Back to skill

Security audit

OpenClaw Safe Ops

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to make OpenClaw operations safer, but it tells agents to run an unbundled relative wrapper script and has rollback instructions that may restore the wrong file.

Review this skill carefully before installing. Do not run the suggested ./scripts/openclaw-safe.sh unless you have independently verified that exact script and its location. If using the manual workflow, fix the rollback commands so they restore the specific backup created immediately before the change, and confirm copy operations succeed before restarting OpenClaw.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:32
Finding

Unbundled Relative Wrapper May Execute Attacker-Controlled Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 32–36
Vulnerability Type: Tool hijacking through an unverified working-directory-relative executable
Risk Level: High

Vulnerable Code:

markdown
## Preferred Command Wrapper

For local terminal operations, prefer:

- `./scripts/openclaw-safe.sh <openclaw args...>`

This wrapper auto-backs up config for risky actions, runs health checks, and rolls back on failure.

Technical Analysis

The Skill recommends executing ./scripts/openclaw-safe.sh, but the audited package contains only SKILL.md and publish.json. The referenced script is not included in the package.

Because the path begins with ./, it resolves relative to the agent's current working directory rather than to a verified Skill installation directory. An attacker who controls the current project or working directory can create a malicious file at scripts/openclaw-safe.sh. If the agent follows the recommendation, that attacker-controlled script will execute as though it were the trusted safety wrapper.

Attack Path

  1. An attacker creates an executable scripts/openclaw-safe.sh in a repository or directory processed by the agent.
  2. The user requests a high-risk OpenClaw operation covered by this Skill.
  3. The agent follows the preferred-wrapper instruction and runs ./scripts/openclaw-safe.sh.
  4. Path resolution selects the attacker's script from the current working directory.
  5. The malicious script executes with the same operating-system permissions and environment access as the agent or user.

Impact Assessment

Successful exploitation permits arbitrary command execution with the invoking agent's privileges. The attacker may read or modify files accessible to that account, including OpenClaw configuration, tamper with plugins or gateway operations, access available environment variables, and perform other actions allowed to the current user.

This iss ...[truncated 172 chars]

Remediation
View remediation

Remediation Suggestions

  • Bundle the wrapper in the published package and subject its contents to security review.
  • Resolve the wrapper from a trusted, absolute Skill installation path rather than from the current working directory.
  • Before execution, verify that the wrapper is a regular file owned by an expected principal and is not a symbolic link.
  • Verify the wrapper against a pinned cryptographic digest or signed manifest.
  • Refuse execution when the verified packaged wrapper cannot be found; do not fall back to a same-named script in the current directory.
  • If a trusted wrapper cannot be shipped, remove this recommendation and document the required OpenClaw commands explicitly.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Rollback Restores a Different File Than the Preflight Backup

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–28
Vulnerability Type: Inconsistent backup and rollback paths
Risk Level: Medium

Vulnerable Code:

markdown
## Safety Workflow

1. Capture a backup before change:
   - `cp ~/.openclaw/openclaw.json ~/.openclaw/openclaw.json.manual.$(date +%Y%m%d-%H%M%S).bak`
2. Run the intended command.
3. Validate immediately:
   - `openclaw channels status --probe`
   - `openclaw status --deep`
4. If checks fail, rollback:
   - `cp ~/.openclaw/openclaw.json.bak ~/.openclaw/openclaw.json`
   - `openclaw gateway restart`
   - `openclaw status --deep`

Technical Analysis

The preflight operation creates a timestamped backup named openclaw.json.manual.<timestamp>.bak. The rollback operation does not restore that file; instead, it reads the fixed path openclaw.json.bak.

The fixed rollback source may not exist, may contain stale configuration, or may have been created for an unrelated operation. Consequently, the documented workflow does not guarantee restoration of the state captured immediately before the risky change. It also proceeds to restart the gateway without first requiring confirmation that the copy succeeded.

Attack Path

  1. The workflow creates a current timestamped backup.
  2. A configuration, plugin, or gateway operation causes health checks to fail.
  3. The rollback step attempts to copy openclaw.json.bak rather than the newly created timestamped backup.
  4. If the fixed file is absent, restoration fails; if it is stale or inappropriate, unrelated configuration is restored.
  5. The workflow restarts the gateway with the failed, stale, or otherwise unintended configuration.
  6. OpenClaw may remain unavailable or operate with outdated security and service settings.

Impact Assessment

The issue can cause loss of configuration integrity and service availability. It may revert unrelated settings, reintroduce ob ...[truncated 345 chars]

Remediation
View remediation

Remediation Suggestions

  • Save the exact generated backup path in a safely quoted variable and use that same variable during rollback.
  • Verify that the backup exists, is a regular file, has expected ownership and permissions, and contains valid configuration before restoring it.
  • Quote all filesystem paths and use restrictive file permissions for backups.
  • Stop the rollback sequence immediately if restoration fails; do not restart the gateway after an unsuccessful copy.
  • Validate the restored configuration before restarting the gateway.
  • Report the exact backup path and restoration result so operators can verify that rollback used the intended snapshot.

A hardened workflow should follow this pattern:

sh
backup="$HOME/.openclaw/openclaw.json.manual.$(date +%Y%m%d-%H%M%S).bak"
cp -- "$HOME/.openclaw/openclaw.json" "$backup" || exit 1

# Run the intended operation and health checks.

if ! cp -- "$backup" "$HOME/.openclaw/openclaw.json"; then
    echo "Rollback failed; gateway will not be restarted." >&2
    exit 1
fi

openclaw gateway restart
openclaw status --deep
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes the skill as guarding a limited set of high-risk operations, but the embedded SKILL.md broadens coverage to additional commands including gateway install/uninstall/run/status and plugin enable/disable. This creates a scope mismatch that can cause an agent or user to apply the skill in contexts not disclosed in the published metadata, reducing reviewability and potentially enabling risky operational guidance to be used more broadly than intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.