Back to skill

Security audit

OpenClaw Config

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent OpenClaw configuration helper that can change persistent gateway settings, but its behavior is disclosed, scoped to that purpose, and not deceptive.

Install only if you want an agent to help inspect and change OpenClaw Gateway configuration. Review proposed config changes before applying them, avoid storing long-lived secrets directly in openclaw.json, and be especially careful with plugin, skill, auth, remote access, and tool-execution settings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill clearly instructs use of shell-capable commands such as openclaw config set, openclaw doctor, and RPC calls, but it does not declare any explicit tool scope or allowed-tools boundary. That creates an authorization ambiguity where an agent may invoke shell operations more broadly than intended, increasing the chance of unsafe command execution or unintended modification of local configuration and state.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
3. **Apply changes with the smallest safe surface**

- Prefer small edits: `openclaw config get|set|unset` (dot path or bracket notation).
- If the Gateway is online and you want "write + validate + restart" in one step: use RPC `config.patch` (merge patch) or `config.apply` (replaces the entire config; use carefully).
- For complex setups, split config with `$include` (see below).

4. **Validate strictly**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation describes plugin and skill loading, installation sources, extra directories, watch behavior, and install mechanisms without any warning that these features can introduce untrusted code execution. In the context of an agent skill specifically meant to edit security-relevant gateway configuration, omitting trust guidance can plausibly lead users to enable or install arbitrary local or package-sourced extensions, expanding attack surface and potentially executing malicious code.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/openclaw-config-check.sh (reported line 49)May include surrounding context.

sh
if [[ -n "${perms}" ]]; then
    echo "Permissions: ${perms}"
    if [[ "${perms}" =~ ^[0-9]+$ ]] && (( perms > 600 )); then
      echo "WARNING: config perms are >600; consider: chmod 600 \"${CONFIG_PATH}\""
    fi
  fi
else

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents authentication and remote access fields such as gateway.auth.token, gateway.auth.password, gateway.remote.token, gateway.remote.password, and sshIdentity, but it does not warn readers that these values are sensitive secrets. In a config reference, omitting any caution about handling credentials can increase the chance that users store, share, or log secrets unsafely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.