Back to skill

Security audit

openclaw-backup-restore

Security checks for vulnerabilities and agentic risk

Overview

This backup skill is coherent, but it handles complete credential-bearing backups and has an unsafe restore path that can write files outside the intended OpenClaw directory.

Review this skill carefully before installing. Only restore archives you created or fully trust, use encrypted backups for any transfer or shared storage, and avoid plaintext backups in cloud-synced or multi-user locations until archive permissions and restore path validation are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/restore.sh:90
Finding

Restore Archive Is Not Confined to the Intended OpenClaw Directory

Content
View full analysis
/dev/null | grep -qE '^\.\./|/\.\./'; then echo "Error: archive contains path traversal sequences (../) — aborting." exit 1 fi } ``` The archive is subsequently extracted into the parent of the configured OpenClaw home: ```bash PARENT_DIR="$(dirname "$OPENCLAW_HOME")" mkdir -p "$PARENT_DIR" echo "Extracting..." tar -xzf "$WORK_ARCHIVE" -C "$PARENT_DIR" ``` ### Technical Analysis The validation only searches archive member names for `../` at the beginning or after a forward slash. It does not enforce the more important security invariant that every archive member must belong to the exact expected root directory, such as `.openclaw/`. For the default target, extraction occurs in `$HOME`, not in a newly created and isolated `.openclaw` directory. Therefore, a crafted archive can contain unrelated top-level entries such as `.ssh/config`, `.bashrc`, or `other-directory/file`. These entries do not contain `../`, pass the traversal check, and are extracted under the target parent rather than under `.openclaw`. The validator also does not explicitly reject: - Absolute archive paths - A member named exactly `..` - Platform-specific separator variants - Symbolic or hard-link entries whose targets escape the intended root - Archives whose root directory does not match `basename "$OPENCLAW_HOME"` The behavior of some absolute paths and link entries can vary between `tar` implementations, but the unrelated-top-level-entry issue is sufficient to bypass the intended extraction boundary. ### Attack Path 1. An attacker creates or modifies a gzip-compressed tar ...[truncated 1404 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup.sh:106
Finding

Plaintext Secret-Bearing Backups Are Created Without Enforced Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly states that backups include credentials, secrets, memory, and workspace data, but it does not prominently warn that the resulting archive is highly sensitive and may enable full account or environment compromise if exposed. Presenting the archive as a portable artifact that can be dropped onto any machine normalizes unsafe handling of material equivalent to a full secrets export.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The migration instructions advise copying the archive via USB, cloud, or SCP without warning that the file may contain credentials and secrets or requiring encryption before transfer. This can lead users to move a full-secret backup through less trusted channels, increasing the chance of disclosure, theft, or later misuse.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 68)May include surrounding context.

md
| Flag | Description |
|---|---|
| `--home DIR` | Restore to a custom OpenClaw home (default: `~/.openclaw`) |
| `--force` | Skip confirmation prompts |
| `--verify` | Verify archive integrity without restoring |

## Environment variables

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

Usage examples

bash
# Create a backup in ~/openclaw-backups/
bash scripts/backup.sh

# Backup to a custom directory

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
# Restore (will prompt before overwriting)
bash scripts/restore.sh openclaw-backup-2026-05-24_120000.tar.gz

# Restore without confirmation prompt
bash scripts/restore.sh --force openclaw-backup-2026-05-24_120000.tar.gz

# Restore to a custom openclaw home

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly states that the entire ~/.openclaw directory is archived with no exclusions and that this includes credentials, auth tokens, secrets, and runtime state, but it does not present a prominent warning at the point of backup behavior. This creates a meaningful risk that users will create and distribute backups containing highly sensitive material without realizing the exposure, especially because the text emphasizes convenience and exact restoration.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| `credentials/` | API keys per service |
| `secrets/` | Encrypted secrets store |

The restore script sets `chmod 700` on these directories after extraction.
Use `--encrypt` with a GPG key for backups stored in cloud or shared drives.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/paths.md (reported line 30)May include surrounding context.

md
| `credentials/` | API keys per service |
| `secrets/` | Encrypted secrets store |

The restore script sets `chmod 700` on these directories after extraction.
Use `--encrypt` with a GPG key for backups stored in cloud or shared drives.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/restore.sh (reported line 53)May include surrounding context.

sh
| `credentials/` | API keys per service |
| `secrets/` | Encrypted secrets store |

The restore script sets `chmod 700` on these directories after extraction.
Use `--encrypt` with a GPG key for backups stored in cloud or shared drives.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/backup.sh (reported line 55)May include surrounding context.

sh
gpg_install_hint() {
  case "$OS" in
    macos)   echo "  Install: brew install gnupg" ;;
    linux)   echo "  Install: sudo apt install gnupg  OR  sudo dnf install gnupg2" ;;
    windows) echo "  Install: winget install GnuPG.GnuPG  OR include via Git for Windows" ;;
    *)       echo "  Install gpg from https://gnupg.org/download/" ;;
  esac

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/restore.sh (reported line 54)May include surrounding context.

sh
for sensitive_dir in identity credentials secrets; do
    if [[ -d "$OPENCLAW_HOME/$sensitive_dir" ]]; then
      chmod 700 "$OPENCLAW_HOME/$sensitive_dir"
      chmod 600 "$OPENCLAW_HOME/$sensitive_dir/"* 2>/dev/null || true
    fi
  done
  [[ -f "$OPENCLAW_HOME/openclaw.json" ]] && chmod 600 "$OPENCLAW_HOME/openclaw.json"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/restore.sh (reported line 57)May include surrounding context.

sh
for sensitive_dir in identity credentials secrets; do
    if [[ -d "$OPENCLAW_HOME/$sensitive_dir" ]]; then
      chmod 700 "$OPENCLAW_HOME/$sensitive_dir"
      chmod 600 "$OPENCLAW_HOME/$sensitive_dir/"* 2>/dev/null || true
    fi
  done
  [[ -f "$OPENCLAW_HOME/openclaw.json" ]] && chmod 600 "$OPENCLAW_HOME/openclaw.json"

Static analysis

No suspicious patterns detected.