Back to skill

Security audit

huawei-cloud-flexus-l-server-openclaw-deployment

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent OpenClaw-on-Huawei-Cloud purpose, but it grants and uses high-impact cloud authority with unsafe logging, auto-renewing paid resources, and mutable remote script execution.

Review before installing. Use only temporary, least-privilege Huawei credentials, avoid non-interactive deployment until auto-pay and auto-renew behavior is acceptable, assume printed logs may expose cloud or integration secrets, and require pinned or bundled scripts before allowing root-level remote execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (83)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instance-creation flow is configured for paid provisioning with is_auto_pay=True and is_auto_renew=True without any explicit confirmation or safety interlock. In an agent context, this can cause unauthorized cloud spending and persistence of resources beyond the user's intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code prints the full Authorization header and request headers for a signed cloud API request. These values may expose reusable signed credentials, temporary tokens, or sensitive request metadata to logs, consoles, or downstream telemetry, enabling credential misuse and cloud account compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill exposes generic cloud custom-script creation and remote execution primitives, which are broader than the declared OpenClaw deployment/configuration purpose. This greatly increases abuse potential because a caller can repurpose the skill as a general remote code execution interface on cloud instances.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The script template fetches external shell content over the network and pipes it directly into bash on remote instances. This creates a supply-chain and integrity risk: if the remote file, storage bucket, DNS, or transport endpoint is compromised, arbitrary code executes on managed instances.

Content

Scanner excerpt · scripts/lib.py (reported line 855)May include surrounding context.

python
"description": "Install MaaS models on OpenClaw instance",
        "risk_level": "MEDIUM",
        "content": '''#!/bin/bash
curl -sSL https://documentation-samples.obs.cn-north-4.myhuaweicloud.com/solution-as-code-publicbucket/solution-as-code-moudle/deploying-clawdbot-agents/userdata/multi_model.sh | bash -s '${modelParams}'

if [ -d "/home/openclaw" ]; then
  export PNPM_HOME="/home/openclaw/.local/share/pnpm"

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

This template repeats the same unsafe curl | bash pattern for channel installation, allowing remote content to control command execution on target instances. Because the skill is intended for deployment/configuration, users may not expect this level of trust in mutable external scripts.

Content

Scanner excerpt · scripts/lib.py (reported line 879)May include surrounding context.

python
"description": "Install channels on OpenClaw instance (WeChat Work/Feishu/DingTalk/QQ)",
        "risk_level": "MEDIUM",
        "content": '''#!/bin/bash
curl -sSL https://documentation-samples.obs.cn-north-4.myhuaweicloud.com/solution-as-code-publicbucket/solution-as-code-moudle/deploying-clawdbot-agents/userdata/multi_channel.sh | bash -s '${channelList}'

if [ -d "/home/openclaw" ]; then
  export PNPM_HOME="/home/openclaw/.local/share/pnpm"

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

Even though this action only checks gateway status, it still obtains shell code from an external location and executes it blindly. A compromise of the external script source would turn a read-like health check into arbitrary code execution on remote instances.

Content

Scanner excerpt · scripts/lib.py (reported line 903)May include surrounding context.

python
"description": "Query OpenClaw gateway status",
        "risk_level": "LOW",
        "content": '''#!/bin/bash
curl -sSL https://documentation-samples.obs.cn-north-4.myhuaweicloud.com/solution-as-code-publicbucket/solution-as-code-moudle/deploying-clawdbot-agents/userdata/openclaw_gateway_manager.sh | bash -s status'''
    }
}

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill includes local shell execution capabilities unrelated to a cloud deployment assistant, including running downloaded scripts and modifying system binaries/links. In an agent setting, this breaks expected trust boundaries and can turn the host running the skill into the attack target rather than just the managed cloud instance.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This local command downloads a remote script and pipes it to bash on the machine running the skill. In the skill context this is especially dangerous because it enables host compromise, not just changes to the intended cloud target, and it is combined with attacker-controlled parameters.

Content

Scanner excerpt · scripts/lib.py (reported line 1098)May include surrounding context.

python
try:
        print("Starting model installation...")
        
        install_command = f"curl -sSL https://documentation-samples.obs.cn-north-4.myhuaweicloud.com/solution-as-code-publicbucket/solution-as-code-moudle/deploying-clawdbot-agents/userdata/multi_model.sh | bash -s {model_params}"
        
        print(f"Executing command: {install_command}")

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This function downloads a remote shell script and executes it locally, then performs additional privileged system changes, all without warning or trust validation. Combined with user-controlled parameters and shell=True, this creates a severe local compromise path for the host environment.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The tool accepts attacker-influenced parameters and embeds them into a shell command executed with shell=True. This is a classic tool-parameter-abuse case that allows users of the skill to escalate intended model installation into arbitrary command execution on the host.

Content

Scanner excerpt · scripts/lib.py (reported line 1102)May include surrounding context.

python
print(f"Executing command: {install_command}")
        
        result = subprocess.run(
            install_command,
            shell=True,
            capture_output=True,

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1118)May include surrounding context.

python
if os.path.exists("/home/openclaw"):
            print("\nDetected OpenClaw installed in /home/openclaw")
            subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/home/openclaw/.local/share/pnpm/openclaw"
            restart_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway restart >> /var/manage_operate.log 2>&1"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1204)May include surrounding context.

python
if os.path.exists("/home/openclaw"):
            print("\nDetected OpenClaw installed in /home/openclaw")
            subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/home/openclaw/.local/share/pnpm/openclaw"
            restart_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway restart >> /var/manage_operate.log 2>&1"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1119)May include surrounding context.

python
if os.path.exists("/home/openclaw"):
            print("\nDetected OpenClaw installed in /home/openclaw")
            subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/home/openclaw/.local/share/pnpm/openclaw"
            restart_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway restart >> /var/manage_operate.log 2>&1"
            subprocess.run(restart_cmd, shell=True)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1205)May include surrounding context.

python
if os.path.exists("/home/openclaw"):
            print("\nDetected OpenClaw installed in /home/openclaw")
            subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/home/openclaw/.local/share/pnpm/openclaw"
            restart_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway restart >> /var/manage_operate.log 2>&1"
            subprocess.run(restart_cmd, shell=True)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1122)May include surrounding context.

python
subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/home/openclaw/.local/share/pnpm/openclaw"
            restart_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway restart >> /var/manage_operate.log 2>&1"
            subprocess.run(restart_cmd, shell=True)
            status_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway status 2>&1"
            status_result = subprocess.run(status_cmd, shell=True, capture_output=True, text=True)
            print(f"Gateway status:\n{status_result.stdout}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1208)May include surrounding context.

python
subprocess.run("ln -sf /home/openclaw/.nvm/versions/node/v22.22.1/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/home/openclaw/.local/share/pnpm/openclaw"
            restart_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway restart >> /var/manage_operate.log 2>&1"
            subprocess.run(restart_cmd, shell=True)
            status_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway status 2>&1"
            status_result = subprocess.run(status_cmd, shell=True, capture_output=True, text=True)
            print(f"Gateway status:\n{status_result.stdout}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1124)May include surrounding context.

python
restart_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway restart >> /var/manage_operate.log 2>&1"
            subprocess.run(restart_cmd, shell=True)
            status_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway status 2>&1"
            status_result = subprocess.run(status_cmd, shell=True, capture_output=True, text=True)
            print(f"Gateway status:\n{status_result.stdout}")
            
        elif os.path.exists("/root/.local/share/pnpm/openclaw"):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1210)May include surrounding context.

python
restart_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway restart >> /var/manage_operate.log 2>&1"
            subprocess.run(restart_cmd, shell=True)
            status_cmd = f"sudo -i -u openclaw env DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus {cmd_name} gateway status 2>&1"
            status_result = subprocess.run(status_cmd, shell=True, capture_output=True, text=True)
            print(f"Gateway status:\n{status_result.stdout}")
            
        elif os.path.exists("/root/.local/share/pnpm/openclaw"):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1129)May include surrounding context.

python
elif os.path.exists("/root/.local/share/pnpm/openclaw"):
            print("\nDetected OpenClaw installed in /root")
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/root/.local/share/pnpm/openclaw"
            subprocess.run(f"{cmd_name} gateway restart >> /var/manage_operate.log 2>&1", shell=True)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1215)May include surrounding context.

python
elif os.path.exists("/root/.local/share/pnpm/openclaw"):
            print("\nDetected OpenClaw installed in /root")
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/root/.local/share/pnpm/openclaw"
            subprocess.run(f"{cmd_name} gateway restart >> /var/manage_operate.log 2>&1", shell=True)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1130)May include surrounding context.

python
elif os.path.exists("/root/.local/share/pnpm/openclaw"):
            print("\nDetected OpenClaw installed in /root")
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/root/.local/share/pnpm/openclaw"
            subprocess.run(f"{cmd_name} gateway restart >> /var/manage_operate.log 2>&1", shell=True)
            status_result = subprocess.run(f"{cmd_name} gateway status 2>&1", shell=True, capture_output=True, text=True)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1216)May include surrounding context.

python
elif os.path.exists("/root/.local/share/pnpm/openclaw"):
            print("\nDetected OpenClaw installed in /root")
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/root/.local/share/pnpm/openclaw"
            subprocess.run(f"{cmd_name} gateway restart >> /var/manage_operate.log 2>&1", shell=True)
            status_result = subprocess.run(f"{cmd_name} gateway status 2>&1", shell=True, capture_output=True, text=True)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1132)May include surrounding context.

python
subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/root/.local/share/pnpm/openclaw"
            subprocess.run(f"{cmd_name} gateway restart >> /var/manage_operate.log 2>&1", shell=True)
            status_result = subprocess.run(f"{cmd_name} gateway status 2>&1", shell=True, capture_output=True, text=True)
            print(f"Gateway status:\n{status_result.stdout}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1218)May include surrounding context.

python
subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/node /usr/local/bin/node", shell=True)
            subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/root/.local/share/pnpm/openclaw"
            subprocess.run(f"{cmd_name} gateway restart >> /var/manage_operate.log 2>&1", shell=True)
            status_result = subprocess.run(f"{cmd_name} gateway status 2>&1", shell=True, capture_output=True, text=True)
            print(f"Gateway status:\n{status_result.stdout}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/lib.py (reported line 1133)May include surrounding context.

python
subprocess.run("ln -sf /root/.nvm/versions/node/v22.22.0/bin/npm /usr/local/bin/npm", shell=True)
            cmd_name = "/root/.local/share/pnpm/openclaw"
            subprocess.run(f"{cmd_name} gateway restart >> /var/manage_operate.log 2>&1", shell=True)
            status_result = subprocess.run(f"{cmd_name} gateway status 2>&1", shell=True, capture_output=True, text=True)
            print(f"Gateway status:\n{status_result.stdout}")
        
        if result.returncode == 0:

Static analysis

No suspicious patterns detected.