Back to skill

Security audit

Auto Updater Andy27725

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about being an auto-updater, but it creates a persistent daily job that can change Clawdbot and every installed skill without reviewing each update first.

Install only if you deliberately want unattended daily updates for Clawdbot and every installed skill. Prefer a check-only or approval-based workflow, pin or allowlist trusted components where possible, and make sure you know how to remove the cron job before enabling it.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:26
Finding

Persistent Daily Update Task Executes Across Sessions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:48
Finding

Unpinned Automatic Updates Trust Mutable Third-Party Releases

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/agent-guide.md:51
Finding

Critical Update and Migration Failures Are Suppressed

Content
View full analysis
&1 | tee -a "$LOG_FILE" || true fi # Run doctor for migrations log "Running doctor..." clawdbot doctor --yes 2>&1 | tee -a "$LOG_FILE" || true # Capture new version CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown") # Update skills log "Updating skills via ClawdHub..." SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true ``` ### Technical Analysis The helper script begins with `set -e`, but appends `|| true` to critical update and migration commands. This explicitly converts their nonzero exit status into success and permits subsequent stages to continue. A failed source update can therefore be followed by migration and Skill updates. Likewise, a failed migration does not stop Skill installation, and a failed Skill update does not cause the overall script to fail. The script later emits an update summary and logs `"Auto-update complete."`, potentially causing scheduling infrastructure to treat a partially failed update as successful. This behavior increases the chance of mixed component versions, incomplete migrations, and inconsistent runtime state. It may also delay detection because the process exit status no longer reliably represents the update result. ### Attack Path 1. An update, migration, or Skill installation fails because of tampered content, a network interruption, a permission problem, an incompatible release, or a filesystem error. 2. The associated `|| true` suppresses the nonzero exit status. 3. The script continues executing later migration or update stages. 4. Core files, configuration, and Skills may be left at incompatible versions. 5. The script reaches its completion and summary logic rather than terminating with an error. 6. Clawdbot subsequently operates using the partial or inconsistent ...[truncated 657 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Self-Modification

High
Category
Rogue Agent
Confidence
99% confidence
Finding

The skill performs self-modification by running clawdhub update --all, which updates all installed skills automatically and unattended. This is dangerous because it allows code and behavior changes to be introduced into the agent environment on a schedule, increasing the blast radius of any compromised dependency, malicious skill update, or accidental breaking change.

Content

Scanner excerpt · references/agent-guide.md (reported line 61)May include surrounding context.

md
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")

# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description emphasizes convenience but does not prominently warn that enabling the skill will automatically and repeatedly modify installed software. Because it updates both the core bot and all skills on a schedule, users may consent without understanding the persistence, scope, and supply-chain risk of unattended updates.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrase is broad enough that a user could invoke recurring automatic updates with a natural-language request that does not clearly convey the full consequence: scheduled software modification of the bot and all installed skills. In this context, the action creates persistence via cron and changes software state over time, so ambiguous activation increases the risk of unintended enablement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide instructs the agent to configure unattended daily updates that modify the local installation and installed skills without any explicit user confirmation, rollback plan, or trust-policy constraints. Automatically applying package and skill updates expands supply-chain risk and can cause availability or integrity issues if a malicious, compromised, or simply broken update is published.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The guide persists an executable helper script under ~/.clawdbot/scripts/auto-update.sh and pairs it with a cron-based recurring task, creating durable behavior that continues to run after initial setup. Persistent update automation increases the risk of long-lived unintended changes, repeated execution of unsafe commands, and abuse if the script or its update path is later tampered with.

Content

Scanner excerpt · references/agent-guide.md (reported line 21)May include surrounding context.

bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"

text

## Step 2: Create the Update Script (Optional)

For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:

Static analysis

No suspicious patterns detected.