Back to skill

Security audit

Gateway Upgrade Local Fork

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local OpenClaw upgrade helper, but it asks users to run high-impact local service, database, and package-management commands with several under-scoped safety risks.

Review the commands before running them. Use this only on the intended OpenClaw host, make verified backups first, pin qmd/OpenClaw versions where possible, avoid sharing generated reports without redacting environment values, and replace broad cleanup or /tmp paths with private, reviewed locations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
references/03-upgrade.md:88
Finding

Mutable npm dependency is downloaded and executed without version or integrity pinning

Content
View full analysis
``` ### Technical Analysis The upgrade procedure installs the mutable `@latest` release of a package from the configured npm registry. The effective dependency content can therefore change after the Skill has been reviewed. An npm installation may execute package lifecycle scripts, while `npm rebuild better-sqlite3` runs build tooling and native compilation steps with the permissions of the invoking user. Network access is reasonably necessary to retrieve an upgrade, and the audited files do not explicitly upload service environment values, credentials, or agent data. However, using a mutable version without integrity verification unnecessarily expands supply-chain trust and prevents reproducible review. Although this behavior resembles remote payload retrieval, the best matching classification is insecure dependency handling because the remote code is introduced through the standard npm dependency channel. ### Attack Path 1. An attacker compromises the npm package, one of its transitive dependencies, its publisher account, or the configured registry. 2. A malicious version becomes the package release selected by the `latest` tag. 3. The operator follows the Skill's upgrade procedure. 4. `npm install -g @tobilu/qmd@latest` retrieves the changed package and dependencies. 5. npm lifecycle scripts or subsequently invoked package code execute under the operator's user account. 6. The mali ...[truncated 563 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/diff-env.sh:31
Finding

Service-unit comparison exposes environment values and potentially unrelated secrets

Content
View full analysis
&1 | head -10 echo "" echo "=== ~/.profile CUDA/QMD env ===" grep -iE "cuda|ld_lib|qmd|hf|hfendpoint" ~/.profile 2>&1 | head -10 echo "" echo "=== Current service unit env ===" grep "^Environment=" ~/.config/systemd/user/openclaw-gateway.service ``` ### Technical Analysis The complete diff displays every changed line in both service units. Systemd service files frequently contain API keys, access tokens, provider credentials, proxy credentials, or internal endpoint information in `Environment=` directives. The preflight command goes further by printing every service environment assignment and selected lines from shell initialization files. Only five GPU/QMD-related variable names are needed for the declared upgrade functionality. Printing unrelated environment directives and plaintext values ex ...[truncated 1280 chars]
Remediation
View remediation
` before comparison. 4. Do not search or print arbitrary lines from `.bashrc` or `.profile`; query only specifically named variables. 5. Add warnings that diagnostic output must not be pasted into tickets or external sessions without review. 6. If a detailed report is required, write it to a user-private file created under `umask 077`. 7. Ensure generated upgrade reports also omit or redact endpoint values and filesystem details that are not necessary for validation. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/qmd-rebuild-serial.sh:12
Finding

Predictable shared temporary paths permit symlink attacks and forged rebuild state

Content
View full analysis
$LOG echo "[$(date +%H:%M:%S)] Note: serial execution, 30-50s/agent" >> $LOG ``` Completion state is written to a predictable path: ```bash touch "$DONE_DIR/$a" ``` From `scripts/backup-env.sh`: ```bash NPM_LIST=/tmp/npm-global-pre-upgrade-${BACKUP_TS}.txt npm list -g --depth=0 > "$NPM_LIST" 2>&1 echo "✓ npm global list: $NPM_LIST" echo "" QMD_DOC=/tmp/qmd-doctor-pre-upgrade-${BACKUP_TS}.txt qmd doctor > "$QMD_DOC" 2>&1 echo "✓ qmd doctor baseline: $QMD_DOC" ``` ### Technical Analysis The scripts use globally predictable names under `/tmp` without securely creating files, validating ownership, rejecting symbolic links, or establishing restrictive permissions. Timestamp-based names reduce accidental collisions but remain predictable. The fixed log path and fixed completion directory are particularly easy to pre-create. On systems where another local user can manipulate `/tmp`, shell redirection and `touch` may follow symbolic links. Separately, pre-created completion markers can make the rebuild script treat agents as already processed, undermining verification and index integrity. Exploitation requires local access and favorable filesystem permissions. It does not provide an independent remote attack vector. ### Attack Path **Symlink overwrite path:** 1. A local attacker predicts `/tmp/qmd-serial-reindex.log` or a timestamped output name. 2. The attacker creates a symbolic link from that path ...[truncated 928 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/06-rollback.md:84
Finding

Rollback cleanup recursively deletes broadly matched paths across the entire home directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

There is a clear description-behavior mismatch. The description presents a comprehensive upgrade skill covering backup, upgrade, env merge, verification, GPU doctor checks, and qmd index rebuilds. The actual code chunk is only diff-env.sh, a diagnostic helper that reads the current and backup systemd unit files, diffs them, checks for a handful of Environment lines, prints Description/ExecStart/version information, and emits suggestions if env vars are missing. It does not modify the service, merge env vars, perform the upgrade, run qmd doctor, rebuild indexes, or manipulate any database. While the code is consistent with one small sub-task mentioned in the description (detecting lost custom environment variables), it materially falls short of the declared primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad local fork-upgrade skill covering the entire backup → upgrade → env-merge → verify lifecycle, specifically preserving custom environment variables during systemd service upgrades and running diagnostic checks. The actual code chunk only performs one subtask: serial per-agent qmd reindexing based on local SQLite state, with logging and done markers in /tmp. This is related to one sentence in the description about serial index rebuilding, but it omits the main advertised upgrade, env-merge, and verification behavior. There is no evidence of data exfiltration or non-local operations, so the mismatch is about scope and primary purpose rather than hidden extra capabilities.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/06-rollback.md (reported line 24)May include surrounding context.

md
systemctl --user stop openclaw-gateway.service

# 2. 恢复旧 binary
rm -rf $HOME/openclaw-local
mv $HOME/openclaw-local.bak.<timestamp> $HOME/openclaw-local

# 3. 恢复 service unit

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly targets local service upgrades, backups, rollback points, and per-agent database handling, which are potentially destructive or service-impacting actions. Without an explicit warning and confirmation requirement, an operator could run the skill in the wrong environment or underestimate downtime/data integrity risks, leading to accidental service disruption or loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The preflight steps instruct the user to grep shell profiles and dump systemd Environment entries that may contain sensitive values such as tokens, mirror endpoints, or custom credentials, and to save diagnostic outputs into /tmp and backup files without any warning about secret exposure or file permissions. In this local-upgrade context the behavior is operationally motivated rather than overtly malicious, but it still increases the risk of leaking secrets through terminal history, world-readable temp files, screenshots, or copied reports.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/02-backup.md (reported line 56)May include surrounding context.

bash
# 跑完检查 .bak 大小是不是合理
ls -la ~/.config/systemd/user/openclaw-gateway.service.bak.<ts>
du -sh $HOME/openclaw-local.bak.<ts>  # 如果有
# per agent dbs 数量应该是 33+1(main + 32 个其他),少一个就说明漏备份
ls ~/.openclaw/agents/*/qmd/xdg-cache/qmd/*.bak.<ts> | wc -l

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section instructs direct in-place modification of a live systemd user service file using sed and then later relies on a service restart to apply changes, but it does not include an explicit execution-time warning, validation step before write, or rollback guard at the point of change. In a local service-upgrade skill, these commands can unintentionally corrupt the unit file, drop required environment variables, or leave the gateway unavailable if anchors do not match or edits are applied to the wrong file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script explicitly reads and prints the values of environment variables from the systemd service file, including HF_ENDPOINT and potentially sensitive local configuration. While these specific variables are not always secrets, environment variables commonly carry tokens, internal endpoints, filesystem paths, or model configuration that can leak private infrastructure details into terminal scrollback, logs, screenshots, or copied reports. In this skill’s context, the generated post-flight report and use of tee/shell output make accidental disclosure more likely.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
80% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · references/80-notes.md (reported line 88)May include surrounding context.

md
- 任何"资源紧张"操作(embed / reindex / sync 涉及 GPU + 锁)**默认串行**
- 想并发前先想清楚是不是会抢同一个 lock

## 5. qmd collection add conflict spam log

**症状**:
- log 里刷 `qmd collection add skipped for docs-<agent>`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Several comments and user-facing messages are exclusively in Chinese, including usage and completion guidance. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a local OpenClaw gateway upgrade workflow focused on backing up the service unit, preserving custom environment variables, verifying GPU acceleration with qmd doctor, and rebuilding qmd indexes. Recording the host's global npm package list is a broader machine inventory action that is not mentioned or obviously required for preserving gateway service configuration or qmd state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language comments and user-facing messages entirely in Chinese, including usage and error output. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script assigns db="$HOME/...", which preserves a literal "$HOME" instead of expanding to the user's home directory. As a result, the pre-check for existing vectors and the post-run verification likely operate on a non-existent or wrong path, causing the script to skip needed rebuilds or falsely report success without validating the real agent database.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script prints full values of preserved environment variables directly into the generated upgrade report. Variables like LD_LIBRARY_PATH, HF_ENDPOINT, and especially any future service environment entries may reveal internal paths, infrastructure endpoints, or model configuration details that can be copied from logs, tickets, or shared reports. In this skill context, the data is local, but the explicit purpose of generating a report increases the chance that sensitive values will be redistributed beyond the local host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The report includes unmasked environment variable values without any warning, consent gate, or sensitivity classification. Even if the listed variables are primarily operational, they can reveal local filesystem layout, GPU/runtime configuration, mirrored model endpoints, or custom model names, which may aid lateral reconnaissance or leak internal infrastructure when the report is shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The diagnostic section emits system and application metadata including qmd doctor output, GPU model/memory information, and aggregate per-agent vector counts. While this is lower risk than full secret disclosure, it still exposes host capabilities and application state that may be sensitive if pasted into support channels or retained in shared logs, and the script provides no warning or minimization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language description and operating instructions are written entirely in Chinese, and the trigger examples are also Chinese-oriented, with no indication that the user may choose another language. Under the policy, locale or language constraints should be optional or explicitly justified when a skill effectively enforces a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The operational instructions, headings, and guidance are presented in Chinese throughout the file, with no indication that the user can choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill directs a global npm package upgrade and native module rebuild for qmd without a direct warning that these commands mutate the active host runtime and can affect other workflows using the same global installation. In context this is less likely to be malicious, but it still creates avoidable operational risk such as version drift, ABI breakage, or unintended impact on unrelated tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents all user-facing instructions in Chinese and does not offer an alternative language or indicate that the locale is intentionally restricted. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This shell script writes backup files for the systemd service and database files using cp, but it does not include any user-facing warning about modifying the filesystem beyond terse success messages after the fact. Although the script's purpose is backup, the current comments and output do not disclose potential side effects such as overwriting existing .bak files with the same timestamp collision or creating many backup artifacts in user directories.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest frames operations as local service and database manipulation for the gateway upgrade flow. Querying $HOME/openclaw-local/package.json to extract the binary version extends into application source/package metadata inspection, which is not called out in the stated scope even though it is local-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script uses Chinese exclusively in its descriptive comments, usage guidance, and runtime log messages. That imposes a language choice on operators without offering an English alternative or any opt-in, which matches the locale/language policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest says the skill serially rebuilds per-agent qmd indexes to avoid lock contention, but this script additionally enumerates every agent directory and queries each SQLite index for content vector counts. That reporting/inspection capability is adjacent to the purpose but more expansive than the manifest's concise description of upgrade and verification steps.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.