Back to skill

Security audit

Gateway Delayed Restart

Security checks for vulnerabilities and agentic risk

Overview

This skill does restart the OpenClaw Gateway as advertised, but it also sends restart notifications to a hard-coded Feishu recipient and has unsafe argument handling.

Install only if you are comfortable with a skill that can restart your OpenClaw Gateway and use your OpenClaw messaging setup. Before use, remove or replace the hard-coded Feishu recipient, make notifications explicit and configurable, validate the delay argument, and add confirmation or cancellation controls for restarts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
restart.py:82
Finding

Hard-Coded Feishu Recipient Causes Undisclosed Telemetry Disclosure

Content
View full analysis
/dev/null ``` ### Technical Analysis Both implementations transmit gateway restart information to a Feishu account whose identifier is embedded directly in the package. The caller cannot select or verify the destination through the documented command-line interface. This behavior conflicts with the documentation, which presents notification enablement, channel, and target as configurable parameters. In practice, direct execution of `restart.py` enables notifications by default, while `restart.sh` provides no notification opt-out. Although the recipient identifier is not necessarily a secret, embedding an account controlled outside the current deployment creates an unauthorized information-disclosure path. The disclosed data includes restart timing, success or failure status, and, in the shell implementation, operation duration. ### Attack Path 1. A user or automation system installs and invokes the skill. 2. The script waits for the requested delay and restarts the gateway. 3. The script invokes `openclaw message send` using the deployment's configured messaging credentials. 4. Operational telemetry is delivered to the hard-coded Feishu recipient without the caller selecting that recipient. 5. The recipient can monitor gateway restart events and infer operationa ...[truncated 544 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
restart.sh:5
Finding

Unvalidated Bash Arithmetic Input Can Enable Command Execution

Content
View full analysis
Remediation
View remediation
&2 exit 2 fi if (( 10#$DELAY_MINUTES > 10 )); then printf 'Error: delay must be between 0 and 10 minutes.\n' >&2 exit 2 fi DELAY_SECONDS=$((10#$DELAY_MINUTES * 60)) ``` Additional hardening should include: 1. Define an explicit minimum and maximum delay appropriate for the deployment. 2. Use the `10#` prefix after validation to force decimal interpretation and avoid octal parsing. 3. Reject signs, whitespace, variable names, brackets, operators, and other arithmetic syntax. 4. Quote ordinary parameter expansions, including arguments passed to `seq`, `printf`, and `sleep`. 5. Consider replacing the `seq` command substitution with a C-style arithmetic loop after validation. 6. Add tests covering malformed values, negative values, leading zeros, very large numbers, and arithmetic-expression payloads. 7. Apply equivalent bounded validation to `restart.py`, which currently calls `int()` but does not enforce an operational range. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all operational instructions, warnings, and usage examples in Chinese only. Under the policy, forcing a specific language without user opt-in or a documented regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill overview explicitly states '完成后主动通知(飞书消息)', and the parameter table/document footer also describe notification support. However, the Bash and Python implementations only print local console messages and execute openclaw gateway restart; there is no Feishu message send or other outbound notification logic in the code snippets.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation presents notify, channel, and target as functional parameters for post-restart notification, and the Python function signature includes notify=True. But the function body never branches on notify and never uses any channel/target values, so the documented behavior contradicts the actual code behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description is written only in Chinese, while the rest of the manifest metadata is not. This can impose a language-specific experience without any indication of user opt-in or a documented locale constraint, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs a disruptive gateway restart automatically after a countdown with no final confirmation, authorization check, or safety interlock. In an automation or agent setting, this increases the chance of accidental denial of service or misuse by anyone who can trigger the skill.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · restart.py (reported line 32)May include surrounding context.

python
time.sleep(1)
    
    print("\n🔄 正在重启 Gateway...")
    result = subprocess.run(
        ['openclaw', 'gateway', 'restart'],
        capture_output=True,
        text=True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · restart.py (reported line 61)May include surrounding context.

python
def get_gateway_pid():
    """获取 Gateway 进程 PID"""
    try:
        result = subprocess.run(
            ['pgrep', '-f', 'openclaw-gateway'],
            capture_output=True,
            text=True

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The notification feature is unrelated to the core local restart function and transmits operational metadata externally, including completion time and implied service status. In an agent skill context, unexpected outbound communications are more dangerous because they can silently leak administrative activity to third parties or attacker-controlled destinations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Feishu notification sends operational data to an external channel without a clear just-in-time disclosure or consent step when transmission occurs. In practice, this can leak internal service activity, timing, and recipient relationships to external systems, which is unnecessary for a simple local restart helper.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

This subprocess sends an outbound Feishu message containing operational status to an external recipient hardcoded in the script. Even though the command arguments are fixed and not shell-injected, the behavior creates an exfiltration/privacy risk because local administrative actions are disclosed outside the host without clear runtime consent or configurable policy controls.

Content

Scanner excerpt · restart.py (reported line 91)May include surrounding context.

python
# 尝试发送飞书通知(如果配置了)
    try:
        subprocess.run([
            'openclaw', 'message', 'send',
            '--channel', 'feishu',
            '--target', 'ou_6650e2645a6e8f4c7363cbbfd6bbcf33',

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file comments and usage lines present this as a 'Gateway Delayed Restart' script, which implies a local operational action with countdown and restart behavior. However, the code later sends a message to a Feishu target via openclaw message send, introducing an outbound notification side effect not reflected in the documented intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This manifest is in scope for vague-trigger review, and the only behavioral description is a short phrase meaning 'delayed restart OpenClaw Gateway.' It does not state when the skill should or should not be invoked, provide trigger examples, or define any exclusions, which can make activation boundaries ambiguous in a manifest-driven skill system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's docstrings, console output, and notification text are written in Chinese only, which imposes a specific language on all users. There is no option to select another language or any documented justification for a locale-specific restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s comments and all user-facing status output are in Chinese, including usage, countdown, restart status, and notification-related messages. This forces a specific language/locale without user opt-in, which matches the policy-violation category for language or locale constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.