Back to skill

Security audit

OpenClaw Guide Maintenance

Security checks for vulnerabilities and agentic risk

Overview

This appears to be legitimate OpenClaw maintenance documentation, but it recommends unsafe install/update commands and a troubleshooting step that can expose secrets.

Review the install and update commands before using this skill. Prefer pinned packages or downloaded installers with checksum/signature verification, avoid running network responses directly through a shell, and do not let an agent print or paste ~/.openclaw/.env or other credential files. Treat daemon, cron, plugin, browser, and remote-access setup as privileged administrative actions that should remain under explicit user control.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:277
Finding

Unverified Remote Installer Is Streamed Directly Into Command Interpreters

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
install.md:40
Finding

Mutable Package Versions and Executable Lifecycle Scripts Create Supply-Chain Risk

Content
View full analysis
`) run untrusted code: - Install path: `~/.openclaw/extensions//` - OpenClaw uses `npm pack` then `npm install --omit=dev` (lifecycle scripts execute during install) - Prefer pinned, exact versions (`@scope/pkg@1.2.3`) - Inspect unpacked code on disk before enabling ``` ### Technical Analysis The main installation instructions use the mutable `latest` tag, while plugin examples use package names without exact versions. This means that identical documented commands may install different code over time. The instructions also recommend globally approving build scripts. Package installation and lifecycle scripts are code-execution boundaries: a compromised maintainer account, registry compromise, malicious transitive dependency, or hostile future package release can execute commands during installation. The security guide correctly advises exact version pinning and inspection, but the primary installation and plugin examples do not consistently apply that guidance. A `--pin` option records an exact resolved version but does not, by itself, authenticate the first package that is resol ...[truncated 1404 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
gateway_ops.md:290
Finding

Troubleshooting Procedure Prints the Entire Secrets Environment File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (120)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Referencing openclaw update in an operational skill exposes a self-modification path where the managed software can change version, behavior, or dependencies during a support flow. In an autonomous or semi-autonomous agent context, self-updates are risky because they can introduce unreviewed code changes and destabilize the environment mid-session.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
openclaw channels status --probe   # Channel health check
openclaw security audit            # Security posture check
openclaw security audit --fix      # Auto-fix security issues
openclaw update                    # Self-update
openclaw dashboard                 # Open Control UI in browser
openclaw tui                       # Terminal UI (interactive REPL)
openclaw agent                     # Direct agent interaction via CLI

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

curl -fsSL https://openclaw.ai/install.sh | bash fetches remote content and immediately executes it without local inspection, signature verification, or pinning. This is dangerous because compromise of the remote host, TLS interception edge cases, or supply-chain tampering could result in arbitrary code execution on the operator's machine.

Content

Scanner excerpt · SKILL.md (reported line 279)May include surrounding context.

bash
# Install (recommended)
curl -fsSL https://openclaw.ai/install.sh | bash

# Update
openclaw update                    # Self-update command

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash pattern is a classic command-chaining hazard because it converts network input directly into shell execution in one step. In an agent skill, this is especially dangerous because it reduces opportunities for human review and makes accidental or automated arbitrary code execution more likely.

Content

Scanner excerpt · SKILL.md (reported line 279)May include surrounding context.

bash
# Install (recommended)
curl -fsSL https://openclaw.ai/install.sh | bash

# Update
openclaw update                    # Self-update command

Self-Modification

High
Category
Rogue Agent
Confidence
93% confidence
Finding

This section combines installation/update guidance with direct upgrade commands, including self-update and package-manager upgrade paths, making code and dependency changes a first-class recommended action. In agent-driven maintenance workflows, this materially increases the chance of unreviewed self-modification or environment drift, especially if invoked as a generic fix step.

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

md
curl -fsSL https://openclaw.ai/install.sh | bash

# Update
openclaw update                    # Self-update command
# Or: npm install -g openclaw@latest
openclaw doctor                    # Run after update to apply migrations

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · browser.md (reported line 195)May include surrounding context.

md
| Endpoint | Description |
|---|---|
| `GET /`, `POST /start`, `POST /stop` | Status/start/stop |
| `GET /tabs`, `POST /tabs/open`, `POST /tabs/focus`, `DELETE /tabs/:targetId` | Tab control |
| `GET /snapshot`, `POST /screenshot` | Snapshot/screenshot |
| `POST /navigate`, `POST /act` | Navigation and actions |
| `POST /hooks/file-chooser`, `POST /hooks/dialog` | Hooks |

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · channel_troubleshooting.md (reported line 172)May include surrounding context.

md
# Step 3: Generate invite URL with scopes: bot, applications.commands
# Permissions: View Channels, Send Messages, Read Message History, Embed Links, Attach Files

# Step 4: Enable Developer Mode
# User Settings → Advanced → Developer Mode → On
# Right-click server → Copy Server ID
# Right-click avatar → Copy User ID

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The document instructs users to fetch and execute a remote script directly from the network. This creates a strong supply-chain risk because any compromise of the source, CDN, DNS, or TLS termination can turn installation into arbitrary code execution on the user's machine.

Content

Scanner excerpt · gateway_ops.md (reported line 208)May include surrounding context.

bash
# Installer script (macOS / Linux)
curl -fsSL https://openclaw.ai/install.sh | bash

# npm
npm install -g openclaw@latest

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash pipeline turns an external network response directly into shell execution, eliminating any review boundary and making exploitation immediate if the upstream content is malicious or tampered with. In a gateway administration guide, this is especially dangerous because operators are likely to run it on privileged or always-on hosts.

Content

Scanner excerpt · gateway_ops.md (reported line 208)May include surrounding context.

bash
# Installer script (macOS / Linux)
curl -fsSL https://openclaw.ai/install.sh | bash

# npm
npm install -g openclaw@latest

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The instructions recommend cat ~/.openclaw/.env, which can print live API keys and tokens directly to the terminal, shell history capture tools, logs, screen shares, or support transcripts. Because this skill concerns a gateway handling multi-channel integrations, the .env file likely contains sensitive credentials whose disclosure can enable account takeover or service abuse.

Content

Scanner excerpt · gateway_ops.md (reported line 297)May include surrounding context.

md
# 1. Validate the config
openclaw config validate

# 2. Check .env has real values (no placeholders)
cat ~/.openclaw/.env

# 3. Full restart (not just hot-reload)

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

This finding is part of the same unsafe guidance to display the entire .env contents for validation. Exposing secrets in plaintext is especially risky in troubleshooting workflows where users may copy terminal output into tickets, chat, or LLM prompts.

Content

Scanner excerpt · gateway_ops.md (reported line 298)May include surrounding context.

md
openclaw config validate

# 2. Check .env has real values (no placeholders)
cat ~/.openclaw/.env

# 3. Full restart (not just hot-reload)
openclaw gateway restart

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The command downloads a script from an external host and immediately executes it with bash, giving the remote content full code-execution capability on the user's machine. In an installation guide for gateway software that may handle credentials, sessions, and daemon setup, this is especially dangerous because compromise could lead to host takeover and theft of tokens or configuration secrets.

Content

Scanner excerpt · install.md (reported line 26)May include surrounding context.

bash
# macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash

# Windows (PowerShell)
iwr -useb https://openclaw.ai/install.ps1 | iex

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The | bash pipeline removes any opportunity for review between download and execution, turning a network fetch directly into command execution. Combined with the adjacent PowerShell iex example, the documentation normalizes dangerous command chaining that could be abused if the remote endpoint or transport is compromised.

Content

Scanner excerpt · install.md (reported line 26)May include surrounding context.

bash
# macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash

# Windows (PowerShell)
iwr -useb https://openclaw.ai/install.ps1 | iex

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This variant still fetches a remote installer script and pipes it directly into bash, only adding arguments to alter onboarding behavior. The same arbitrary-code-execution risk remains, with no integrity check or explicit trust boundary, so an attacker controlling the script source or delivery path could run commands immediately.

Content

Scanner excerpt · install.md (reported line 35)May include surrounding context.

Skip the onboarding wizard with --no-onboard:

bash
curl -fsSL https://openclaw.ai/install.sh | bash -s -- --no-onboard

npm / pnpm

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Recommending users re-run a remote installer script during updates repeats the same unsafe pattern and may expose already-installed systems to fresh arbitrary code execution. Because updates often occur on long-lived gateway hosts, compromise at update time could affect production credentials, service configuration, and connected channels.

Content

Scanner excerpt · install.md (reported line 151)May include surrounding context.

Re-run Installer (Recommended)

bash
curl -fsSL https://openclaw.ai/install.sh | bash

Before You Update

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Using | bash for updates creates a direct download-to-execution chain on systems that may already be trusted and operational, increasing blast radius if the update source is compromised. The absence of a verification or review step makes this a genuine unsafe pattern rather than a mere convenience issue.

Content

Scanner excerpt · install.md (reported line 151)May include surrounding context.

Re-run Installer (Recommended)

bash
curl -fsSL https://openclaw.ai/install.sh | bash

Before You Update

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · install.md (reported line 165)May include surrounding context.

bash
npm install -g openclaw@latest
# Or:
openclaw update          # Self-update command

Auto-Updater (Optional)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · openprose.md (reported line 66)May include surrounding context.

text
.prose/
├── .env
├── runs/
│   └── {YYYYMMDD}-{HHMMSS}-{random}/
│       ├── program.prose

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · remote_access.md (reported line 167)May include surrounding context.

md
## Webhooks

External systems can send messages to the Gateway via webhooks.

## Config (Default-On)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · security.md (reported line 314)May include surrounding context.

md
## Webhooks

External systems can send messages to the Gateway via webhooks.

## Config (Default-On)

Privileged Kubernetes Workload

High
Category
Tool Misuse
Confidence
55% confidence
Finding

Code deploys a privileged Kubernetes workload (privileged container, hostPath mount, or host namespaces). This grants root on the node and is a node/cluster takeover vector.

Content

Scanner excerpt · sandboxing.md (reported line 71)May include surrounding context.

Config: agents.defaults.sandbox.docker.binds

Format: "hostPath:containerPath:mode" (mode = ro or rw)

json5
{

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Documenting a file-based secret store at ~/.openclaw/secrets.json creates a credential concentration point on disk. Even though the skill recommends external secret resolution, a local plaintext JSON secret file can be exposed through weak filesystem permissions, backups, endpoint compromise, or accidental inclusion in support bundles and repos.

Content

Scanner excerpt · secrets.md (reported line 77)May include surrounding context.

md
// File provider
      filemain: {
        type: "file",
        path: "~/.openclaw/secrets.json",
      },

      // Exec provider

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

Automatically loading .env from the current working directory is risky because secrets may be sourced from an untrusted project directory or repository checkout. In a self-hosted gateway context, this can cause credential confusion, accidental secret injection, or use of attacker-controlled values when operators run commands in the wrong directory.

Content

Scanner excerpt · secrets.md (reported line 195)May include surrounding context.

md
## Environment Variables

### .env Files

OpenClaw loads env from (in order):
1. `.env` from current working directory (if present)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · secrets.md (reported line 259)May include surrounding context.

md
2. **Run `openclaw secrets audit`** regularly to scan for plaintext leaks
3. **Use `openclaw secrets configure`** for interactive setup
4. **Prefer `source: "env"`** for simplicity, `source: "exec"` for vault integration
5. **File permissions**: `chmod 600 ~/.openclaw/secrets.json`
6. **Rotate secrets** immediately if you suspect compromise

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · security.md (reported line 761)May include surrounding context.

md
- Execute arbitrary shell commands
- Read/write files
- Access network services
- Send messages to anyone (if given WhatsApp access)

A malicious external actor can:
- Try to trick your AI into doing bad things

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · slash_commands.md (reported line 105)May include surrounding context.

md
| `/subagents kill <id\|#\|all>` | Stop a sub-agent (or all) |
| `/subagents log <id\|#> [limit] [tools]` | View sub-agent transcript |
| `/subagents info <id\|#>` | Detailed sub-agent info |
| `/subagents send <id\|#> <message>` | Send message to sub-agent |
| `/subagents steer <id\|#> <message>` | Nudge sub-agent without replacing context |
| `/subagents spawn <agentId> <task>` | Spawn new sub-agent (one-shot `mode: "run"`) |

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions, suspicious.secret_argv_exposure

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
voice.md:42

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
memory.md:60

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
gateway_ops.md:84