Back to skill

Security audit

Bengii Gemini Fix

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent OpenClaw documentation, but it recommends unsafe installer/update commands and includes a troubleshooting step that can expose secrets.

Review before installing. Prefer pinned package or signed release installation over curl | bash or iwr | iex, avoid running installers as root, and do not paste or print ~/.openclaw/.env into an AI session. If you use the skill, keep the gateway on loopback or a private network, enable auth, restrict tools and subagents, use sandboxing for untrusted channels, and redact or rotate any secrets that were printed during troubleshooting.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/install.md:24
Finding

Unverified Remote Installer Scripts Are Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:277-279
  • references/install.md:24-35
  • references/install.md:125-127
  • references/gateway_ops.md:206-208

Vulnerability Type: Remote payload retrieval and immediate shell execution
Risk Level: Critical

Vulnerable Code

SKILL.md:277-279:

bash
# Install (recommended)
curl -fsSL https://openclaw.ai/install.sh | bash

references/install.md:24-35:

bash
# macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash

# Windows (PowerShell)
iwr -useb https://openclaw.ai/install.ps1 | iex
bash
curl -fsSL https://openclaw.ai/install.sh | bash -s -- --no-onboard

references/install.md:125-127:

bash
### Re-run Installer (Recommended)

curl -fsSL https://openclaw.ai/install.sh | bash

references/gateway_ops.md:206-208:

bash
# Installer script (macOS / Linux)
curl -fsSL https://openclaw.ai/install.sh | bash

Technical Analysis

These commands retrieve mutable content from an external server and immediately pass it to Bash or PowerShell for execution. There is no intervening review, version pinning, cryptographic signature verification, or pinned checksum validation.

TLS protects the network connection in transit but does not guarantee that the server will return the same installer that was reviewed. A compromise of the distribution server, publishing account, domain, DNS infrastructure, or certificate issuance process could cause arbitrary replacement content to be executed. The effective payload can therefore change after this Skill has passed review.

The installer is also documented as capable of installing prerequisites and setting up a long-running gateway daemon. Consequently, a malicious replacement could modify user files, access credentials available to the invoking process, install persistence, or alter system configuration. If the command is run from an ele ...[truncated 1629 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all curl | bash, curl | sh, and Invoke-WebRequest | Invoke-Expression recommendations.
  2. Publish versioned, immutable installer artifacts rather than relying on a mutable unversioned URL.
  3. Require users to download the installer without executing it:
    bash
    curl -fL --proto '=https' --tlsv1.2 \
      -o openclaw-install.sh \
      https://openclaw.ai/releases/VERSION/install.sh
    
  4. Publish a signed checksum manifest through an independently protected release channel.
  5. Verify both the publisher signature and a pinned SHA-256 digest before execution:
    bash
    printf '%s  %s\n' 'PINNED_SHA256' 'openclaw-install.sh' | sha256sum -c -
    
  6. Allow and encourage inspection of the downloaded script before running it:
    bash
    less openclaw-install.sh
    bash openclaw-install.sh
    
  7. Prefer a pinned package release such as openclaw@<verified-version> instead of openclaw@latest.
  8. For source installation, pin a full commit hash, verify its signed release or tag, and review installation hooks before running package-manager commands.
  9. Explicitly advise users not to execute the installer as root unless a documented operation strictly requires elevation.
  10. Apply the corrected procedure consistently in SKILL.md, references/install.md, and references/gateway_ops.md so that no unsafe fallback remains.

T09 · Insecure Skill Coding Practices

Warning
Location
references/gateway_ops.md:290
Finding

Troubleshooting Instructions Print the Entire Global Secrets File

Content
View full analysis

Vulnerability Details

File Location: references/gateway_ops.md:290-298
Vulnerability Type: Plaintext credential exposure through diagnostic output
Risk Level: Medium

Vulnerable Code

bash
3. **Verify `.env` before restarting**: Always check that `~/.openclaw/.env` has real values for all referenced variables before restarting the Gateway. Missing or placeholder env vars silently degrade features.

**Checklist after config replacement:**
```bash
# 1. Validate the config
openclaw config validate

# 2. Check .env has real values (no placeholders)
cat ~/.openclaw/.env
text

### Technical Analysis

The project identifies `~/.openclaw/.env` as a global environment fallback used for API keys, gateway authentication values, provider credentials, and channel tokens. The troubleshooting procedure prints the complete file to standard output using `cat`.

Reading the file may be relevant when diagnosing missing variables, but displaying every raw value is not necessary. In an AI-agent workflow, command output may be inserted into conversation transcripts, tool-call records, telemetry, debug logs, or other retained session data. It can also be exposed through terminal recording, screen sharing, scrollback capture, or centralized shell monitoring.

This creates a plaintext disclosure path even when the `.env` file itself has restrictive filesystem permissions. File permissions do not protect a secret after an authorized process prints it into a less-protected output channel.

### Attack Path

1. The global `.env` file contains valid provider API keys, gateway tokens, bot tokens, or other credentials.
2. An operator or AI agent follows the documented configuration-replacement troubleshooting checklist.
3. The command `cat ~/.openclaw/.env` prints all variable names and plaintext values.
4. The output is captured in an agent transcript, tool log, terminal recording, monitoring platform, screen share, or s
...[truncated 793 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to run cat ~/.openclaw/.env.
  2. Use openclaw secrets audit or another purpose-built diagnostic that redacts credential values.
  3. Validate only whether required variable names exist and whether values resemble known placeholders; output status rather than values.
  4. If a custom diagnostic is necessary, ensure it prints only variable names and a redacted status such as set, missing, or placeholder.
  5. Never include raw .env contents in AI conversations, support tickets, logs, screenshots, or command transcripts.
  6. Add explicit guidance to rotate any credential that has already been printed into a retained or shared output channel.
  7. Retain restrictive permissions such as chmod 600 ~/.openclaw/.env, while clarifying that permissions alone do not prevent output-based disclosure.
  8. Prefer SecretRef integrations backed by environment, file, 1Password, Vault, or sops providers, and avoid diagnostics that materialize all resolved secrets at once.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (122)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
| [tools.md](references/tools.md) | Tools inventory (profiles, groups, all built-in tools) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 292)May include surrounding context.

md
| [tools.md](references/tools.md) | Tools inventory (profiles, groups, all built-in tools) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
| [install.md](references/install.md) | Installation, updating, rollback, migration, uninstall |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

md
| [install.md](references/install.md) | Installation, updating, rollback, migration, uninstall |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
| [subagents.md](references/subagents.md) | Sub-agents: nested spawning, thread binding, announce, tool policy |

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
openclaw channels status --probe   # Channel health check
openclaw security audit            # Security posture check
openclaw security audit --fix      # Auto-fix security issues
openclaw update                    # Self-update
openclaw dashboard                 # Open Control UI in browser
openclaw tui                       # Terminal UI (interactive REPL)
openclaw agent                     # Direct agent interaction via CLI

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/install.md (reported line 141)May include surrounding context.

md
openclaw channels status --probe   # Channel health check
openclaw security audit            # Security posture check
openclaw security audit --fix      # Auto-fix security issues
openclaw update                    # Self-update
openclaw dashboard                 # Open Control UI in browser
openclaw tui                       # Terminal UI (interactive REPL)
openclaw agent                     # Direct agent interaction via CLI

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill recommends piping a remote script directly into bash without verification, pinning, or integrity checks. This is dangerous because any compromise of the server, DNS, TLS trust chain, or script content could lead to arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching a script from the network and piping it directly to the shell is a classic arbitrary code execution anti-pattern. It eliminates opportunities for inspection and makes the user trust both transport and remote content at execution time, so compromise of the endpoint or content distribution channel can fully compromise the host.

Content

Scanner excerpt · SKILL.md (reported line 279)May include surrounding context.

bash
# Install (recommended)
curl -fsSL https://openclaw.ai/install.sh | bash

# Update
openclaw update                    # Self-update command

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The command chains network retrieval directly into shell execution, creating a dangerous one-step path from untrusted remote content to code execution. In an agent skill, this is especially risky because it can be reproduced or recommended without sufficient scrutiny, amplifying the chance of unsafe host compromise.

Content

Scanner excerpt · SKILL.md (reported line 279)May include surrounding context.

bash
# Install (recommended)
curl -fsSL https://openclaw.ai/install.sh | bash

# Update
openclaw update                    # Self-update command

Self-Modification

High
Category
Rogue Agent
Confidence
93% confidence
Finding

This finding appears in the install/update section alongside remote code execution patterns and directly references self-update behavior. In that context, encouraging self-modification without version pinning, verification, or warnings materially increases the risk of unsafe code changes being applied to the host.

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

md
curl -fsSL https://openclaw.ai/install.sh | bash

# Update
openclaw update                    # Self-update command
# Or: npm install -g openclaw@latest
openclaw doctor                    # Run after update to apply migrations

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/browser.md (reported line 176)May include surrounding context.

md
| Endpoint | Description |
|---|---|
| `GET /`, `POST /start`, `POST /stop` | Status/start/stop |
| `GET /tabs`, `POST /tabs/open`, `POST /tabs/focus`, `DELETE /tabs/:targetId` | Tab control |
| `GET /snapshot`, `POST /screenshot` | Snapshot/screenshot |
| `POST /navigate`, `POST /act` | Navigation and actions |
| `POST /hooks/file-chooser`, `POST /hooks/dialog` | Hooks |

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/channel_troubleshooting.md (reported line 172)May include surrounding context.

md
# Step 3: Generate invite URL with scopes: bot, applications.commands
# Permissions: View Channels, Send Messages, Read Message History, Embed Links, Attach Files

# Step 4: Enable Developer Mode
# User Settings → Advanced → Developer Mode → On
# Right-click server → Copy Server ID
# Right-click avatar → Copy User ID

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

Fetching and executing an external script in one step is a high-risk pattern because it trusts both remote content and delivery integrity at execution time. Any compromise of the remote server, CDN, DNS, TLS termination, or publishing process could lead to arbitrary code execution on every user who runs the command.

Content

Scanner excerpt · references/gateway_ops.md (reported line 208)May include surrounding context.

bash
# Installer script (macOS / Linux)
curl -fsSL https://openclaw.ai/install.sh | bash

# npm
npm install -g openclaw@latest

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash chaining pattern directly converts downloaded content into code execution, which is especially dangerous in user-facing documentation because it encourages copy-paste execution without scrutiny. In an operations guide for a network-exposed gateway, this increases supply-chain risk and can lead to full host compromise.

Content

Scanner excerpt · references/gateway_ops.md (reported line 208)May include surrounding context.

bash
# Installer script (macOS / Linux)
curl -fsSL https://openclaw.ai/install.sh | bash

# npm
npm install -g openclaw@latest

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The command fetches a remote script from openclaw.ai and executes it immediately via bash, creating a direct remote code execution path for anyone who can tamper with the script source or delivery. Because this is installation guidance, users are likely to run it verbatim, increasing exploitation likelihood.

Content

Scanner excerpt · references/install.md (reported line 26)May include surrounding context.

bash
# macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash

# Windows (PowerShell)
iwr -useb https://openclaw.ai/install.ps1 | iex

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The shell pipeline chains network retrieval directly into command execution, eliminating any pause for inspection or verification and making abuse trivial if the upstream content is altered. In a security-sensitive gateway installation guide, this pattern is more dangerous because the installed software may later broker messages, tokens, and multi-channel integrations.

Content

Scanner excerpt · references/install.md (reported line 26)May include surrounding context.

bash
# macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash

# Windows (PowerShell)
iwr -useb https://openclaw.ai/install.ps1 | iex

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This is the same unsafe remote-script execution pattern as the primary installer example, just with arguments passed to the script. It still causes users to execute unverified network content directly in a shell, so compromise of the source or transport can yield immediate code execution.

Content

Scanner excerpt · references/install.md (reported line 35)May include surrounding context.

Skip the onboarding wizard with --no-onboard:

bash
curl -fsSL https://openclaw.ai/install.sh | bash -s -- --no-onboard

npm / pnpm

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

Recommending users re-run the installer using curl ... | bash during updates repeats the same unverified remote execution pattern and broadens exposure over time. Update operations are especially sensitive because they may run on production systems with existing secrets and services present.

Content

Scanner excerpt · references/install.md (reported line 127)May include surrounding context.

Re-run Installer (Recommended)

bash
curl -fsSL https://openclaw.ai/install.sh | bash

Before You Update

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The update path again uses a direct fetch-to-shell chain, which can be exploited to turn a routine maintenance step into remote code execution. Since updates may be run repeatedly and on already-trusted hosts, successful abuse can yield compromise of long-lived services and stored credentials.

Content

Scanner excerpt · references/install.md (reported line 127)May include surrounding context.

Re-run Installer (Recommended)

bash
curl -fsSL https://openclaw.ai/install.sh | bash

Before You Update

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/gateway_ops.md (reported line 297)May include surrounding context.

text
.prose/
├── .env
├── runs/
│   └── {YYYYMMDD}-{HHMMSS}-{random}/
│       ├── program.prose

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/gateway_ops.md (reported line 298)May include surrounding context.

text
.prose/
├── .env
├── runs/
│   └── {YYYYMMDD}-{HHMMSS}-{random}/
│       ├── program.prose

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/openprose.md (reported line 66)May include surrounding context.

text
.prose/
├── .env
├── runs/
│   └── {YYYYMMDD}-{HHMMSS}-{random}/
│       ├── program.prose

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/remote_access.md (reported line 167)May include surrounding context.

md
## Webhooks

External systems can send messages to the Gateway via webhooks.

## Config (Default-On)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/security.md (reported line 313)May include surrounding context.

md
## Webhooks

External systems can send messages to the Gateway via webhooks.

## Config (Default-On)

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions, suspicious.secret_argv_exposure

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/voice.md:42

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/memory.md:58

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
references/gateway_ops.md:84