Back to skill

Security audit

OpenClaw Dual Agent

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only OpenClaw setup guide whose agent, Telegram, and model-provider steps fit its purpose, though users should tighten credential handling when following the examples.

Install only if you intend to configure additional OpenClaw agents and Telegram bots. Use interactive onboarding where possible, avoid pasting real bot or API tokens directly into shell commands, set auth-profiles.json and openclaw.json to mode 600, and remove OpenRouter fallback or heartbeat entries if you require fully local Ollama-only operation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Telegram Bot Token Exposed Through Command-Line URL

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/troubleshooting.md:92
Finding

OpenRouter Credential File Created Without Enforcing Restrictive Permissions

Content
View full analysis
~/.openclaw/agents/free-agent/agent/auth-profiles.json <<'EOF' { "version": 1, "profiles": { "openrouter:default": { "type": "api_key", "provider": "openrouter", "key": "sk-or-v1-YOUR_OPENROUTER_KEY" } }, "lastGood": { "openrouter": "openrouter:default" } } EOF ``` ### Technical Analysis The troubleshooting procedure writes an OpenRouter API key to a plaintext JSON file but does not establish a restrictive `umask`, securely create the file, or apply `chmod 600`. The resulting permissions depend on the user's ambient umask. Although `SKILL.md:24` separately recommends mode `600` for credential files, that protection is absent from the executable recovery procedure. On systems with permissive defaults, the file may become readable by other users or groups. The key also remains directly embedded in a persistent plaintext file. ### Attack Path 1. A user follows the troubleshooting instructions on a shared or multi-user system. 2. The user's ambient umask allows group or world read access to newly created files. 3. `auth-profiles.json` is created with permissions that expose its contents to another local account or process. 4. A local attacker reads the OpenRouter API key from the file. 5. The attacker authenticates to OpenRouter using the stolen key and performs requests under the victim's account until the key is revoked. Exploitation requires local file-read access through insecure permissions, a compromised process operating as an authorized group member, or another mechanism that can inspect the file. ### Impact Assessment The attacker can obtain the OpenRouter API privileges associated with the exposed key. This may enable unauthorized model requests, consumption of account quota or credits, access ...[truncated 272 chars]
Remediation
View remediation
~/.openclaw/agents/free-agent/agent/auth-profiles.json <<'EOF' { "version": 1, "profiles": { "openrouter:default": { "type": "api_key", "provider": "openrouter", "key": "sk-or-v1-YOUR_OPENROUTER_KEY" } }, "lastGood": { "openrouter": "openrouter:default" } } EOF chmod 600 ~/.openclaw/agents/free-agent/agent/auth-profiles.json ``` - Prefer OpenClaw's interactive credential enrollment or an operating-system secret store when available. - Add a verification command such as: ```bash ls -l ~/.openclaw/agents/free-agent/agent/auth-profiles.json ``` - Never include the populated file in source control, support bundles, backups without encryption, or shared diagnostic output. - Rotate the API key if the file was previously created with broader permissions or exposed to another user. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

  1. Create two Telegram bots via @BotFather and extract chat IDs:

    bash
    curl https://api.telegram.org/bot{TOKEN}/getUpdates | jq '.result[0].message.chat.id'
    
  2. Authenticate agents:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/config-reference.md (reported line 233)May include surrounding context.

  1. Create two Telegram bots via @BotFather and extract chat IDs:

    bash
    curl https://api.telegram.org/bot{TOKEN}/getUpdates | jq '.result[0].message.chat.id'
    
  2. Authenticate agents:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Run interactively — avoids exposing keys in shell history

openclaw onboard

text
> ⚠️ Never pass API keys directly on the CLI (e.g. `--anthropic-api-key ...`) — it exposes them in shell history. Always use `openclaw onboard` interactively. Credential files (`auth-profiles.json`, `openclaw.json`) should be `chmod 600`.

3. **Configure** `openclaw.json` with two agents, separate bindings, and Telegram accounts.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
## Common Usage

**Adding a free agent:**
- Create agentDir at `/Users/YOUR_USERNAME/.openclaw/agents/free-agent/agent`
- Add agent entry to `openclaw.json` with `model.primary: "openrouter/..."`
- Create `auth-profiles.json` with OpenRouter API key in agent's directory
- Add binding with unique `accountId` (e.g., `"tg2"`)

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The troubleshooting guide explicitly directs users to persist API credentials in a local auth-profiles.json file under the agent directory. Persistent local secret storage is not inherently malicious, but without warnings, permission hardening, or a stronger preference for secret-management mechanisms, it increases the chance of credential theft from disk, backups, or accidental disclosure.

Content

Scanner excerpt · references/troubleshooting.md (reported line 89)May include surrounding context.

Cause: Missing or incorrectly placed auth-profiles.json.

Fix: Create auth-profiles.json in the free agent's agentDir:

bash
cat > ~/.openclaw/agents/free-agent/agent/auth-profiles.json <<'EOF'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs users to create an auth file containing an API key in plaintext on disk, but it does not explicitly warn that the file is sensitive secret material or recommend restrictive permissions/secure secret storage. Even though the value shown is a placeholder, the workflow normalizes storing real credentials in a local file, which increases the risk of accidental exposure through backups, screenshots, logs, world-readable permissions, or source control.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 159)May include surrounding context.

md
grep -A 2 '"id"' ~/.openclaw/openclaw.json | grep -E 'id|name'

# Test Anthropic auth (uses env var, no key in command)
curl -s https://api.anthropic.com/v1/models \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01"

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/troubleshooting.md (reported line 177)May include surrounding context.

Inspect active sessions:

bash
ls -la ~/.openclaw/agents/*/store/sessions/

Check recent logs:

Static analysis

No suspicious patterns detected.