Back to skill

Security audit

OpenClaw Config

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a legitimate OpenClaw configuration helper, but it includes guidance to bypass protected configuration-path controls and ships helper scripts with unsafe backup and restore handling.

Review this skill before installing if it will be used on a real gateway. Do not follow the protected-path workaround unless you intentionally want to make a privileged security change and have a rollback plan. Avoid copying the pipe-to-shell CI installer example, and treat the backup/restore scripts as risky until their temp-file and deletion handling are fixed. Keep secrets in a managed secret provider or tightly permissioned environment file, and do not expose secret file contents in logs or chat transcripts.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/common-errors.md:449
Finding

Unverified Remote Installer Is Executed Directly in CI

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:15
Finding

Instructions Recommend Bypassing Protected Configuration-Path Enforcement

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/restore-config.sh:226
Finding

Predictable Restore Temporary File Permits Symlink-Based File Overwrite

Content
View full analysis
"${temp_file}"; then log_error "Failed to decompress backup file" rm -f "${temp_file}" return 1 fi else if ! cp "${backup_file}" "${temp_file}"; then log_error "Failed to copy backup file" rm -f "${temp_file}" return 1 fi fi # Atomic move if mv "${temp_file}" "${CONFIG_PATH}"; then log_success "Configuration restored successfully" log_info "Restored to: ${CONFIG_PATH}" chmod 600 "${CONFIG_PATH}" return 0 else log_error "Restore failed" rm -f "${temp_file}" return 1 fi ``` ### Technical Analysis The script uses the fixed temporary pathname `.openclaw.json.tmp`. It does not create this file exclusively, verify that it is a regular file, reject symbolic links, or use `mktemp`. For compressed backups, shell redirection opens the predictable path before `gunzip` runs. If an attacker can create entries in the target directory, a pre-created symbolic link can redirect the decompressed configuration data to another file writable by the victim. The uncompressed `cp` path can similarly follow a destination symlink. The subsequent `mv` does not eliminate the initial overwrite because the redirected write has already occurred. ### Attack Path 1. An attacker obtains write access to the target configuration directory. 2. The attacker creates `.openclaw.json.tmp` as a symbolic link to another file tha ...[truncated 890 chars]
Remediation
View remediation
"${temp_file}" || return 1 else cp -- "${backup_file}" "${temp_file}" || return 1 fi chmod 600 -- "${temp_file}" mv -f -- "${temp_file}" "${CONFIG_PATH}" || return 1 trap - RETURN ``` Also validate restored content before replacing the active configuration. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup-config.sh:82
Finding

Backup Cleanup Uses Unsafe Filename Processing and Unvalidated Retention Input

Content
View full analysis
keep_count )); then local delete_count=$((count - keep_count)) log_info "Deleting ${delete_count} old backups" find "${backup_dir}" -name "openclaw-config-*.json*" -type f \ | sort -r \ | tail -n "${delete_count}" \ | xargs rm -f log_success "Cleaned ${delete_count} old backups" else log_info "Backup count does not exceed the limit" fi } ``` The retention option is accepted without validation: ```bash -k|--keep) KEEP_COUNT="$2" shift 2 ;; ``` It is later passed into the cleanup routine: ```bash cleanup_old_backups "${BACKUP_DIR}" "${KEEP_COUNT}" ``` ### Technical Analysis The deletion pipeline represents file paths as newline-delimited text and passes them to `xargs` without NUL separation. Filenames containing spaces, quotes, backslashes, or newlines can be split or reinterpreted as multiple arguments. A filename component beginning with option-like text may also be interpreted unexpectedly by downstream utilities unless option termination is used. In addition, `KEEP_COUNT` is not validated as a non-negative integer before being used in Bash arithmetic and as an argument to `tail -n`. Invalid, negative, or option-like values can cause unexpected retention behavior, errors, or deletion of more backups than intended. The normal backup naming scheme is predictable and generally safe, but the cleanup directory is user-selectable and may already contain attacker-created files matching the search pattern. ### Attack Pa ...[truncated 1107 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose centers on modifying and validating OpenClaw Gateway config content and preventing schema/security issues. The actual script only performs file backup management: resolving the config path, copying the file, optionally compressing it, creating directories, listing backups, and deleting old ones. These are materially different capabilities and involve undeclared filesystem archival/retention behavior rather than config editing or validation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises a skill for editing and validating OpenClaw Gateway config content across many config sections, intended to prevent schema mismatches and diagnose validation errors. The supplied code does something narrower and materially different: it locates the config file, checks whether it exists, prints file metadata, inspects permissions, and optionally invokes openclaw doctor. There is no code to modify config keys, parse JSON/JSON5, inspect specific config areas, or validate schema/content directly. While invoking openclaw doctor is loosely related to diagnosis, the overall implementation does not match the broad edit-and-validate capability claimed in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about configuration editing and schema validation for OpenClaw Gateway settings. The supplied code does not parse, edit, validate, or diagnose openclaw.json/JSON5 contents. Its primary purpose is operational recovery: locating backup files, optionally backing up the current config, restoring a selected backup to the config path, and setting file permissions. While it does operate on the OpenClaw config file, that resource overlap is incidental; the actual behavior is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose promises a broad configuration-editing and validation skill for OpenClaw Gateway, covering many config domains and helping avoid schema mismatches. The supplied code is only a validation/reporting shell script. Its validation is relatively shallow: file existence/readability, standard JSON parseability, file size/permissions, backup presence, and a generic openclaw doctor call if available. It neither edits configuration nor performs comprehensive schema-aware validation across the listed config areas. It also explicitly parses with Python's json module, so JSON5 support is not present. The extra filesystem checks are supporting behavior, but the missing editing, JSON5 handling, and schema/domain coverage make the description materially overstate what the code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about editing and validating OpenClaw Gateway configuration, specifically openclaw.json/JSON5 and many gateway config sections, to prevent schema mismatches and security policy issues. The supplied code instead is a standalone shell script for migration validation of a skill/package-like directory structure. It checks existence of _meta.json, SKILL.md, and .clawhub, validates standard JSON syntax using python3 -m json.tool, checks a few metadata fields in meta.json, inspects file permissions, and searches for backup* directories. It neither edits files nor performs comprehensive gateway config/schema validation, and it does not mention or process openclaw.json or JSON5. This is a materially different primary purpose and resource scope, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill explicitly points users toward a local secrets file path, which normalizes direct file-based secret handling inside an operational skill that also discusses shell access, logs, and config edits. In practice, this can encourage agents or operators to inspect or manipulate credential files directly, increasing the risk of accidental disclosure, exfiltration, or insecure storage patterns. Because this is a configuration-management skill, exposure of auth material has elevated impact across gateway, channels, and provider integrations.

Content

Scanner excerpt · SKILL.md (reported line 416)May include surrounding context.

md
"providers": {
    "lark-secrets": {
      "source": "file",
      "path": "~/.openclaw/credentials/lark.secrets.json"
    }
  }
}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/common-errors.md (reported line 227)May include surrounding context.

port: !int $DB_PORT

方案 2: 使用环境文件

.env

DB_PORT=5432

text

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The documentation recommends curl -fsSL https://get.openclaw.dev | sh, which executes remote content directly in the shell without prior integrity verification. If the hosting endpoint, network path, or distribution channel is compromised, users or CI runners could execute attacker-controlled code immediately.

Content

Scanner excerpt · references/common-errors.md (reported line 462)May include surrounding context.

md
- uses: actions/checkout@v2
      - name: Install OpenClaw
        run: |
          curl -fsSL https://get.openclaw.dev | sh
      - name: Check Required Fields
        run: |
          openclaw doctor --check-required

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The | sh construct is a classic dangerous chaining pattern because it turns fetched network data directly into code execution. In the context of a config/operations skill that may be copied into automation pipelines, this is especially risky because it can compromise developer machines or CI environments with little visibility.

Content

Scanner excerpt · references/common-errors.md (reported line 462)May include surrounding context.

md
- uses: actions/checkout@v2
      - name: Install OpenClaw
        run: |
          curl -fsSL https://get.openclaw.dev | sh
      - name: Check Required Fields
        run: |
          openclaw doctor --check-required

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

The guide instructs users to place a secret directly into ~/.openclaw/.env, which can encourage plaintext secret storage on disk without accompanying guidance on file permissions, secret rotation, or safer secret backends. Although common, this increases the risk of credential exposure through backups, accidental disclosure, or local compromise, especially in a security-sensitive gateway configuration context.

Content

Scanner excerpt · references/complex-operations.md (reported line 434)May include surrounding context.

或直接使用环境变量:

bash
# 在 ~/.openclaw/.env 中添加
export LARK_APP_SECRET="your-app-secret-here"

# 配置中引用

Chaining Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The pipeline ls -t .clawhub/backup_* | tail -n +6 | xargs rm -rf is a dangerous deletion pattern because it relies on parsing ls output and passes results into recursive deletion. Filenames containing spaces, newlines, or unexpected glob expansions can cause accidental deletion of unintended paths, which is especially risky in a config-management skill that handles backups and recovery.

Content

Scanner excerpt · references/version-migration.md (reported line 837)May include surrounding context.

bash
# 保留最近 5 个备份
ls -t .clawhub/backup_* | tail -n +6 | xargs rm -rf

# 自动备份脚本(添加到 crontab)
# 每天凌晨 2 点自动备份

Chaining Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

Using find output piped into xargs rm -f is dangerous because filenames with spaces, newlines, or unusual characters can be misparsed, causing unintended deletions. Since the backup directory is user-controlled, this chaining pattern makes the cleanup step more hazardous and amplifies the destructive nature of the script within an agent skill context.

Content

Scanner excerpt · scripts/backup-config.sh (reported line 98)May include surrounding context.

sh
find "${backup_dir}" -name "openclaw-config-*.json*" -type f \
      | sort -r \
      | tail -n "${delete_count}" \
      | xargs rm -f

    log_success "已清理 ${delete_count} 个旧备份"
  else

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script claims to validate OpenClaw Gateway migration/configuration, but its checks are focused on skill-package artifacts such as _meta.json, SKILL.md, and .clawhub rather than the gateway config files described in the skill manifest (for example openclaw.json/JSON5 and related security-relevant config sections). This creates a dangerous false sense of safety: users may rely on a 'validation passed' result while actual gateway configuration errors or weakened security settings remain undetected, potentially causing insecure startup behavior or policy bypass.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill provides actionable shell and file-read procedures but does not declare any explicit tool scope such as permissions or allowed-tools. That weakens least-privilege controls and makes it easier for an agent runtime to invoke broader capabilities than users expect when following the skill. In a config-management skill that routinely touches validation, logs, backups, and restart operations, undeclared capability use increases the chance of unintended filesystem or command execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill’s headings and operational guidance are written as mandatory Chinese-language instructions, beginning with '一句话' and continuing through the core workflow, without any indication that another language may be used. This creates a locale/language policy issue because it imposes a specific language on users without opt-in or justification for a region-specific scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file describes configWrites as allowing Telegram to write configuration, which can affect user data or system integrity by modifying persistent settings. In the surrounding Telegram section, there is no explicit warning about the implications of enabling this behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The Feishu field index states that configWrites allows Feishu to write configuration, but the document does not warn users that this may alter persistent settings. Because this is a markdown description of behavior affecting system integrity, an explicit warning is expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The Signal example enables configWrites: true, indicating the channel can write configuration, yet the section provides no warning about this potentially changing persistent settings. The omission leaves users uninformed about a behavior that may affect system state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The summary table describes configWrites across several channels as allowing the channel to write configuration, but it gives no warning about the risk of persistent changes. In a reference document, this omission can cause users to enable the option without understanding the impact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

该 Markdown 文档从标题到正文均仅以中文编写,且未说明这是面向特定中文用户群体的区域化文档,也未提供其他语言选项。根据语言/区域政策,若技能或文档强制单一语言而没有用户选择或合理限定,属于自然语言策略违规。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/complex-operations.md (reported line 87)May include surrounding context.

md
"mode": "merge",
    "providers": {
      "yourprovider": {
        "baseUrl": "https://api.yourprovider.com/v1",
        "apiKey": "env:YOURPROVIDER_API_KEY",
        "api": "openai-completions",
        "models": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/complex-operations.md (reported line 525)May include surrounding context.

md
**Slack 配置**

1. **创建 Slack 应用**:
   - 访问 [Slack API](https://api.slack.com/apps)
   - 创建应用并配置 Bot 权限
   - 安装应用到工作区
   - 保存 Bot Token 和 Signing Secret

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide recommends enabling OpenTelemetry traces, metrics, and logs without warning that telemetry backends may transmit operational and potentially sensitive request data off-system. Because this file is instructional and aimed at real configuration changes, operators may enable external observability pipelines without understanding the data exposure implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The diagnostics example explicitly enables cache tracing with message, prompt, and system content included, which can capture sensitive user data, prompts, secrets, and internal context into telemetry or logs. In a configuration guide for a gateway product, presenting this as a standard example without a strong privacy warning or minimization guidance can lead operators to deploy privacy-invasive settings in production.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/complex-operations.md (reported line 1401)May include surrounding context.

  1. 检查文件权限:

    bash
    ls -la ~/.openclaw/openclaw.json
    
  2. 修正权限:

Static analysis

No suspicious patterns detected.