Back to skill

Security audit

OpenClaw Course Reference

Security checks for vulnerabilities and agentic risk

Overview

This is a searchable OpenClaw course reference, but it includes multiple copy-paste setup examples that can run unverified or overprivileged commands on a user's machine or server.

Review this skill before installing or using its output as commands. It is not showing hidden exfiltration or automatic destructive behavior, but users should avoid blindly running the remote installer, privileged Docker, systemd, and autonomous coding-agent examples; verify installers, avoid Docker socket exposure where possible, keep secrets out of logs, and harden any persistent service before deployment.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (7)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/01-FOUNDATIONS.md:98
Finding

Unverified OpenClaw and NodeSource Scripts Executed Directly by a Shell

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
references/04-CONTEXT-AND-COSTS.md:37
Finding

Unverified Ollama Installer Executed Directly by a Shell

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
references/05-VPS-EMPLOYEE.md:142
Finding

Unverified NodeSource Setup Script Executed with Administrative Privileges

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/03-LOCAL-POWER.md:1163
Finding

Command Injection Through Unescaped Agent, Filename, and Model-Generated Values

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/05-VPS-EMPLOYEE.md:237
Finding

Gateway Password Disclosed to Terminal and Process Logs

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/05-VPS-EMPLOYEE.md:486
Finding

Persistent OpenClaw Service Explicitly Disables Key Systemd Isolation Controls

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/06-SECURITY.md:568
Finding

Privileged Audit Reports Written Through Predictable Paths in Shared Temporary Storage

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (197)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
- `SKILL.md`, `manifest`, `clawhub`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
- `references`, `scripts`, `index.js`

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

curl -fsSL https://openclaw.ai/install.sh | bash is a classic unsafe install pattern that executes network-delivered code immediately. Any compromise of the distribution path or installer content leads directly to arbitrary command execution on the user's machine.

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 98)May include surrounding context.

macOS/Linux:

bash
curl -fsSL https://openclaw.ai/install.sh | bash

Windows (PowerShell):

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping an externally retrieved installer script directly to bash creates a one-step arbitrary code execution path with no opportunity for integrity verification or review. In documentation for an AI agent platform, this is especially risky because users may copy-paste it unquestioningly during setup.

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 98)May include surrounding context.

macOS/Linux:

bash
curl -fsSL https://openclaw.ai/install.sh | bash

Windows (PowerShell):

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Chaining a network fetch directly into sudo -E bash - combines two high-risk operations: unverified remote content and privileged execution. This magnifies the impact of any upstream compromise into full root-level code execution on the host.

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 117)May include surrounding context.

bash
# Install Node.js 22+ using NodeSource
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs

# Verify installation

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 137)May include surrounding context.

md
# Additional WSL2 optimizations
echo '[interop]
appendWindowsPath=false' | sudo tee /etc/wsl.conf

# Restart WSL
wsl --shutdown

Docker Socket Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Documenting OPENCLAW_DOCKER_SOCKET=/var/run/docker.sock as part of a sandbox setup normalizes direct host Docker API exposure. Any code path able to access that socket can control the Docker daemon, start privileged containers, mount host filesystems, and effectively take over the host.

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 216)May include surrounding context.

bash
# Enable sandboxing for Docker deployments
export OPENCLAW_SANDBOX=1
export OPENCLAW_DOCKER_SOCKET=/var/run/docker.sock

# Run with sandbox capability
docker run -d \

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
100% confidence
Finding

--privileged disables most container isolation protections and grants extensive kernel/device capabilities. In combination with an AI agent platform that may execute tools or untrusted workflows, this materially increases the chance of host compromise through container escape or abuse of granted privileges.

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 222)May include surrounding context.

md
docker run -d \
  --name openclaw-gateway \
  -p 18789:18789 \
  --privileged \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v ~/.openclaw:/root/.openclaw \
  openclaw/openclaw:latest

Docker Socket Access

High
Category
Privilege Escalation
Confidence
100% confidence
Finding

Mounting /var/run/docker.sock into the container gives processes inside the container direct access to the host Docker daemon. This effectively defeats container isolation because the container can create or control sibling containers with arbitrary host mounts and privileges.

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 223)May include surrounding context.

--name openclaw-gateway
-p 18789:18789
--privileged
-v /var/run/docker.sock:/var/run/docker.sock
-v ~/.openclaw:/root/.openclaw
openclaw/openclaw:latest

text

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 748)May include surrounding context.

Check API Key:

bash
# Test API key
curl -H "x-api-key: $ANTHROPIC_API_KEY" \
  https://api.anthropic.com/v1/models

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 774)May include surrounding context.

md
npm update -g openclaw@latest

# Clear cache if needed
rm -rf ~/.openclaw/.cache

# Restart gateway
openclaw gateway restart

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 774)May include surrounding context.

md
npm update -g openclaw@latest

# Clear cache if needed
rm -rf ~/.openclaw/.cache

# Restart gateway
openclaw gateway restart

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The quick reference repeats the same unsafe curl | bash pattern, reinforcing risky behavior and increasing the chance users will execute it verbatim. Repetition in a summary section makes the issue more dangerous because quick-reference blocks are commonly copy-pasted without reading surrounding context.

Content

Scanner excerpt · references/01-FOUNDATIONS.md (reported line 821)May include surrounding context.

bash
# Installation
curl -fsSL https://openclaw.ai/install.sh | bash
npm install -g openclaw@latest

# Onboarding

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
55% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/02-THE-SOUL-ARCHITECTURE.md (reported line 125)May include surrounding context.

md
## Vibe

Calm, organized, and dependable. The eye of the hurricane.
Speak with quiet confidence. Don't apologize for normal delays.

## Communication Style

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/03-LOCAL-POWER.md (reported line 8)May include surrounding context.

md
2. [Voice Input with Whisper/FFmpeg](#voice-input-with-whisperffmpeg)
3. [Local Image Generation with ComfyUI](#local-image-generation-with-comfyui)
4. [Agentic Coding with Claude Code/Codex/OpenCode](#agentic-coding-with-claude-codecodexopcode)
5. [Self-Modifying Agents](#self-modifying-agents)
6. [Integration Patterns](#integration-patterns)

---

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/03-LOCAL-POWER.md (reported line 8)May include surrounding context.

md
2. [Voice Input with Whisper/FFmpeg](#voice-input-with-whisperffmpeg)
3. [Local Image Generation with ComfyUI](#local-image-generation-with-comfyui)
4. [Agentic Coding with Claude Code/Codex/OpenCode](#agentic-coding-with-claude-codecodexopcode)
5. [Self-Modifying Agents](#self-modifying-agents)
6. [Integration Patterns](#integration-patterns)

---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/03-LOCAL-POWER.md (reported line 290)May include surrounding context.

Environment Variables

bash
# ~/.openclaw/.env
OPENAI_API_KEY=sk-...

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/06-SECURITY.md (reported line 437)May include surrounding context.

Environment Variables

bash
# ~/.openclaw/.env
OPENAI_API_KEY=sk-...

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/06-SECURITY.md (reported line 450)May include surrounding context.

Environment Variables

bash
# ~/.openclaw/.env
OPENAI_API_KEY=sk-...

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/06-SECURITY.md (reported line 651)May include surrounding context.

Environment Variables

bash
# ~/.openclaw/.env
OPENAI_API_KEY=sk-...

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
95% confidence
Finding

The example recommends delegating work to an external model provider using claude --print --permission-mode bypassPermissions, combining third-party code generation with reduced safeguards. This can expose source code or prompts to an external provider and permit broad automated modifications without normal confirmation controls.

Content

Scanner excerpt · references/03-LOCAL-POWER.md (reported line 731)May include surrounding context.

bash
# Quick one-shot task (no PTY needed)
claude --print --permission-mode bypassPermissions "Refactor this function"

# Interactive session (PTY required)
claude

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
95% confidence
Finding

codex exec --full-auto delegates implementation to an external coding agent in autonomous mode, creating both data-sharing and uncontrolled-change risk. In a skill about powerful local tooling, this is especially dangerous because it can chain into shell execution and repository modification.

Content

Scanner excerpt · references/03-LOCAL-POWER.md (reported line 765)May include surrounding context.

bash
# Full auto mode
codex exec --full-auto "Add user authentication"

# With yolo mode (less confirmation)
codex exec --yolo "Fix the bug in utils.py"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
96% confidence
Finding

codex exec --yolo further lowers confirmation barriers for an external coding agent, increasing the likelihood of unsafe edits, dependency additions, or command execution. The example lacks compensating controls such as sandboxing, diff review, or data-sharing warnings.

Content

Scanner excerpt · references/03-LOCAL-POWER.md (reported line 768)May include surrounding context.

codex exec --full-auto "Add user authentication"

With yolo mode (less confirmation)

codex exec --yolo "Fix the bug in utils.py"

text

From OpenClaw:

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Selecting a specific external model/provider via kilo run --model claude-sonnet-4 is not inherently malicious, but it does create undisclosed third-party processing and model-routing risk if used without consent boundaries. The concern is heightened because the surrounding guidance encourages broad coding delegation.

Content

Scanner excerpt · references/03-LOCAL-POWER.md (reported line 837)May include surrounding context.

kilo run "Implement pagination"

Run with specific model

kilo run --model claude-sonnet-4 "Complex refactoring"

text

### Agentic Coding Examples

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

The example constructs shell commands with interpolated variables in paths, such as /tmp/pr-${pr}-review, and executes them directly. Even if pr looks numeric in the sample, this pattern normalizes command construction without validation or escaping and can become command/path injection if adapted to less trusted inputs.

Content

Scanner excerpt · references/03-LOCAL-POWER.md (reported line 927)May include surrounding context.

await postPRReview(pr, log);

// Cleanup await exec({ command: git worktree remove /tmp/pr-${pr}-review }); }

text

Static analysis

Detected: suspicious.destructive_delete_command, suspicious.exposed_secret_literal

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/01-FOUNDATIONS.md:774

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/05-VPS-EMPLOYEE.md:173