T03 · Remote Payload Retrieval and Execution
- Location
references/common-errors.md:449- Finding
Unverified Remote Installer Is Executed Directly in CI
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly a legitimate OpenClaw configuration helper, but it includes guidance to bypass protected configuration-path controls and ships helper scripts with unsafe backup and restore handling.
Review this skill before installing if it will be used on a real gateway. Do not follow the protected-path workaround unless you intentionally want to make a privileged security change and have a rollback plan. Avoid copying the pipe-to-shell CI installer example, and treat the backup/restore scripts as risky until their temp-file and deletion handling are fixed. Keep secrets in a managed secret provider or tightly permissioned environment file, and do not expose secret file contents in logs or chat transcripts.
references/common-errors.md:449Unverified Remote Installer Is Executed Directly in CI
SKILL.md:15Instructions Recommend Bypassing Protected Configuration-Path Enforcement
scripts/restore-config.sh:226Predictable Restore Temporary File Permits Symlink-Based File Overwrite
scripts/backup-config.sh:82Backup Cleanup Uses Unsafe Filename Processing and Unvalidated Retention Input
There is a clear description-behavior mismatch. The declared purpose centers on modifying and validating OpenClaw Gateway config content and preventing schema/security issues. The actual script only performs file backup management: resolving the config path, copying the file, optionally compressing it, creating directories, listing backups, and deleting old ones. These are materially different capabilities and involve undeclared filesystem archival/retention behavior rather than config editing or validation.
The declared description promises a skill for editing and validating OpenClaw Gateway config content across many config sections, intended to prevent schema mismatches and diagnose validation errors. The supplied code does something narrower and materially different: it locates the config file, checks whether it exists, prints file metadata, inspects permissions, and optionally invokes openclaw doctor. There is no code to modify config keys, parse JSON/JSON5, inspect specific config areas, or validate schema/content directly. While invoking openclaw doctor is loosely related to diagnosis, the overall implementation does not match the broad edit-and-validate capability claimed in the description.
The declared description is about configuration editing and schema validation for OpenClaw Gateway settings. The supplied code does not parse, edit, validate, or diagnose openclaw.json/JSON5 contents. Its primary purpose is operational recovery: locating backup files, optionally backing up the current config, restoring a selected backup to the config path, and setting file permissions. While it does operate on the OpenClaw config file, that resource overlap is incidental; the actual behavior is materially different from the declared purpose.
The declared purpose promises a broad configuration-editing and validation skill for OpenClaw Gateway, covering many config domains and helping avoid schema mismatches. The supplied code is only a validation/reporting shell script. Its validation is relatively shallow: file existence/readability, standard JSON parseability, file size/permissions, backup presence, and a generic openclaw doctor call if available. It neither edits configuration nor performs comprehensive schema-aware validation across the listed config areas. It also explicitly parses with Python's json module, so JSON5 support is not present. The extra filesystem checks are supporting behavior, but the missing editing, JSON5 handling, and schema/domain coverage make the description materially overstate what the code actually does.
The declared description is about editing and validating OpenClaw Gateway configuration, specifically openclaw.json/JSON5 and many gateway config sections, to prevent schema mismatches and security policy issues. The supplied code instead is a standalone shell script for migration validation of a skill/package-like directory structure. It checks existence of _meta.json, SKILL.md, and .clawhub, validates standard JSON syntax using python3 -m json.tool, checks a few metadata fields in meta.json, inspects file permissions, and searches for backup* directories. It neither edits files nor performs comprehensive gateway config/schema validation, and it does not mention or process openclaw.json or JSON5. This is a materially different primary purpose and resource scope, so it is a clear mismatch.
The skill explicitly points users toward a local secrets file path, which normalizes direct file-based secret handling inside an operational skill that also discusses shell access, logs, and config edits. In practice, this can encourage agents or operators to inspect or manipulate credential files directly, increasing the risk of accidental disclosure, exfiltration, or insecure storage patterns. Because this is a configuration-management skill, exposure of auth material has elevated impact across gateway, channels, and provider integrations.
"providers": {
"lark-secrets": {
"source": "file",
"path": "~/.openclaw/credentials/lark.secrets.json"
}
}
}
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
port: !int $DB_PORT
DB_PORT=5432
The documentation recommends curl -fsSL https://get.openclaw.dev | sh, which executes remote content directly in the shell without prior integrity verification. If the hosting endpoint, network path, or distribution channel is compromised, users or CI runners could execute attacker-controlled code immediately.
- uses: actions/checkout@v2
- name: Install OpenClaw
run: |
curl -fsSL https://get.openclaw.dev | sh
- name: Check Required Fields
run: |
openclaw doctor --check-required
The | sh construct is a classic dangerous chaining pattern because it turns fetched network data directly into code execution. In the context of a config/operations skill that may be copied into automation pipelines, this is especially risky because it can compromise developer machines or CI environments with little visibility.
- uses: actions/checkout@v2
- name: Install OpenClaw
run: |
curl -fsSL https://get.openclaw.dev | sh
- name: Check Required Fields
run: |
openclaw doctor --check-required
The guide instructs users to place a secret directly into ~/.openclaw/.env, which can encourage plaintext secret storage on disk without accompanying guidance on file permissions, secret rotation, or safer secret backends. Although common, this increases the risk of credential exposure through backups, accidental disclosure, or local compromise, especially in a security-sensitive gateway configuration context.
或直接使用环境变量:
# 在 ~/.openclaw/.env 中添加
export LARK_APP_SECRET="your-app-secret-here"
# 配置中引用
The pipeline ls -t .clawhub/backup_* | tail -n +6 | xargs rm -rf is a dangerous deletion pattern because it relies on parsing ls output and passes results into recursive deletion. Filenames containing spaces, newlines, or unexpected glob expansions can cause accidental deletion of unintended paths, which is especially risky in a config-management skill that handles backups and recovery.
# 保留最近 5 个备份
ls -t .clawhub/backup_* | tail -n +6 | xargs rm -rf
# 自动备份脚本(添加到 crontab)
# 每天凌晨 2 点自动备份
Using find output piped into xargs rm -f is dangerous because filenames with spaces, newlines, or unusual characters can be misparsed, causing unintended deletions. Since the backup directory is user-controlled, this chaining pattern makes the cleanup step more hazardous and amplifies the destructive nature of the script within an agent skill context.
find "${backup_dir}" -name "openclaw-config-*.json*" -type f \
| sort -r \
| tail -n "${delete_count}" \
| xargs rm -f
log_success "已清理 ${delete_count} 个旧备份"
else
The script claims to validate OpenClaw Gateway migration/configuration, but its checks are focused on skill-package artifacts such as _meta.json, SKILL.md, and .clawhub rather than the gateway config files described in the skill manifest (for example openclaw.json/JSON5 and related security-relevant config sections). This creates a dangerous false sense of safety: users may rely on a 'validation passed' result while actual gateway configuration errors or weakened security settings remain undetected, potentially causing insecure startup behavior or policy bypass.
The skill provides actionable shell and file-read procedures but does not declare any explicit tool scope such as permissions or allowed-tools. That weakens least-privilege controls and makes it easier for an agent runtime to invoke broader capabilities than users expect when following the skill. In a config-management skill that routinely touches validation, logs, backups, and restart operations, undeclared capability use increases the chance of unintended filesystem or command execution.
The skill’s headings and operational guidance are written as mandatory Chinese-language instructions, beginning with '一句话' and continuing through the core workflow, without any indication that another language may be used. This creates a locale/language policy issue because it imposes a specific language on users without opt-in or justification for a region-specific scope.
This markdown file describes configWrites as allowing Telegram to write configuration, which can affect user data or system integrity by modifying persistent settings. In the surrounding Telegram section, there is no explicit warning about the implications of enabling this behavior.
The Feishu field index states that configWrites allows Feishu to write configuration, but the document does not warn users that this may alter persistent settings. Because this is a markdown description of behavior affecting system integrity, an explicit warning is expected.
The Signal example enables configWrites: true, indicating the channel can write configuration, yet the section provides no warning about this potentially changing persistent settings. The omission leaves users uninformed about a behavior that may affect system state.
The summary table describes configWrites across several channels as allowing the channel to write configuration, but it gives no warning about the risk of persistent changes. In a reference document, this omission can cause users to enable the option without understanding the impact.
该 Markdown 文档从标题到正文均仅以中文编写,且未说明这是面向特定中文用户群体的区域化文档,也未提供其他语言选项。根据语言/区域政策,若技能或文档强制单一语言而没有用户选择或合理限定,属于自然语言策略违规。
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"mode": "merge",
"providers": {
"yourprovider": {
"baseUrl": "https://api.yourprovider.com/v1",
"apiKey": "env:YOURPROVIDER_API_KEY",
"api": "openai-completions",
"models": [
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
**Slack 配置**
1. **创建 Slack 应用**:
- 访问 [Slack API](https://api.slack.com/apps)
- 创建应用并配置 Bot 权限
- 安装应用到工作区
- 保存 Bot Token 和 Signing Secret
The guide recommends enabling OpenTelemetry traces, metrics, and logs without warning that telemetry backends may transmit operational and potentially sensitive request data off-system. Because this file is instructional and aimed at real configuration changes, operators may enable external observability pipelines without understanding the data exposure implications.
The diagnostics example explicitly enables cache tracing with message, prompt, and system content included, which can capture sensitive user data, prompts, secrets, and internal context into telemetry or logs. In a configuration guide for a gateway product, presenting this as a standard example without a strong privacy warning or minimization guidance can lead operators to deploy privacy-invasive settings in production.
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
检查文件权限:
ls -la ~/.openclaw/openclaw.json
修正权限:
No suspicious patterns detected.