Back to skill

Security audit

OpenClaw 备份还原工具

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: backs up, restores, and restarts OpenClaw locally, but its backups may contain sensitive agent state.

Install only if you are comfortable with local plaintext backups of OpenClaw identity, user, memory, tool, soul, and configuration files. Keep the backup directory private, avoid restoring backups you do not trust, and expect the restart command to briefly interrupt the OpenClaw Gateway.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup.sh:5
Finding

Plaintext Backups of Sensitive Agent State Lack Enforced Access Controls

Content
View full analysis

Vulnerability Details

File Location: scripts/backup.sh, lines 5-27
Vulnerability Type: Plaintext sensitive-data exposure through insufficient filesystem permission enforcement
Risk Level: Medium

Vulnerable Code

bash
BACKUP_DIR="$HOME/.openclaw/workspace/backups"
DATE=$(date +%Y-%m-%d_%H%M%S)
BACKUP_NAME="backup_$DATE"

# 需要备份的关键文件
FILES=(
    "$HOME/.openclaw/workspace/IDENTITY.md"
    "$HOME/.openclaw/workspace/USER.md"
    "$HOME/.openclaw/workspace/MEMORY.md"
    "$HOME/.openclaw/workspace/SOUL.md"
    "$HOME/.openclaw/workspace/TOOLS.md"
    "$HOME/.openclaw/openclaw.json"
    "$HOME/.openclaw/workspace/memory/"
)

mkdir -p "$BACKUP_DIR/$BACKUP_NAME"

echo "🛡️  OpenClaw 备份中..."
echo "====================="

for file in "${FILES[@]}"; do
    if [ -e "$file" ]; then
        cp -r "$file" "$BACKUP_DIR/$BACKUP_NAME/"
        echo "✓ 备份: $file"
    fi
done

Technical Analysis

The script copies identity information, user data, persistent memory, behavioral instructions, tool definitions, and the OpenClaw configuration into a plaintext backup tree. It does not establish a restrictive umask, explicitly set directory or file permissions, validate ownership, or encrypt the resulting backup.

Consequently, the effective permissions depend on the caller's environment, existing parent-directory permissions, source permissions, and platform-specific cp behavior. Under a permissive configuration, other local users or processes may be able to inspect the duplicated data. The backup operation also increases the number of locations from which potentially sensitive configuration and Agent state can be recovered.

No remote transfer or deliberate data exfiltration was found. Exploitation requires filesystem access to the backup directory, directly or through another compromised local process.

Attack Path

  1. The user invokes scripts/backup.sh in an environment with ...[truncated 1016 chars]
Remediation
View remediation

Remediation Suggestions

  • Set umask 077 at the beginning of the script before creating any backup content.
  • Create the backup root and each backup directory with explicit mode 0700.
  • Set copied regular files to mode 0600 and directories to mode 0700.
  • Verify that the backup directory is owned by the current user and refuse to proceed if ownership or permissions are unsafe.
  • Avoid following symbolic links when collecting sensitive files, and verify source paths before copying.
  • Consider encrypting backups at rest with an authenticated encryption mechanism and securely managing the encryption key.
  • Check every mkdir, cp, and permission-setting operation for failure and terminate safely if any operation fails.
  • Document retention and secure deletion procedures to prevent unnecessary accumulation of historical sensitive data.

T02 · Agent Memory Poisoning

Warning
Location
scripts/restore.sh:37
Finding

Unverified Backup Content Can Poison Persistent Agent State During Restore

Content
View full analysis

Vulnerability Details

File Location: scripts/restore.sh, lines 37-56
Vulnerability Type: Untrusted persistent state restoration without integrity or provenance validation
Risk Level: Medium

Vulnerable Code

bash
# 执行还原
TARGET_DIR="$BACKUP_DIR/$BACKUP_NAME"

# 还原 workspace 文件
for file in IDENTITY.md USER.md MEMORY.md SOUL.md TOOLS.md; do
    if [ -f "$TARGET_DIR/$file" ]; then
        cp "$TARGET_DIR/$file" "$HOME/.openclaw/workspace/"
        echo "✓ 还原: $file"
    fi
done

# 还原 memory 目录
if [ -d "$TARGET_DIR/memory" ]; then
    cp -r "$TARGET_DIR/memory" "$HOME/.openclaw/workspace/"
    echo "✓ 还原: memory/"
fi

if [ -f "$TARGET_DIR/openclaw.json" ]; then
    cp "$TARGET_DIR/openclaw.json" "$HOME/.openclaw/openclaw.json"
    echo "✓ 还原: openclaw.json"
fi

Technical Analysis

The restore script treats every selected backup as trusted and copies its contents over live OpenClaw state. It does not authenticate the backup, verify a checksum or signed manifest, validate ownership and permissions, reject symbolic links, or present sensitive changes for review.

The affected files include persistent memory and behavioral state such as MEMORY.md, SOUL.md, and TOOLS.md, as well as openclaw.json. If another local principal or compromised process can modify a backup, the restore operation becomes a trusted path for introducing attacker-controlled instructions or configuration into future Agent sessions.

The interactive selection and confirmation prompts only confirm which backup the user intends to restore. They do not establish that the backup has remained intact since creation. Exploitation therefore requires prior write access to the backup tree or compromise of the user account; the script does not independently provide that access.

Attack Path

  1. A local attacker or compromised process obtains write access to $HOME/.openclaw/workspace/backups.
  2. The attacker ...[truncated 1253 chars]
Remediation
View remediation

Remediation Suggestions

  • Generate an authenticated manifest when each backup is created, covering every relative path, file type, size, and cryptographic digest.
  • Protect the manifest with a keyed MAC or digital signature whose key is stored separately from the writable backup tree.
  • Verify the complete manifest before restoring any file and abort on missing, added, changed, or type-mismatched entries.
  • Confirm that the backup root and selected backup are owned by the expected user and are not writable by group or other users.
  • Resolve and validate canonical paths, reject symbolic links and special files, and ensure every source remains beneath the selected backup directory.
  • Display diffs for sensitive files such as SOUL.md, MEMORY.md, TOOLS.md, and openclaw.json before confirmation.
  • Restore into a securely created staging directory first, validate all staged content, and then replace live files atomically.
  • Preserve restrictive permissions during restoration and explicitly set safe modes on restored files and directories.
  • Create a protected pre-restore snapshot so an unsafe or accidental restoration can be rolled back.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description promises a broader backup/restore tool with automatic backups before debug-feature installation, terminal one-click restore, and reboot support. The actual code chunk is a standalone backup script only: it copies a fixed set of files into a timestamped backup directory. There is no restore logic, no reboot logic, and no evidence of being automatically invoked before installation actions. The backup portion is consistent with the description, but the declared behavior materially exceeds what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description emphasizes backup and restore capabilities, including automatic backups before installing debugging features and one-click terminal restore/reboot. The supplied code only restarts the OpenClaw Gateway. While the description mentions reboot/restart-related behavior, the script lacks the core advertised backup and restore functions, making its primary purpose materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to run a restart script without clearly warning that it will restart the OpenClaw Gateway and temporarily disrupt service availability. In an operational environment, unexpected restarts can interrupt active sessions, automation, or dependent services, creating avoidable denial-of-service conditions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented backup behavior includes copying identity, memory, configuration, and other potentially sensitive files, but the skill does not warn users about the privacy and security implications of storing those backups. Unprotected backups can expose credentials, personal data, configuration secrets, or conversational memory if accessed by other users or processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The comments and status output use Chinese-only messaging (for example, '一键重启 Gateway' and '正在重启 OpenClaw Gateway...') with no indication that another language is available. This creates a natural-language locale policy issue because the skill appears to enforce a specific language for user-facing interaction without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script presents its title, prompts, confirmations, and status messages in Chinese, including the required restore confirmation prompt. This creates a language/locale restriction in the user-facing workflow with no opt-in, alternative language, or documented justification that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing instructions and description text are written only in Chinese, with no indication that another language can be used or selected. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern unless clearly documented as region-specific or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This shell script includes natural-language comments and status messages in Chinese while the rest of the skill naming is in English, and it does not indicate that users can choose or opt into a locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.