Back to skill

Security audit

OpenClaw Deploy Guide

Security checks for vulnerabilities and agentic risk

Overview

This deployment skill is mostly purpose-aligned, but it asks users to run unverified remote installers, bypass OS security warnings, and enable persistent services.

Review this skill carefully before installing. Prefer manual downloads from trusted releases, verify signatures or hashes, avoid curl|bash and iwr|iex commands, do not bypass OS warnings unless you have independently verified the publisher, and store API keys with restrictive permissions. Treat service and Docker restart setup as opt-in persistence.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:23
Finding

Mutable Remote Installation Scripts Are Executed Without Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:114
Finding

Unverified Executables and Floating Container Images Create a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation
``` 5. Avoid discovering executable download URLs by parsing mutable “latest release” API output. 6. Fail closed if integrity or publisher validation cannot be completed. 7. Maintain a documented update procedure that reviews and deliberately changes pinned versions and digests. 8. Generate a software bill of materials and use automated dependency and image vulnerability scanning. ]]>

T06 · System Persistence

Error
Location
skill.md:318
Finding

Deployment Instructions Establish Cross-Session Service and Container Persistence

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.sh:199
Finding

API Keys Are Echoed and Written to Plaintext Configuration Without Enforced File Permissions

Content
View full analysis
"$CONFIG_FILE" << EOF ai: provider: deepseek deepseek: api_key: $api_key model: deepseek-chat EOF ;; 3) read -p "输入 Kimi API Key: " api_key cat > "$CONFIG_FILE" << EOF ai: provider: kimi kimi: api_key: $api_key model: moonshot-v1-8k EOF ;; ``` ### Technical Analysis The installer uses `read -p` rather than silent input, so API keys are displayed while entered. It then writes the values directly into a plaintext YAML file. The script does not set `umask 077`, pre-create the configuration with mode `0600`, or apply restrictive permissions after writing it. Actual exposure to other local users depends on the invoking user's ambient `umask` and directory permissions. Nevertheless, the script does not enforce the confidentiality required for API credentials. The values are also inserted into YAML without quoting or escaping. Keys containing YAML-significant characters or newlines can corrupt the configuration or inject additional YAML fields. This is primarily a configuration-integrity issue because the input is supplied interactively by the same user, but it becomes more relevant if invocation is automated or input is supplied from an untrusted source. ### Attack Path 1. A user enters a provider API key into the visible terminal prompt. 2. The key may be exposed through shoulder surfing, terminal recording, or session capture. 3. The installer writes the key to `~/.nexusbot/config.yaml` using ambient permissions. 4. Another local principal, backup process, support bundle, or overly broad synchronization mechanism reads the file. 5. The exposed key is used to consume API quota, access provider resources, or impersonate the account within the provider's authorization scop ...[truncated 370 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skill.md:558
Finding

Instructions Encourage Users to Bypass Operating-System Application Security Warnings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (69)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

curl ... | bash is a well-known dangerous chaining pattern because it turns remote network content directly into executed shell commands with no review barrier. In a deployment guide, the skill context makes this more dangerous, not less, because the documentation is explicitly designed to encourage copy-paste execution on user systems.

Content

Scanner excerpt · README.md (reported line 23)May include surrounding context.

双击安装

方法 2:脚本安装

curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

text

### Windows

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The repeated | bash pattern in the Linux section presents the same direct remote-code-execution hazard and may be even more severe when run on Linux servers or CI/CD hosts. If the hosting account, repository, or delivery path is compromised, users executing this command can hand over full control of the target machine.

Content

Scanner excerpt · README.md (reported line 45)May include surrounding context.

md
sudo dpkg -i nexusbot_amd64.deb

# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

# 或 Docker
docker run -d -p 3000:3000 markovmodcn/nexusbot:latest

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a comprehensive cross-platform deployment guide, explicitly including Windows and broader topics like platform integration and troubleshooting. The supplied code is instead a concrete shell installer limited to macOS and Linux. Its primary behavior is downloading and installing application packages, optionally installing Ollama by piping a remote script to sh, pulling a model, and storing API keys/config in the user's home directory. That is materially narrower and operationally different from a general guide, and the Windows support claim is clearly inaccurate.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
93% confidence
Finding

The generic Linux path downloads a tarball discovered dynamically from release metadata, extracts it into a user directory, and exposes the resulting binary via /usr/local/bin. Without checksum/signature verification, this creates a supply-chain vector where a compromised repo, release artifact, or API response can lead to execution of attacker-controlled code.

Content

Scanner excerpt · scripts/install.sh (reported line 153)May include surrounding context.

sh
fi

    TEMP_TAR="/tmp/nexusbot-linux.tar.gz"
    curl -L -o "$TEMP_TAR" "$LATEST_URL"

    # 解压
    echo "📦 解压..."

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This line fetches a shell script from ollama.com and executes it immediately, without showing the contents, pinning a version, or asking for confirmation. That creates a direct remote code execution path and removes the user’s opportunity to review what will run on their system.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping curl output directly into sh is a classic dangerous chaining pattern because network-fetched content becomes immediately executable code. In the context of an installer skill, this is more dangerous than usual because users are primed to trust and run setup steps without review.

Content

Scanner excerpt · scripts/install.sh (reported line 236)May include surrounding context.

sh
# 检查是否已安装
    if ! command -v ollama &> /dev/null; then
        echo "📥 安装 Ollama..."
        curl -fsSL https://ollama.com/install.sh | sh
    fi

    # 拉取模型

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The macOS section encourages overriding Gatekeeper-style protections to open the app, but does not explain the trust implications. In a public install guide, that reduces users' caution around unsigned or unverified binaries and can facilitate execution of malicious software.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guide includes a remote shell script piped directly to bash with no warning about trust, code review, or host modification. Because this is a deployment skill, users are likely to copy-paste it verbatim, making arbitrary code execution risk more acute.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash construction chains network retrieval directly into shell execution, eliminating any review boundary. In a skill intended for copy-paste deployment, this materially raises the risk of arbitrary code execution and supply-chain compromise.

Content

Scanner excerpt · skill.md (reported line 86)May include surrounding context.

bash
# 一键安装脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

方法三:Homebrew 安装(如可用)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The PowerShell one-liner downloads and executes remote code immediately without warning. This is especially risky on Windows because it collapses download, trust, and execution into one step, leaving no opportunity for validation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Linux instructions include curl ... | bash without explaining that it executes untrusted remote code and may alter the system. In a deployment guide, this creates a realistic path to arbitrary command execution if the source is compromised.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The Linux one-liner pipes a remote install script straight into bash, which is a classic unsafe execution chain. If the remote content is malicious or tampered with, the user grants immediate code execution on the host.

Content

Scanner excerpt · skill.md (reported line 242)May include surrounding context.

bash
# 一键安装脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

Docker 安装(跨平台)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

curl -fsSL https://ollama.com/install.sh | sh downloads and executes a remote script in one step. This creates direct arbitrary code execution risk if the script source, hosting, DNS, or transport trust is compromised.

Content

Scanner excerpt · skill.md (reported line 379)May include surrounding context.

bash
# 一键安装
curl -fsSL https://ollama.com/install.sh | sh

下载模型

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | sh Ollama installer is another direct fetch-and-execute chain. This is dangerous because it combines retrieval and execution of remote content into a single blind action with no verification step.

Content

Scanner excerpt · skill.md (reported line 379)May include surrounding context.

bash
# 一键安装
curl -fsSL https://ollama.com/install.sh | sh

下载模型

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The troubleshooting section tells users to remove the quarantine attribute from a macOS app without discussing the loss of platform protections. This increases the chance of users running unverified software and undermines OS security expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README instructs users to fetch a remote shell script and immediately execute it with bash, with no warning, verification step, or integrity check. This creates a direct remote-code-execution path on the user's machine and is especially dangerous in a deployment guide because users are likely to copy-paste commands verbatim.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The PowerShell command downloads remote content and passes it directly to iex, which executes it immediately in memory. This is a classic high-risk pattern that enables silent execution of attacker-controlled code if the source is compromised, redirected, or tampered with.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

bash
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb

# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · skill.md (reported line 208)May include surrounding context.

bash
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb

# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · skill.md (reported line 211)May include surrounding context.

bash
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb

# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · skill.md (reported line 221)May include surrounding context.

bash
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb

# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · skill.md (reported line 222)May include surrounding context.

bash
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb

# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · skill.md (reported line 235)May include surrounding context.

bash
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb

# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · skill.md (reported line 336)May include surrounding context.

bash
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb

# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · skill.md (reported line 337)May include surrounding context.

bash
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb

# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash