [ ! -d "$BACKUP_DIR" ]; then echo "❌ No backup found!" echo "Usage: bash restore-sol.sh ~/SolCal-Backups/20260403_120000" exit 1 fi echo "📂 Restoring from: $BACKUP_DIR" # Stop gateway first openclaw gateway stop 2>/dev/null # Restore config if [ -f "$BACKUP_DIR/openclaw.json" ]; then cp "$BACKUP_DIR/openclaw.json" ~/.openclaw/openclaw.json echo "✓ Config restored" fi # Restore sessions if [ -d "$BACKUP_DIR/sessions" ]; then rm -rf ~/.openclaw/agents/main/sessions 2>/dev/null cp -r "$BACKUP_DIR/sessions" ~/.openclaw/agents/main/ echo "✓ Sessions restored" fi ``` ### Technical Analysis The script accepts any user-supplied directory as a backup and validates only whether the directory and expected paths exist. It does not verify backup provenance, ownership, permissions, a manifest, content schema, hashes, or configuration safety. When a `sessions` directory exists, current sessions are recursively deleted before the replacement copy is proven valid. The copy operation is not checked before a success message is printed. The configuration is likewise overwritten directly rather than staged and atomically replaced. This creates both an availability risk and a local state-poisoning path. A malicious or incomplete directory can replace trusted configuration and session state. ### Attack Path 1. An attacker creates or supplies a directory containing a crafted `openclaw.json` and/or `sessions` tree. 2. The user is induced to run `restore-sol.sh `. 3. The script stops the gateway. 4. The crafted configuration overwrites the existing OpenClaw configuration. 5. Existing sessions are recursively deleted. 6. Attacker ...[truncated 687 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
emergency-repair.sh:11
Finding

Emergency Repair Uses Overbroad Process Termination and Deletes Diagnostic Logs

Content
View full analysis
/dev/null pkill -f openclaw 2>/dev/null sleep 1 # 2. Clear logs echo "[2/6] Clearing logs..." rm -f /tmp/openclaw/*.log 2>/dev/null ``` ### Technical Analysis `pkill -f openclaw` matches the full command line rather than a verified gateway PID. It may terminate unrelated processes whose arguments or executable paths contain the string `openclaw`. The script also deletes every matching log under `/tmp/openclaw` without confirmation, archival, ownership validation, or a demonstrated need to remove logs before restart. This removes diagnostic and potentially forensic evidence precisely when troubleshooting is underway. Although the deletion pattern is constrained to `*.log`, the action remains destructive and does not follow least-impact recovery practices. ### Attack Path 1. A user invokes emergency repair. 2. The normal gateway stop command runs. 3. `pkill -f openclaw` terminates every process with a matching full command line, including potentially unrelated user processes. 4. All matching log files under `/tmp/openclaw` are deleted. 5. Active work may be interrupted, and evidence needed to diagnose the original failure is lost. ### Impact Assessment The direct impact is denial of service against matching processes and deletion of OpenClaw temporary logs available to the invoking account. This can interrupt unrelated work and hinder troubleshooting or incident investigation. The code does not itself provide persistent access or elevated privileges. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
save-sol.sh:7
Finding

Quoted Tilde Paths Cause Critical Backup Data to Be Silently Omitted

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (43)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The README recommends piping a remote script directly into sh, which executes code fetched over the network without prior review or integrity verification. If the remote source, DNS, TLS path, or hosting is compromised, users can execute arbitrary code immediately on their system.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

  1. Ollama (optional, for AI repair)
    bash
    curl -fsSL https://ollama.ai/install | sh
    

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The use of '| sh' creates a direct execution chain from remote content to shell, removing opportunities for inspection, sandboxing, or integrity validation. In a skill with shell execution capability and a beginner-friendly framing, this increases the chance of arbitrary code execution through supply-chain compromise or user trust abuse.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

  1. Ollama (optional, for AI repair)
    bash
    curl -fsSL https://ollama.ai/install | sh
    

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the skill claims backup/restore and recovery but actually performs service management and status checks, users may invoke it under false assumptions about safety and effect. This mismatch is less severe than overt destructive behavior, but it still undermines informed consent and can trigger unintended operational changes on a live system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the skill claims backup/restore and recovery but actually performs service management and status checks, users may invoke it under false assumptions about safety and effect. This mismatch is less severe than overt destructive behavior, but it still undermines informed consent and can trigger unintended operational changes on a live system.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly includes restore and emergency reset capabilities, yet the description lacks prominent warnings about data-affecting or destructive consequences. In a recovery tool, missing safety warnings can cause users or downstream agents to invoke high-impact actions without understanding rollback limits, overwrite behavior, or possible data loss.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script performs outbound network access and remote software installation even though the skill manifest only declares shell and file permissions, creating a capability mismatch and hidden dependency on external resources. In this context, a recovery tool with broad shell execution is more dangerous because it can fetch and execute untrusted code paths during remediation, which expands impact beyond diagnostics into supply-chain compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The AI-assisted recovery path installs Ollama by executing a remotely fetched shell script, which is a classic supply-chain and arbitrary code execution risk. This is disproportionate to the stated role of a repair assistant because a troubleshooting helper should not silently bootstrap new software from the internet, especially through curl-to-shell.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script installs software via Homebrew or a remote curl-to-shell pipeline without an explicit warning or confirmation, exposing users to unintended software changes and, in the curl case, direct execution of unreviewed remote code. Given the skill's recovery framing, this behavior is especially risky because users may trust it during a stressful troubleshooting scenario.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
100% confidence
Finding

Fetching and executing an external script in one step delegates full code execution to a remote server at runtime, with no integrity verification or opportunity for review. In a repair skill with shell.exec permission, this creates a severe supply-chain risk and can fully compromise the host if the upstream content is malicious or tampered with.

Content

Scanner excerpt · SolCal-Recovery.sh (reported line 170)May include surrounding context.

sh
if command -v brew &> /dev/null; then
            brew install ollama
        else
            curl -fsSL https://ollama.ai/install | sh
        fi
    fi

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The use of a pipe into sh is a command-chaining pattern that removes inspection boundaries and immediately executes network-supplied content in the shell. This is especially dangerous here because the script is positioned as a benign recovery utility, making users less likely to scrutinize a high-risk execution path.

Content

Scanner excerpt · SolCal-Recovery.sh (reported line 170)May include surrounding context.

sh
if command -v brew &> /dev/null; then
            brew install ollama
        else
            curl -fsSL https://ollama.ai/install | sh
        fi
    fi

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs software installation and model retrieval over the network, which is materially more powerful than diagnostics or guided recovery alone. In a repair toolkit context, that mismatch is dangerous because users may run it expecting local troubleshooting, not remote code and artifact acquisition.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching and executing an external installer script at runtime is a classic supply-chain risk. In the context of a shell-capable repair tool, compromise of the fetched script would allow arbitrary code execution and persistent system modification.

Content

Scanner excerpt · ai-repair.sh (reported line 14)May include surrounding context.

sh
# Check Ollama
if ! command -v ollama &> /dev/null; then
    echo "Installing Ollama..."
    curl -fsSL https://ollama.ai/install | sh
fi

# Pull model if needed

Scope Creep

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code uses undeclared network access to fetch an installer and model, exceeding the stated permissions of shell.exec, file.read, and file.write. That hidden capability undermines trust boundaries and can expose the host to unreviewed external content and supply-chain compromise.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The shell pipeline into sh enables direct execution of whatever bytes are returned by the remote server, combining network retrieval and command execution into a single unsafe chain. This removes opportunities for validation and makes exploitation trivial if the source or connection is tampered with.

Content

Scanner excerpt · ai-repair.sh (reported line 14)May include surrounding context.

sh
# Check Ollama
if ! command -v ollama &> /dev/null; then
    echo "Installing Ollama..."
    curl -fsSL https://ollama.ai/install | sh
fi

# Pull model if needed

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · emergency-repair.sh (reported line 19)May include surrounding context.

sh
# 2. Clear logs
echo "[2/6] Clearing logs..."
rm -f /tmp/openclaw/*.log 2>/dev/null

# 3. Reinstall if needed
echo "[3/6] Checking OpenClaw..."

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · restore-sol.sh (reported line 28)May include surrounding context.

sh
# Restore sessions
if [ -d "$BACKUP_DIR/sessions" ]; then
    rm -rf ~/.openclaw/agents/main/sessions 2>/dev/null
    cp -r "$BACKUP_DIR/sessions" ~/.openclaw/agents/main/
    echo "✓ Sessions restored"
fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · restore-sol.sh (reported line 28)May include surrounding context.

sh
# Restore sessions
if [ -d "$BACKUP_DIR/sessions" ]; then
    rm -rf ~/.openclaw/agents/main/sessions 2>/dev/null
    cp -r "$BACKUP_DIR/sessions" ~/.openclaw/agents/main/
    echo "✓ Sessions restored"
fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · restore-sol.sh (reported line 28)May include surrounding context.

sh
# Restore sessions
if [ -d "$BACKUP_DIR/sessions" ]; then
    rm -rf ~/.openclaw/agents/main/sessions 2>/dev/null
    cp -r "$BACKUP_DIR/sessions" ~/.openclaw/agents/main/
    echo "✓ Sessions restored"
fi

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Copying a GitHub access token is a sensitive operation because possession of the backup may grant the same repository or API access as the original secret. The skill's stated recovery purpose does not clearly justify silently collecting and persisting a live credential, making this dangerous if backups are readable by other users, synced externally, or exfiltrated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly states backups include a GitHub token but provides no warning about sensitive credential handling, storage protection, or scope minimization. In a recovery toolkit with file read/write permissions, encouraging token backup without safeguards increases the risk of credential theft from backup folders, accidental sharing, or insecure restores.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The emergency repair section describes a 'nuclear option' that resets components and reinstalls software without clearly warning users about destructive or service-impacting effects. This can lead users to run high-impact repair actions casually, causing data loss, configuration loss, downtime, or unintended system changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The troubleshooting instructions tell users to disable the firewall with sudo but do not explain the security implications or safer alternatives. Disabling host firewall protections can expose services and ports during troubleshooting, especially in a tool intended for beginners.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 147)May include surrounding context.

Network Blocked

bash
# Check network
curl https://api.minimax.io

# Check firewall
sudo pfctl -d  # Temporarily disable

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
92% confidence
Finding

The README instructs users to run a sudo command that disables the firewall, combining privilege escalation with a security-reducing system modification. In a repair toolkit for novice users, this is particularly dangerous because it normalizes privileged execution without discussing risks, rollback, or narrower alternatives.

Content

Scanner excerpt · README.md (reported line 150)May include surrounding context.

curl https://api.minimax.io

Check firewall

sudo pfctl -d # Temporarily disable

text

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Broad trigger conditions such as general breakage, errors, or maintenance increase the likelihood that the skill is invoked in inappropriate contexts without careful review. Because this skill advertises reset, restore, and repair functions and has shell/file permissions, accidental invocation could lead to disruptive or destructive actions on systems that only needed diagnosis.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.