Back to skill

Security audit

OpenClaw Emergency Rollback

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its rollback purpose, but it needs review because it installs persistent recovery hooks and can automatically overwrite OpenClaw configuration with weak safeguards.

Install only if you intentionally want a persistent local rollback system that can overwrite OpenClaw config and restart the gateway after a timer expires. Before using it on production systems, restrict rollback directory permissions, review what openclaw.json contains, validate snapshot contents before restore, avoid arbitrary shell restart commands, and make sure you have independent terminal access for manual recovery.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/restore.mjs:17
Finding

Arbitrary Shell Command Execution Through Mutable Restart Configuration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/restore.mjs:21
Finding

Unvalidated Snapshot Archive Selection and Extraction to the Filesystem Root

Content
View full analysis
s.slot === SLOT); const snapFile = snapInfo ? snapInfo.file : `snapshot-${SLOT}.tar.gz`; const snapLabel = snapInfo ? snapInfo.label : 'unknown'; const snapTs = snapInfo ? snapInfo.timestamp : 'unknown'; const zipPath = join(SNAPSHOTS_DIR, snapFile); ``` ```js // Restore files — unzip with full path overwrite to / let unzipExit = 0; try { execSync(`tar -xzf "${zipPath}" -C /`, { stdio: 'ignore' }); } catch (e) { unzipExit = e.status || 1; appendLog(RESTORE_LOG, `RESTORE WARNING — unzip exit code: ${unzipExit}`); } ``` ### Technical Analysis The archive filename comes from the mutable `manifest.json` file and is passed to `join(SNAPSHOTS_DIR, snapFile)` without validating that it is one of the expected snapshot filenames. A value containing traversal components can resolve outside the snapshots directory. The selected archive is then extracted directly into `/`. The implementation does not inspect archive entries before extraction and does not reject: - Absolute archive paths - `..` traversal components - Symbolic or hard links - Unexpected files outside the documented OpenClaw configuration paths - Entries targeting scripts or hooks This creates two related trust failures: the manifest can redirect restoration to an unintended archive, and a modified archive can attempt to overwrite arbitrary locations writable by the OpenClaw account. In addition, extraction failure is caught but treated only as a warning. The script subsequently disarms the watchdog and restarts the gateway, potentially leaving a partial or failed restoration with no automatic retry. ### Attack Path 1. An attacker gains write access to `manifest.json`, a snapshot archive, or another file readable by ...[truncated 1315 chars]
Remediation
View remediation
3) { throw new Error('Invalid snapshot slot'); } ``` 2. Derive the filename exclusively from the validated slot. Do not trust the manifest’s `file` property: ```js const snapFile = `snapshot-${SLOT}.tar.gz`; ``` 3. Resolve the archive path and enforce directory containment with `path.resolve` and `path.relative`. 4. List and inspect all archive entries before extraction. Reject entries that: - Are absolute - Contain `..` - Are symbolic or hard links - Fall outside the exact documented destination allowlist 5. Extract into a newly created private temporary directory rather than `/`. 6. Validate extracted file types, names, and destinations, then copy only allowlisted files to their final paths using filesystem APIs. 7. Verify archive integrity using a trusted digest stored separately with restrictive permissions. 8. Abort immediately on any extraction or validation error. Do not disarm the watchdog or restart the gateway after a partial or failed restoration. 9. Apply restrictive ownership and permissions to the manifest and snapshot directory. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/snapshot.mjs:55
Finding

Gateway Credentials Are Stored in Plaintext Snapshot Archives Without Enforced Access Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

Even though the matched pattern duplicates the same line, the underlying issue remains a real hazard: rm -rf is an unsafe primitive in human-run instructions and can be catastrophic if the home directory or path is resolved unexpectedly. The context makes it more sensitive because administrators using rollback tooling may assume the docs are safe and run destructive steps quickly during maintenance or recovery.

Content

Scanner excerpt · references/SETUP.md (reported line 204)May include surrounding context.

md
If the user wants to reinstall from scratch:
1. Back up existing snapshots: `cp -r ~/.openclaw/rollback/snapshots/ /tmp/openclaw-snapshots-backup/`
2. `rm -rf ~/.openclaw/rollback/`
3. Remove any old startup hook that points at a previous rollback install, if present.
4. Run setup again from Step 1.
5. Ask the user if they want their old snapshots restored from the backup.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

Even though the matched pattern duplicates the same line, the underlying issue remains a real hazard: rm -rf is an unsafe primitive in human-run instructions and can be catastrophic if the home directory or path is resolved unexpectedly. The context makes it more sensitive because administrators using rollback tooling may assume the docs are safe and run destructive steps quickly during maintenance or recovery.

Content

Scanner excerpt · references/SETUP.md (reported line 204)May include surrounding context.

md
If the user wants to reinstall from scratch:
1. Back up existing snapshots: `cp -r ~/.openclaw/rollback/snapshots/ /tmp/openclaw-snapshots-backup/`
2. `rm -rf ~/.openclaw/rollback/`
3. Remove any old startup hook that points at a previous rollback install, if present.
4. Run setup again from Step 1.
5. Ask the user if they want their old snapshots restored from the backup.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

Even though the matched pattern duplicates the same line, the underlying issue remains a real hazard: rm -rf is an unsafe primitive in human-run instructions and can be catastrophic if the home directory or path is resolved unexpectedly. The context makes it more sensitive because administrators using rollback tooling may assume the docs are safe and run destructive steps quickly during maintenance or recovery.

Content

Scanner excerpt · references/SETUP.md (reported line 204)May include surrounding context.

md
If the user wants to reinstall from scratch:
1. Back up existing snapshots: `cp -r ~/.openclaw/rollback/snapshots/ /tmp/openclaw-snapshots-backup/`
2. `rm -rf ~/.openclaw/rollback/`
3. Remove any old startup hook that points at a previous rollback install, if present.
4. Run setup again from Step 1.
5. Ask the user if they want their old snapshots restored from the backup.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes operational behaviors that read environment state, inspect local processes, and invoke local scripts, but it declares no explicit tool scope or permissions boundary. In a skill that performs file backup, restore, and restart-related actions, missing scope increases the chance the agent can invoke capabilities more broadly than intended or without clear user/auditor visibility.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
79% confidence
Finding

The skill is explicitly designed to create persistent state across sessions through snapshots, watchdog files, startup hooks, and automatic post-restart behavior. Persistent autonomous behavior is risky here because it can continue modifying local configuration after the original conversation ends, including restoring files and restarting service state based on prior instructions.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
OpenClaw Emergency Config Rollback — dead man's switch system for safely making
  risky changes to OpenClaw configuration. Use this skill whenever the user mentions
  wanting to make changes to openclaw.json or agent configs and wants a safety net,
  says anything like "set emergency recovery", "create a snapshot", "take a backup
  before changes", "set a backout timer", "restore snapshot", "accept changes",
  "test emergency recovery", "run recovery test", "how does the rollback work",
  "what rollback commands", or any variation of wanting to safely change OpenClaw

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation text is overly broad and can trigger on general discussion of recovery, rollback, backups, or explanation requests, causing a high-risk operational skill to engage in contexts where the user may only want information. Because this skill can lead to destructive testing, config overwrites, and gateway restarts, over-triggering materially raises the risk of unintended disruptive actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The command set encourages creation and retention of persistent snapshots that become future restore targets. In this context, session persistence is more dangerous than usual because stored state can later overwrite current configuration, making stale or poisoned snapshots a long-lived recovery mechanism that outlasts the initiating session.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

• "extend recovery XX minutes" — add more time to the timer • "list snapshots" — show all saved snapshots • "restore snapshot 2" — manually restore snapshot 2 or 3 • "create snapshot" — save current state as new snapshot [1]

text

---

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

This persistent restore path can overwrite the current OpenClaw configuration and trigger a gateway restart, effects that survive beyond the immediate session. In a rollback skill, persistent state is contextually more dangerous because it directly enables later destructive actions against availability and system configuration, even if the original conversation is no longer active.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
### "restore snapshot [1|2|3]"
Manually restore a specific snapshot immediately.

1. Confirm with user: "This will overwrite your current OpenClaw config with
   snapshot [N] '<label>' from <timestamp> and restart the gateway. Are you sure?"
2. On confirmation: run `~/.openclaw/rollback/scripts/restore.mjs <slot>`
3. Gateway restarts. Next session will detect uptime < 90 seconds.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The restore procedure instructs users to run unzip -o ... -d /, which forcibly overwrites files at absolute paths without any confirmation, dry run, or explicit warning about clobbering current state. In this skill's context, the archive is intended to restore OpenClaw configs, but because it preserves full paths and extracts to /, any unexpected or maliciously crafted archive contents could overwrite arbitrary files accessible to the user, making the operation materially dangerous.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/SETUP.md (reported line 30)May include surrounding context.

md
Node.js is required to run OpenClaw itself, so it is always present. If `zip`
or `unzip` are missing (common on stripped Docker images), install them:

- **Ubuntu/Debian VPS:** `sudo apt-get install -y tar gzip`
- **Docker (node:22-bookworm-slim):** Set `OPENCLAW_DOCKER_APT_PACKAGES="tar gzip"`
  in your Docker setup, or add to Dockerfile: `RUN apt-get update && apt-get install -y tar gzip`

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The setup tells the operator to provide a restart command and says it will be stored, but the generated config hardcodes kill -USR1 1 instead. In a rollback system, using the wrong restart command can cause failed recovery, unexpected signaling of PID 1, or service disruption on platforms where that signal is incorrect.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/SETUP.md (reported line 63)May include surrounding context.


Step 2 — Create Directory Structure

bash
mkdir -p ~/.openclaw/rollback/snapshots

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file advertises a 'destructive' recovery test without explaining what resources, configs, or service state it will modify, and without instructing the operator to confirm before execution. In a rollback skill, ambiguity around destructive testing can lead users to trigger service restarts, config replacement, or downtime unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The reinstall instructions include deletion of the rollback directory with rm -rf but do not place a clear, immediate warning next to the command about irreversible data loss if backups are incomplete or incorrect. In operational docs, destructive commands without strong confirmation language increase the chance of accidental deletion of snapshots or rollback state.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/TESTING.md (reported line 63)May include surrounding context.

directory is properly initialized, and that all scripts are present. If anything fails, stop and fix it before continuing.

Step 2 — Create Test Snapshot

bash
~/.openclaw/rollback/scripts/snapshot.mjs "pre-test known-good config" "Snapshot taken before recovery test."

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document first instructs operators to use the actual restart command from rollback-config.json, but the failed-test cleanup section later hard-codes kill -USR1 1. In recovery scenarios, inconsistent restart instructions can cause the service to fail to restart, restart the wrong process, or behave differently across deployments, increasing outage duration during an already disruptive destructive test.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The header comment documents the sabotage subcommand as deliberately breaking openclaw.json into invalid JSON and verify as checking whether it became valid JSON again. In reality, lines L141-L156 mutate fields and then write the file back with JSON.stringify, preserving valid JSON; the verify logic correspondingly checks for poisoned values rather than JSON restoration alone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The sabotage subcommand deliberately modifies a live configuration file in a destructive way without any interactive confirmation, dry-run guard, environment check, or explicit force flag. In the context of an emergency rollback skill, this is more dangerous because the tool is designed for operational use on real systems, so accidental invocation can break authentication and routing immediately and may cause service outage or lockout before recovery occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script executes a restart command from configuration via execSync with a bash shell, which turns a configuration value into arbitrary command execution. In the context of an emergency rollback skill that restores files to / and then restarts automatically, any attacker who can influence config or snapshot contents can gain reliable code execution during a privileged recovery path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script extracts a snapshot tarball directly to '/' with overwrite semantics, which is a safety-critical file write operation affecting the whole system. Although the file has internal comments and logging, there is no user-facing disclosure at the point of execution, and the script is explicitly designed for zero user interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The Node.js snippet reads and rewrites ~/.openclaw/rollback/watchdog.json, changing the watchdog state. While the intent is described, the documentation does not clearly warn that it edits rollback metadata on disk, which affects future recovery behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation says the system uses zip and unzip, but the checks and install commands verify tar and gzip instead, which is inconsistent and can leave operators without the tools the rollback workflow actually needs. This is primarily a reliability and recovery-readiness issue: backups or restores may fail when urgently needed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline comment on L47 says 'Restore files — unzip with full path overwrite to /', and the warning log on L53 also refers to an 'unzip exit code'. However, the implementation on L50 invokes tar -xzf, not unzip. This is a direct documentation-to-code contradiction, even though the overall restore intent is the same.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
hooks/watchdog-recovery/handler.ts:55

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/recovery-test.mjs:39

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/restore-if-armed.mjs:34

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/restore.mjs:50

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/snapshot.mjs:81

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/watchdog-clear.mjs:32

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/watchdog-set.mjs:46

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/watchdog-timer.mjs:38

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/SETUP.md:204