Back to skill

Security audit

Comprehensive skill for installing, configuring, and managing the OpenClaw ecosystem (Gateway, Channels, Models, Automation, Nodes, and Deployment)

Security checks for vulnerabilities and agentic risk

Overview

This is a broad OpenClaw admin wrapper, but its approval gate does not consistently block documented high-risk changes.

Review this before installing as an admin tool, not just a documentation skill. Treat the wrapper as convenience routing rather than a reliable safety boundary, pin and verify the OpenClaw CLI version, run it under a least-privileged account, protect gateway tokens and environment secrets, and manually confirm any command that changes config, approvals, services, agents, messaging, secrets, DNS, nodes, or browser state.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/openclaw.sh:27
Finding

High-Risk Mutations Bypass the Wrapper's Approval Gate

Content
View full analysis
/dev/null || true case "$sub" in login) openclaw channels login --channel "$@" ;; logout) openclaw channels logout --channel "$@" ;; pairing) _risky; openclaw pairing "$@" ;; *) openclaw channels "$sub" "$@" ;; esac ;; # Model routing model) sub=${1:-}; shift 2>/dev/null || true case "$sub" in auth) openclaw models auth "$@" ;; alias) openclaw models aliases "$@" ;; fallback) openclaw models fallbacks "$@" ;; *) openclaw models "$sub" "$@" ;; esac ;; # Granular-gated commands plugin) sub=${1:-} [[ "$sub" == "install" || "$sub" == "enable" ]] && _risky openclaw plugins "$@" ;; hooks) sub=${1:-} [[ "$sub" == "install" || "$sub" == "enable" ]] && _risky openclaw hooks "$@" ;; secrets) sub=${1:-} [[ "$sub" == "apply" ]] && _risky openclaw secrets "$@" ;; ``` ### Technical Analysis The wrapper advertises a least-privilege model in which high-risk actions require `OPENCLAW_WRAPPER_ALLOW_RISKY=1`. However, authorization is primarily performed at the top-level command name rather than at the complete command, subcommand, option, and RPC-method level. Several broadly forwarded commands contain ...[truncated 3090 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
scripts/openclaw.sh:27
Finding

Persistent Service Installation Is Exposed Without High-Risk Approval

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/deployment.md:5
Finding

Deployment Instructions Install an Unpinned Global npm Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
| Find a command | `references/cli-full.md` → search by keyword |

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/cli-full.md (reported line 198)May include surrounding context.

md
- `openclaw models scan [--min-params <b>] [--max-age-days <d>] [--provider <name>] [--set-default] [--set-image] [--json]`: Discover local models.

## Agents
- `openclaw agent [--message <text>] [--to <dest>] [--session-id <id>] [--agent <id>] [--channel <ch>] [--local] [--deliver] [--json] [--timeout <s>] [--thinking <off|minimal|low|medium|high|xhigh>] [--verbose <on|full|off>]`: Send message to agent.
  - `--reply-channel <ch>` + `--reply-to <dest>`: Route agent reply to a different channel/target.
  - `--thinking` only works with GPT-5.2+ and Codex models.
  - `OPENCLAW_AGENT_DIR` / `PI_CODING_AGENT_DIR` env vars also scope agent context.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
# OpenClaw Security Policy

Default stance: least privilege. Do not chain high-risk actions unattended.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/advanced-tools.md (reported line 1)May include surrounding context.

md
# OpenClaw Security Policy

Default stance: least privilege. Do not chain high-risk actions unattended.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/cli-full.md (reported line 1)May include surrounding context.

md
# OpenClaw Security Policy

Default stance: least privilege. Do not chain high-risk actions unattended.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/config-schema.md (reported line 1)May include surrounding context.

md
# OpenClaw Security Policy

Default stance: least privilege. Do not chain high-risk actions unattended.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/deployment.md (reported line 1)May include surrounding context.

md
# OpenClaw Security Policy

Default stance: least privilege. Do not chain high-risk actions unattended.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/hubs.md (reported line 1)May include surrounding context.

md
# OpenClaw Security Policy

Default stance: least privilege. Do not chain high-risk actions unattended.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/nodes-platforms.md (reported line 1)May include surrounding context.

md
# OpenClaw Security Policy

Default stance: least privilege. Do not chain high-risk actions unattended.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/prerequisites.md (reported line 1)May include surrounding context.

md
# OpenClaw Security Policy

Default stance: least privilege. Do not chain high-risk actions unattended.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/security-policy.md (reported line 1)May include surrounding context.

md
# OpenClaw Security Policy

Default stance: least privilege. Do not chain high-risk actions unattended.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/advanced-tools.md (reported line 8)May include surrounding context.

md
## Gateway RPC Methods
Use `openclaw gateway call <method> [--params <json>]` for direct RPC:
- `config.apply`: validate → write → restart → wake
- `config.patch`: merge partial update → restart → wake
- `config.get`: read current config
- `update.run`: run update → restart

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document states that secrets apply is one-way with no rollback, which is a safety-critical operation affecting system configuration and potentially user data. Although it recommends --dry-run, it does not present a clear warning or cautionary note about the consequences of proceeding or advise backup/recovery steps.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli-full.md (reported line 277)May include surrounding context.

md
## Automation (Cron)
- `openclaw cron status [--json]`: Cron engine status.
- `openclaw cron list [--all] [--json]`: List cron jobs (table by default).
- `openclaw cron add --name <name> (--at|--every|--cron) (--system-event|--message)`: Create cron job (high-risk).
  - `--announce`: announce to channel. `--deliver` / `--no-deliver`: control delivery.
  - `--at` + `--keep-after-run`: one-time job that persists after execution.
  - `--channel <ch>`, `--to <dest>`: delivery target for announce.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/cli-full.md (reported line 412)May include surrounding context.

md
## Webhooks and DNS
- `openclaw webhooks gmail setup|run [--account <email>] [--project] [--topic]`: Gmail webhook integration (high-risk).
- `openclaw dns setup [--apply]`: Local DNS setup (high-risk, `--apply` requires sudo on macOS).

## Other
- `openclaw docs [query...]`: Search docs from CLI.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/config-schema.md (reported line 25)May include surrounding context.

md
Use CLI sub-commands (not flags) to manage config:

- `openclaw config get <key>`: Read a config value.
- `openclaw config set <key> <value>`: Write a config value.
- `openclaw config unset <key>`: Remove a config value.

Interactive wizard:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Documenting shell environment import without caution can cause operators to load a broad set of sensitive environment variables into the application context unintentionally. This expands the blast radius of prompt injection, plugin compromise, logging mistakes, or debugging output because secrets unrelated to OpenClaw may become accessible to the process.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation includes inline examples showing plaintext credential values in configuration, which can normalize insecure secret handling and lead users to store live API keys directly in config files. Although one later section introduces secret references, the examples themselves lack an immediate warning that plaintext secrets in config and .env files increase the risk of credential leakage through backups, source control, logs, or local file compromise.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/config-schema.md (reported line 140)May include surrounding context.

md
- Missing/empty vars throw error at load time.
- Escape with `$${VAR}` for literal output.
- Works inside `$include` files.
- Example: `"${BASE}/v1"` → `"https://api.example.com/v1"`

## Secret Refs
Replace plaintext secrets with structured refs:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entry dns setup --apply explicitly notes macOS, sudo, indicating a privileged operation that can modify system DNS behavior, yet the markdown does not warn users about the system-wide impact or need to verify the change. Markdown descriptions should warn about operations that can affect system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The prerequisites list includes Tailscale for remote node access, but the document provides no warning that enabling remote access can affect system exposure or require careful access control. In markdown files, capabilities that may affect privacy or system integrity should include an explicit warning or caution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown documents OPENCLAW_GATEWAY_TOKEN and OPENCLAW_GATEWAY_PASSWORD as environment variables, but it does not include any warning about treating them as secrets, avoiding logging/sharing them, or the risks of exposing credentials. For markdown files, omitted warnings about behaviors affecting privacy or system integrity should be flagged when sensitive data is involved.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The top comments present the wrapper as a unified manager with a risk-checking layer, which implies protective behavior. In practice, the protection is only a soft gate controlled by OPENCLAW_WRAPPER_ALLOW_RISKY, after which the script forwards explicitly high-risk commands such as plugin enable/install, secrets apply, pairing, and dns operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.