Back to skill

Security audit

gateway-notify

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says: it installs a persistent gateway startup notification hook that sends only a timestamp, with disclosed setup prompts and uninstall instructions.

Install this only if you want a persistent OpenClaw hook that sends a message every time the gateway starts. Confirm the channel and recipient carefully, understand that the messaging provider may log metadata, use --yes only for automation you control, and uninstall by removing the hook with the provided script and restarting the gateway. Users outside the China timezone may want to adjust the timestamp formatting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill sets up automatic notifications for gateway startup/restart events. The provided code does the opposite: it is an uninstall script that deletes the hook directory at ~/.openclaw/hooks/gateway-restart-notify and informs the user the hook remains active until the gateway is restarted. It may also invoke openclaw gateway restart after confirmation. This is a materially different primary purpose from installation/setup. The permissions used are not themselves problematic, but the behavior clearly corresponds to removal/deactivation, not setup of notifications.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
scripts/setup_gateway_notify.sh <channel> <address>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
scripts/setup_gateway_notify.sh <channel> <address>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
scripts/setup_gateway_notify.sh <channel> <address>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
scripts/setup_gateway_notify.sh <channel> <address>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The manual includes a destructive rm -rf ~/.openclaw/hooks/gateway-restart-notify command. Although the path is fixed and preceded by a warning and verification step, recursive force deletion is inherently dangerous in operational documentation because copying, editing, or path expansion mistakes can delete unintended files.

Content

Scanner excerpt · references/MANUAL.md (reported line 105)May include surrounding context.

bash
# Confirm the target path first, then remove
ls -la ~/.openclaw/hooks/gateway-restart-notify
rm -rf ~/.openclaw/hooks/gateway-restart-notify
openclaw gateway restart

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The manual includes a destructive rm -rf ~/.openclaw/hooks/gateway-restart-notify command. Although the path is fixed and preceded by a warning and verification step, recursive force deletion is inherently dangerous in operational documentation because copying, editing, or path expansion mistakes can delete unintended files.

Content

Scanner excerpt · references/MANUAL.md (reported line 105)May include surrounding context.

bash
# Confirm the target path first, then remove
ls -la ~/.openclaw/hooks/gateway-restart-notify
rm -rf ~/.openclaw/hooks/gateway-restart-notify
openclaw gateway restart

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The manual includes a forceful recursive deletion command. Although the target is a narrowly scoped hook directory and the text warns the user to verify the path first, destructive shell examples are still security-relevant because path expansion mistakes, copy/paste edits, or variable substitution changes could delete unintended files.

Content

Scanner excerpt · references/MANUAL_zh.md (reported line 125)May include surrounding context.

bash
# 先确认目标路径,再删除
ls -la ~/.openclaw/hooks/gateway-restart-notify
rm -rf ~/.openclaw/hooks/gateway-restart-notify
openclaw gateway restart

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The manual includes a forceful recursive deletion command. Although the target is a narrowly scoped hook directory and the text warns the user to verify the path first, destructive shell examples are still security-relevant because path expansion mistakes, copy/paste edits, or variable substitution changes could delete unintended files.

Content

Scanner excerpt · references/MANUAL_zh.md (reported line 125)May include surrounding context.

bash
# 先确认目标路径,再删除
ls -la ~/.openclaw/hooks/gateway-restart-notify
rm -rf ~/.openclaw/hooks/gateway-restart-notify
openclaw gateway restart

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CHANGELOG.md (reported line 20)May include surrounding context.

md
- Removed false address-format-validation claim from SECURITY.md (actual validation is done by the channel CLI at runtime)

### Added
- `--yes` flag for fully non-interactive setup (CI/automation); `--force` now only skips overwrite prompt
- `--force` and `--yes` can be passed in any argument order
- Privacy confirmation is now independent of `--force` — cannot be bypassed without explicit `--yes`
- `uninstall_gateway_notify.sh` with `--force`/`--yes` support and gateway restart prompt

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SECURITY.md (reported line 22)May include surrounding context.

md
- `python3 json.dumps` encodes all user-supplied values; Python re-serializes via `json.loads` + `json.dumps` before writing to TypeScript

### File Permissions
- Hook directory created with `chmod 700` — only the owner can read or write

### Rollback on Failure
- `trap cleanup EXIT` ensures partial hook directories are removed if setup fails mid-way

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/setup_gateway_notify.sh (reported line 101)May include surrounding context.

sh
- `python3 json.dumps` encodes all user-supplied values; Python re-serializes via `json.loads` + `json.dumps` before writing to TypeScript

### File Permissions
- Hook directory created with `chmod 700` — only the owner can read or write

### Rollback on Failure
- `trap cleanup EXIT` ensures partial hook directories are removed if setup fails mid-way

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

This skill explicitly establishes a persistent gateway:startup hook that automatically sends outbound messages on every gateway restart. Even if the stated payload is only a timestamp, persistence plus automatic network egress expands attack surface, survives beyond the current session, and can be abused or modified later to exfiltrate more data or create covert signaling without repeated user awareness.

Content

Scanner excerpt · SKILL.md (reported line 6)May include surrounding context.

md
version: 2.1.5
description: "Set up automatic notifications when OpenClaw gateway restarts. Use when user wants to be notified of gateway startup events via any messaging channel (iMessage, WhatsApp, Telegram, Discord, etc.)."
permissions:
  - shell_exec      # runs setup_gateway_notify.sh to create hook files
  - file_write      # writes hook handler under ~/.openclaw/hooks/
  - hook_install    # registers a persistent gateway:startup hook
  - network_send    # hook sends outbound notification on every gateway startup

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The manual instructs the user to install a persistent startup hook under ~/.openclaw/hooks/, causing code to execute automatically on every gateway startup. Even though the documented behavior is benign notification delivery, persistence mechanisms are security-sensitive because they create an ongoing execution path with shell_exec, network_send, and restart-triggered invocation.

Content

Scanner excerpt · references/MANUAL.md (reported line 5)May include surrounding context.

Requirements: OpenClaw gateway 2026.7+, python3 in $PATH, channel CLI installed.

Step 1: Create Hook Directory

bash
mkdir -p ~/.openclaw/hooks/gateway-restart-notify

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/MANUAL.md (reported line 104)May include surrounding context.

bash
# Confirm the target path first, then remove
ls -la ~/.openclaw/hooks/gateway-restart-notify
rm -rf ~/.openclaw/hooks/gateway-restart-notify
openclaw gateway restart

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/MANUAL_zh.md (reported line 124)May include surrounding context.

bash
# Confirm the target path first, then remove
ls -la ~/.openclaw/hooks/gateway-restart-notify
rm -rf ~/.openclaw/hooks/gateway-restart-notify
openclaw gateway restart

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a hook directory and registering a startup-triggered handler under the user's OpenClaw hooks path. Persistence is especially relevant here because the skill has shell execution and network notification context, so compromise of the installed hook could be abused repeatedly on each gateway restart.

Content

Scanner excerpt · references/MANUAL_zh.md (reported line 8)May include surrounding context.

步骤 1:创建钩子目录

bash
mkdir -p ~/.openclaw/hooks/gateway-restart-notify
chmod 700 ~/.openclaw/hooks/gateway-restart-notify

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

This duplicate finding points to the same persistence behavior: creating a hook directory and registering a startup-triggered handler under the user's OpenClaw hooks path. Persistence is especially relevant here because the skill has shell execution and network notification context, so compromise of the installed hook could be abused repeatedly on each gateway restart.

Content

Scanner excerpt · references/MANUAL_zh.md (reported line 8)May include surrounding context.

步骤 1:创建钩子目录

bash
mkdir -p ~/.openclaw/hooks/gateway-restart-notify
chmod 700 ~/.openclaw/hooks/gateway-restart-notify

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/MANUAL.md (reported line 9)May include surrounding context.

bash
mkdir -p ~/.openclaw/hooks/gateway-restart-notify
chmod 700 ~/.openclaw/hooks/gateway-restart-notify

步骤 2:创建 HOOK.md

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/MANUAL_zh.md (reported line 9)May include surrounding context.

bash
mkdir -p ~/.openclaw/hooks/gateway-restart-notify
chmod 700 ~/.openclaw/hooks/gateway-restart-notify

步骤 2:创建 HOOK.md

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated TypeScript handler formats the startup time using the hard-coded locale "zh-CN" and timezone "Asia/Shanghai". This imposes a specific language/locale choice on all users and matches the policy's example of a locale constraint without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example hard-codes zh-CN and Asia/Shanghai when formatting the notification timestamp. This is a natural-language/locale policy concern because it imposes a specific locale on all users rather than offering a choice or documenting that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

L053 的 toLocaleString("zh-CN", { timeZone: "Asia/Shanghai" ... }) 将输出语言和时区固定为特定区域设置。文档未说明该技能仅面向中国地区用户,也未提供用户可配置的语言/时区选项,因此属于自然语言/区域策略上的硬编码限制。

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/MANUAL_zh.md:125

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/MANUAL.md:105