Back to skill

Security audit

OpenClaw Docker Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly documents Docker setup, but it also includes instructions that can expose OpenClaw on broader networks and install a persistent host service, so it needs careful review before use.

Install only if you are comfortable reviewing and running Docker/Tailscale commands with administrator privileges. Keep the gateway bound to localhost and use Tailscale Serve or MagicDNS for remote access, avoid the broad ufw allow rule, do not run the global systemd service section unless you intentionally want host-level persistence, pin container images or npm versions where possible, protect .env with restrictive permissions, and avoid mounting host credential directories into the container unless you fully trust the image.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T06 · System Persistence

Error
Location
references/troubleshooting.md:321
Finding

Boot-Persistent OpenClaw Service Exceeds the Docker Deployment Scope

Content
View full analysis
/dev/null << EOF [Unit] Description=OpenClaw Gateway After=network.target [Service] Type=simple User=$USER ExecStart=/usr/bin/node $(npm prefix -g)/bin/openclaw gateway --bind lan --port 18789 Restart=on-failure RestartSec=5 [Install] WantedBy=multi-user.target EOF sudo systemctl daemon-reload sudo systemctl enable openclaw sudo systemctl start openclaw sudo systemctl status openclaw ``` ``` ### Technical Analysis The instructions globally install OpenClaw, use root privileges to write a systemd unit under `/etc/systemd/system`, configure automatic restart, and enable the service at boot. Although the service process is configured to run as the invoking user rather than root, creating and enabling the unit requires administrative privileges and gives the installed package a durable host execution path. This behavior exceeds the minimum privileges necessary for the Skill's declared purpose, which is running OpenClaw inside Docker. A host-level global installation and boot-enabled service bypass the intended container boundary and persist across terminal sessions and system restarts. The service also starts the gateway with `--bind lan`, increasing its network exposure relative to a localhost-only deployment. The globally installed npm package is not pinned to a reviewed version, so the persistent executable may change depending on the package version available when the user follows the instructions. ### Attack Path 1. A user follows the Docker-to-global migration instructions. 2. `npm install -g openclaw` installs the currently published, unpinned package. 3. Root privileges are used to create a sys ...[truncated 1027 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/docker-config.md:8
Finding

Mutable Container Tags and Unpinned Global Package Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/docker-config.md:148
Finding

Recursive World-Readable Permissions Can Expose OpenClaw State

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/troubleshooting.md:111
Finding

Tailscale Troubleshooting Guidance Can Expose the Gateway on Untrusted Networks

Content
View full analysis
18789/tcp` 5. **Check firewall allows 18789:** ```bash sudo ufw status sudo ufw allow 18789/tcp ``` ``` Related raw-IP guidance uses plaintext HTTP: ```text http://TAILSCALE_IP:18789 ``` ### Technical Analysis The expected `0.0.0.0` mapping indicates that Docker should listen on every host interface, not only the Tailscale interface. The command `ufw allow 18789/tcp` permits inbound traffic to the port from any source unless other firewall policy overrides it. This guidance contradicts the safer Compose template, which binds the gateway to `127.0.0.1`, and the primary recommendation to use `tailscale serve`. A broad Docker mapping plus an unrestricted firewall rule may expose the gateway through Ethernet, Wi-Fi, cloud public interfaces, or other untrusted networks. The raw-IP fallback also uses HTTP. Gateway tokens placed in query strings may be exposed through browser history, logs, screenshots, referrer behavior, or network observation where traffic is not encrypted. ### Attack Path 1. A user cannot access the service through Tailscale. 2. Following the troubleshooting instructions, the user changes or accepts a Docker mapping on `0.0.0.0`. 3. The user runs `sudo ufw allow 18789/tcp`. 4. Port 18789 becomes reachable on every host interface allowed by upstream routing or security-group rules. 5. An attacker on the local network—or potentially the public internet on an exposed host—connects to the gateway. 6. The attacker attempts token theft, authentication attacks, or exploitation of gateway vulnerabilities over the directly exposed service. ### Impact Assessment The gateway may become remotely reachable from networks out ...[truncated 438 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (83)

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The instruction to place the onboard token into docker-compose.yml or .env creates a credential-handling risk because secrets stored in plaintext files are commonly leaked via shell history, backups, repository commits, or permissive file permissions. Given the skill explicitly uses tokens for access control, compromise of that token may grant remote access to the service.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

text

3. **Create `docker-compose.yml`** using the token from onboard.
   See `references/docker-config.md` for the full template and .env setup.

4. **Start the container:**
   ```bash

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-config.md (reported line 179)May include surrounding context.

bash
# Install
curl -fsSL https://pkgs.tailscale.com/stable/ubuntu/noble.noarmor.gpg | \
  sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg >/dev/null

curl -fsSL https://pkgs.tailscale.com/stable/ubuntu/noble.tailscale-keyring.list | \
  sudo tee /etc/apt/sources.list.d/tailscale.list

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-config.md (reported line 181)May include surrounding context.

bash
# Install
curl -fsSL https://pkgs.tailscale.com/stable/ubuntu/noble.noarmor.gpg | \
  sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg >/dev/null

curl -fsSL https://pkgs.tailscale.com/stable/ubuntu/noble.tailscale-keyring.list | \
  sudo tee /etc/apt/sources.list.d/tailscale.list

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/docker-config.md (reported line 184)May include surrounding context.

md
curl -fsSL https://pkgs.tailscale.com/stable/ubuntu/noble.tailscale-keyring.list | \
  sudo tee /etc/apt/sources.list.d/tailscale.list

sudo apt-get update && sudo apt-get install tailscale

# Connect
sudo tailscale up

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
print_success "Docker and Docker Compose are installed"
}

# Check .env file
check_env() {
    if [ ! -f .env ]; then
        print_error ".env file not found!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-config.md (reported line 60)May include surrounding context.

md
print_success "Docker and Docker Compose are installed"
}

# Check .env file
check_env() {
    if [ ! -f .env ]; then
        print_error ".env file not found!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-setup.sh (reported line 57)May include surrounding context.

sh
print_success "Docker and Docker Compose are installed"
}

# Check .env file
check_env() {
    if [ ! -f .env ]; then
        print_error ".env file not found!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-setup.sh (reported line 59)May include surrounding context.

sh
print_success "Docker and Docker Compose are installed"
}

# Check .env file
check_env() {
    if [ ! -f .env ]; then
        print_error ".env file not found!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-setup.sh (reported line 60)May include surrounding context.

sh
print_success "Docker and Docker Compose are installed"
}

# Check .env file
check_env() {
    if [ ! -f .env ]; then
        print_error ".env file not found!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-setup.sh (reported line 62)May include surrounding context.

sh
print_success "Docker and Docker Compose are installed"
}

# Check .env file
check_env() {
    if [ ! -f .env ]; then
        print_error ".env file not found!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-setup.sh (reported line 74)May include surrounding context.

sh
print_success "Docker and Docker Compose are installed"
}

# Check .env file
check_env() {
    if [ ! -f .env ]; then
        print_error ".env file not found!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-setup.sh (reported line 78)May include surrounding context.

sh
print_success "Docker and Docker Compose are installed"
}

# Check .env file
check_env() {
    if [ ! -f .env ]; then
        print_error ".env file not found!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-setup.sh (reported line 81)May include surrounding context.

sh
print_success "Docker and Docker Compose are installed"
}

# Check .env file
check_env() {
    if [ ! -f .env ]; then
        print_error ".env file not found!"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-setup.sh (reported line 63)May include surrounding context.

sh
print_error ".env file not found!"
        echo ""
        echo "Please create a .env file with your configuration:"
        echo "  cp .env.example .env"
        echo "  nano .env"
        echo ""
        echo "Required variables:"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/docker-setup.sh (reported line 64)May include surrounding context.

sh
print_error ".env file not found!"
        echo ""
        echo "Please create a .env file with your configuration:"
        echo "  cp .env.example .env"
        echo "  nano .env"
        echo ""
        echo "Required variables:"

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The script reads the gateway token from .env and embeds a partially masked version in URLs shown to the user. Even partial secret disclosure increases exposure through terminal logs, screenshots, shell history capture, support transcripts, or multi-user systems; combined with Tailscale remote access, it also advertises the protected endpoint and part of its bearer token.

Content

Scanner excerpt · references/docker-setup.sh (reported line 170)May include surrounding context.

sh
# Show status and access info
show_info() {
    # Get token from .env (masked for display)
    TOKEN=$(grep OPENCLAW_GATEWAY_TOKEN .env | cut -d '=' -f2)
    MASKED_TOKEN="${TOKEN:0:8}...${TOKEN: -4}"

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Constructing and displaying MASKED_TOKEN from a real secret is a form of credential handling that unnecessarily reveals token fragments. Partial leaks can aid token correlation, reduce search space in some contexts, and create durable exposure in logs or recordings.

Content

Scanner excerpt · references/docker-setup.sh (reported line 171)May include surrounding context.

sh
# Show status and access info
show_info() {
    # Get token from .env (masked for display)
    TOKEN=$(grep OPENCLAW_GATEWAY_TOKEN .env | cut -d '=' -f2)
    MASKED_TOKEN="${TOKEN:0:8}...${TOKEN: -4}"
    
    # Get Tailscale IP if available

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The Tailscale setup path reads the gateway token from .env in order to display remote access information, again coupling remote reachability with secret-derived output. In the context of enabling network exposure over Tailscale, even masked token handling is more sensitive because it helps operators or observers identify the exact remote service and associated credential scheme.

Content

Scanner excerpt · references/docker-setup.sh (reported line 280)May include surrounding context.

sh
echo ""
    
    TAILSCALE_IP=$(tailscale ip -4)
    TOKEN=$(grep OPENCLAW_GATEWAY_TOKEN .env | cut -d '=' -f2)
    
    MASKED_TOKEN="${TOKEN:0:4}...[redacted]"

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The guide instructs users to place long-lived API keys and gateway tokens into a plaintext .env file, which creates a clear credential exposure risk if the file is later copied, backed up, mounted broadly into containers, or accidentally committed. In this Docker setup context, credential handling is especially sensitive because the skill explicitly relies on multiple external service tokens and local filesystem persistence.

Content

Scanner excerpt · references/quickstart.md (reported line 19)May include surrounding context.

2. Create .env file

bash
cat > .env << 'EOF'
# AI Model API Key (REQUIRED - at least one)
ANTHROPIC_API_KEY=sk-ant-api03-your-key-here
# OPENAI_API_KEY=sk-your-key-here

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

sudo rm /etc/systemd/system/openclaw.service is a destructive file-operation on a privileged path and can be abused or misapplied if the path is edited incorrectly. Even though labeled optional cleanup, it permanently removes service configuration and can disrupt availability or recovery.

Content

Scanner excerpt · references/troubleshooting.md (reported line 304)May include surrounding context.

Cleanup (optional):

bash
# Remove systemd service files
sudo rm /etc/systemd/system/openclaw.service
sudo systemctl daemon-reload

# Or uninstall global OpenClaw

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
This skill involves elevated privileges and credential management. Review before running:

- **sudo operations** — All Docker setup commands require elevated trust. Review `references/docker-setup.sh` before executing.
- **Tailscale remote access** — Enables network access to your OpenClaw instance. Ensure your Tailscale network policy allows this and review your firewall rules.
- **Credential mounting** — Mounting `~/.config/gh` or other credential directories into containers exposes them to the container image. Only do this if you fully trust the image source.
- **Host file exposure** — Volume mounts give containers access to host files. Be careful which directories you mount and which containers you run.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
This skill involves elevated privileges and credential management. Review before running:

- **sudo operations** — All Docker setup commands require elevated trust. Review `references/docker-setup.sh` before executing.
- **Tailscale remote access** — Enables network access to your OpenClaw instance. Ensure your Tailscale network policy allows this and review your firewall rules.
- **Credential mounting** — Mounting `~/.config/gh` or other credential directories into containers exposes them to the container image. Only do this if you fully trust the image source.
- **Host file exposure** — Volume mounts give containers access to host files. Be careful which directories you mount and which containers you run.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/docker-config.md (reported line 182)May include surrounding context.

md
This skill involves elevated privileges and credential management. Review before running:

- **sudo operations** — All Docker setup commands require elevated trust. Review `references/docker-setup.sh` before executing.
- **Tailscale remote access** — Enables network access to your OpenClaw instance. Ensure your Tailscale network policy allows this and review your firewall rules.
- **Credential mounting** — Mounting `~/.config/gh` or other credential directories into containers exposes them to the container image. Only do this if you fully trust the image source.
- **Host file exposure** — Volume mounts give containers access to host files. Be careful which directories you mount and which containers you run.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/docker-config.md (reported line 184)May include surrounding context.

md
This skill involves elevated privileges and credential management. Review before running:

- **sudo operations** — All Docker setup commands require elevated trust. Review `references/docker-setup.sh` before executing.
- **Tailscale remote access** — Enables network access to your OpenClaw instance. Ensure your Tailscale network policy allows this and review your firewall rules.
- **Credential mounting** — Mounting `~/.config/gh` or other credential directories into containers exposes them to the container image. Only do this if you fully trust the image source.
- **Host file exposure** — Volume mounts give containers access to host files. Be careful which directories you mount and which containers you run.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/docker-config.md (reported line 187)May include surrounding context.

md
This skill involves elevated privileges and credential management. Review before running:

- **sudo operations** — All Docker setup commands require elevated trust. Review `references/docker-setup.sh` before executing.
- **Tailscale remote access** — Enables network access to your OpenClaw instance. Ensure your Tailscale network policy allows this and review your firewall rules.
- **Credential mounting** — Mounting `~/.config/gh` or other credential directories into containers exposes them to the container image. Only do this if you fully trust the image source.
- **Host file exposure** — Volume mounts give containers access to host files. Be careful which directories you mount and which containers you run.

Static analysis

No suspicious patterns detected.