Back to skill

Security audit

CC3PO System Healthcheck

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local system health-check skill; its main risk is optional cron scheduling that keeps running checks in the background.

Install this only if you want local OpenClaw/system health checks. Enable the cron entries only if you want recurring background monitoring, review and edit the paths first, and avoid the sudo cron-service commands unless you understand the system-level change. Before uninstalling, preview the target directories/log files so scoped rm commands do not remove local changes you meant to keep.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Warning
Location
templates/crontab_example.txt:9
Finding

Persistent Scheduled Execution of Mutable Skill Scripts

Content
View full analysis
> $WORKSPACE/logs/healthcheck_l2.log 2>&1 # L3 daily audit # Run every day at 08:00 0 8 * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/l3_daily_audit.py >> $WORKSPACE/logs/healthcheck_l3.log 2>&1 # Heartbeat check # Run every 30 minutes */30 * * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/heartbeat.py >> $WORKSPACE/logs/heartbeat.log 2>&1 ``` `INSTALL.md:134-142`: ```bash # Linux sudo systemctl start cron sudo systemctl enable cron # macOS sudo launchctl load -w /System/Library/LaunchDaemons/com.vix.cron.plist ``` `SKILL.md:65-70`: ```bash ### 3. Setup Crontab ```bash cat templates/crontab_example.txt # Copy and edit crontab crontab -e ``` ``` ### Technical Analysis The project explicitly directs users to register three recurring cron jobs. These jobs survive the installation session and execute scripts from the user-writable Skill directory every 30 minutes, hourly, and daily. Scheduled execution is relevant to the declared continuous health-monitoring functionality and is presented transparently rather than installed silently. Nevertheless, it creates a persistent execution path. If the Skill directory is later modified through a compromised update, another process running as the user, or an untrusted replacement of the scripts, cron will execute the modified code automatically. The installation gui ...[truncated 2136 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (52)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · INSTALL.md (reported line 129)May include surrounding context.

"scripts" / "l1_fast_check.py")], capture_output=True, text=True, timeout=1 )

if result.returncode != 0: print(f"⚠️ Warning: {result.stdout}")

text

### 5.2 心跳机制

心跳检查已设计为智能输出:
- 工作时间(9-18 点):有问题时输出,正常时输出 `HEARTBEAT_OK`
- 非工作时间:静默

---

## 6. 常见问题

### Q: 提示找不到 Python
A: 修改 crontab 中的 `PYTHON` 路径:
```bash
which python3  # 查看 Python 路径

Q: Cron 服务未运行

A: 启动 Cron 服务:

bash
# Linux
sudo systemctl start cron
sudo systemctl enable cron

# macOS
sudo launchctl load -w /System/Library/LaunchDaemons/com.vix.cron.plist

Q: 输出乱码

A: 确保终端支持 UTF-8:

bash
export LANG=en_US.UTF-8  # 或 zh_CN.UTF-8

Q: 如何禁用某项检查?

A: 编辑 config/default_config.yaml,设置 enabled: false


7. 卸载

bash
# 删除技能目录
rm -rf ~/.openclaw/skills/system-healthcheck

# 移

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

rm -rf ~/.openclaw/skills/system-healthcheck is an explicitly destructive command in end-user documentation. While the target is appropriately scoped to the skill directory, the use of forceful recursive deletion without confirmation or safety notes can cause unintended data loss, especially if the path is customized or mistyped.

Content

Scanner excerpt · INSTALL.md (reported line 160)May include surrounding context.

bash
# 删除技能目录
rm -rf ~/.openclaw/skills/system-healthcheck

# 移除 crontab 配置
crontab -e

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

rm -rf ~/.openclaw/skills/system-healthcheck is an explicitly destructive command in end-user documentation. While the target is appropriately scoped to the skill directory, the use of forceful recursive deletion without confirmation or safety notes can cause unintended data loss, especially if the path is customized or mistyped.

Content

Scanner excerpt · INSTALL.md (reported line 160)May include surrounding context.

bash
# 删除技能目录
rm -rf ~/.openclaw/skills/system-healthcheck

# 移除 crontab 配置
crontab -e

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The log cleanup command uses a wildcard, which can delete multiple files unexpectedly if the path or naming convention changes. This is not inherently malicious, but wildcard deletion in documentation can still produce avoidable data loss.

Content

Scanner excerpt · INSTALL.md (reported line 167)May include surrounding context.

删除相关行

清理日志(可选)

rm ~/.openclaw/workspace/logs/healthcheck*.log

text

---

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · DEVELOPMENT_SUMMARY.md (reported line 173)May include surrounding context.

方式 2: 手动安装

bash
# 已安装在本地
cd ~/.openclaw/skills/system-healthcheck

📋 使用指南

快速测试

bash
cd ~/.openclaw/skills/system-healthcheck

# L1 检查
python scripts/l1_fast_check.py

# L2 检查
python scripts/l2_hourly_check.py

# L3 审计
python scripts/l3_daily_audit.py

# 心跳检查
python scripts/heartbeat.py --force

配置 Crontab

bash
# 编辑 crontab
crontab -e

# 添加以下配置(修改路径)
PYTHON=/usr/bin/python3
HEALTHCHECK_DIR=$HOME/.openclaw/skills/system-healthcheck
WORKSPACE=$HOME/.openclaw/workspace

# L2 小时级检查
0 * * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/l2_hourly_check.py >> $WORKSPACE/logs/healthcheck.log 2>&1

# 心跳检查(每 30 分钟)
*/30 * * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/heartbeat.py >> $WORKSPACE/logs/heartbeat.log 2>&1

# L3 日级审计(每日 08:00)
0 8 * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/l3_daily_audit.py >> $WORKSPACE/logs/healthc

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · PUBLISHED.md (reported line 82)May include surrounding context.

方式 2: 手动安装

bash
# 已安装在本地
cd ~/.openclaw/skills/system-healthcheck

📋 使用指南

快速测试

bash
cd ~/.openclaw/skills/system-healthcheck

# L1 检查
python scripts/l1_fast_check.py

# L2 检查
python scripts/l2_hourly_check.py

# L3 审计
python scripts/l3_daily_audit.py

# 心跳检查
python scripts/heartbeat.py --force

配置 Crontab

bash
# 编辑 crontab
crontab -e

# 添加以下配置(修改路径)
PYTHON=/usr/bin/python3
HEALTHCHECK_DIR=$HOME/.openclaw/skills/system-healthcheck
WORKSPACE=$HOME/.openclaw/workspace

# L2 小时级检查
0 * * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/l2_hourly_check.py >> $WORKSPACE/logs/healthcheck.log 2>&1

# 心跳检查(每 30 分钟)
*/30 * * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/heartbeat.py >> $WORKSPACE/logs/heartbeat.log 2>&1

# L3 日级审计(每日 08:00)
0 8 * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/l3_daily_audit.py >> $WORKSPACE/logs/healthc

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code chunk does not implement a three-tier health monitoring system or heartbeat functionality. Its primary purpose is internationalization support only. While i18n is mentioned in the declared description, the code shown is just the localization module, not the monitoring system described. It also accesses environment variables, system locale APIs, and locale files on disk, which are resource interactions not reflected in the empty declared permissions. Additionally, the code optionally imports the external 'yaml' package, which conflicts with the claim of zero external dependencies, even though it includes a fallback parser.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises a broader three-tier health monitoring system with heartbeat functionality, but this code chunk only performs a narrow L1 file presence/readability check. That is a materially different and incomplete primary purpose relative to the declared system scope. Additionally, the script supports JSON output, which goes beyond a strict 'console output only' description if that implies plain human-readable console text only. Finally, although dependencies metadata is empty, the code conditionally imports yaml for config parsing when available, which weakens the 'zero external dependencies' claim. i18n support is consistent with the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code generally fits a system health monitoring purpose and clearly appears to be the L2 portion of a tiered monitoring setup, with internationalization support and mostly local-only checks. However, several declared details do not match the actual behavior. First, there is no heartbeat mechanism present in this chunk: it performs one-shot checks and exits. Second, the description claims zero external dependencies, but the code attempts to import yaml and parse a YAML config file, which implies an optional external dependency not reflected in the declaration. Third, 'console output only' is overstated because the script explicitly supports a --json mode that outputs structured JSON, even though it still writes to stdout. No clearly malicious or unrelated capability is present; the mismatch is about omitted or inaccurate feature claims rather than a different primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code is broadly aligned with system health monitoring and does have zero third-party Python dependencies and some i18n usage. However, the declared description is not fully accurate. Most notably, there is no heartbeat mechanism visible in this chunk. The script is specifically an L3 daily audit tool, not a generic three-tier monitor by itself, and it includes additional capabilities such as checking pending OS package updates, process counts, swap usage, old log files, and disk cleanup needs. It also offers --json and --report output modes, which is broader than a simple console-only health display. These are material description-behavior differences, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/l3_daily_audit.py (reported line 383)May include surrounding context.

python
for check in results["checks"]:
            if check.get("status") in ["warning", "error", "critical"]:
                if check["check"] == "updates":
                    lines.append("- Run system updates: `sudo apt update && sudo apt upgrade`")
                elif check["check"] == "old_logs":
                    lines.append("- Clean old log files in workspace/logs/")
                elif check["check"] == "disk_cleanup":

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language description says the skill will automatically detect system language and supports only English and Simplified Chinese. This can violate language/locale policy because it selects locale behavior implicitly rather than explicitly offering the user a choice or documenting a justified regional restriction.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The guide instructs users to create cron jobs, which establishes periodic execution and therefore persistence on the host. While expected for a health-check skill, persistent scheduled execution increases risk because a compromised or modified script would continue running automatically in the background.

Content

Scanner excerpt · INSTALL.md (reported line 49)May include surrounding context.

3.2 编辑 Crontab

bash
crontab -e

3.3 添加以下配置(修改路径)

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · INSTALL.md (reported line 71)May include surrounding context.

bash
# 查看已配置的任务
crontab -l

# 查看系统 Cron 服务状态
systemctl status cron  # Linux

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 138)May include surrounding context.

A: 启动 Cron 服务:

bash
# Linux
sudo systemctl start cron
sudo systemctl enable cron

# macOS

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 139)May include surrounding context.

A: 启动 Cron 服务:

bash
# Linux
sudo systemctl start cron
sudo systemctl enable cron

# macOS

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 142)May include surrounding context.

A: 启动 Cron 服务:

bash
# Linux
sudo systemctl start cron
sudo systemctl enable cron

# macOS

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

systemctl enable cron ensures the cron service starts on boot, which contributes to system-level persistence for any configured jobs. In this context it is operationally legitimate, but it still increases the durability of scheduled execution and broadens the impact of any future script compromise.

Content

Scanner excerpt · INSTALL.md (reported line 139)May include surrounding context.

bash
# Linux
sudo systemctl start cron
sudo systemctl enable cron

# macOS
sudo launchctl load -w /System/Library/LaunchDaemons/com.vix.cron.plist

Session Persistence

Medium
Category
Rogue Agent
Confidence
77% confidence
Finding

launchctl load -w on macOS loads and persists the cron daemon configuration, enabling recurring execution after reboot. Although presented as troubleshooting guidance, this still establishes persistence infrastructure that could be abused if the monitored scripts are altered later.

Content

Scanner excerpt · INSTALL.md (reported line 142)May include surrounding context.

sudo systemctl enable cron

macOS

sudo launchctl load -w /System/Library/LaunchDaemons/com.vix.cron.plist

text

### Q: 输出乱码

Session Persistence

Medium
Category
Rogue Agent
Confidence
77% confidence
Finding

launchctl load -w on macOS loads and persists the cron daemon configuration, enabling recurring execution after reboot. Although presented as troubleshooting guidance, this still establishes persistence infrastructure that could be abused if the monitored scripts are altered later.

Content

Scanner excerpt · INSTALL.md (reported line 142)May include surrounding context.

sudo systemctl enable cron

macOS

sudo launchctl load -w /System/Library/LaunchDaemons/com.vix.cron.plist

text

### Q: 输出乱码

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The uninstall section includes destructive deletion commands (rm -rf and log removal) without an explicit warning, verification step, or backup guidance. In an installation guide, users may copy-paste these commands directly, and path mistakes or unexpected shell expansion can lead to accidental data loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is written almost entirely in Chinese, including operational release steps and checklist items, while the file itself does not state that it is region-specific or provide an explicit language choice. Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill documentation shows it expects shell execution, filesystem reads, and environment access, but it does not declare any explicit tool scope or permissions. That creates an authorization gap: an agent or reviewer cannot reliably determine the minimum required capabilities, increasing the risk of over-privileged execution and unintended access to local system data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill instructs users to install recurring cron jobs, which creates persistence on the host outside the immediate agent session. Persistence is security-relevant because periodic execution of local scripts can continue indefinitely, inherit user privileges, and become a durable foothold if the skill or its files are later modified or replaced.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

bash
cat templates/crontab_example.txt
# Copy and edit crontab
crontab -e

4. Heartbeat Check

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file includes natural-language documentation and usage text entirely in Chinese, and it imports an i18n layer without exposing any visible user choice of locale in this file. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALL.md:160