T08 · Insecure Dependencies
- Location
SKILL.md:32- Finding
Execution of an Unpinned Remote Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears intended for legitimate OpenClaw maintenance, but it asks users to run unreviewed mutable installers for high-impact scheduled cleanup, recovery, and service-control behavior.
Review before installing. This is not evidence of malware, but you should not run the one-click setup unless you trust the publisher and have inspected the exact scripts at a pinned commit or signed release. Confirm what cron jobs, cleanup paths, backup locations, service restarts, webhooks, and uninstall steps it will use, and test dry-run or status commands before enabling automation.
SKILL.md:32Execution of an Unpinned Remote Package
SKILL.md:37Mutable Remote Repository Is Cloned and Its Installer Executed
package.json:5Declared Executable and Security-Critical Components Are Missing from the Artifact
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
ed)
bunx clawhub@latest install system-maintenance
git clone https://github.com/jazzqi/openclaw-system-maintenance.git \
~/.openclaw/skills/system-maintenance
cd ~/.openclaw/skills/system-maintenance
chmod +x scripts/*.sh
bash scripts/install-maintenance-system.sh
# Check cron tasks
crontab -l | grep -i openclaw
# Test monitoring
bash scripts/real-time-monitor.sh --test
# Quick health check
bash scripts/daily-maintenance.sh --quick-check
| Frequency | Task | Description | Script |
|---|---|---|---|
| Every 5 min | Real-time Monitoring | Gateway monitoring & auto-recovery | real-time-monitor.sh |
| Daily 2:00 AM | Log Management | Log cleanup, rotation, compression | log-management.sh |
| Daily 3:30 AM | Daily Maintenance | Comprehensive cleanup & health checks | ` |
The description advertises automated cleanup, auto-recovery, backup/rollback, and maintenance automation, but it does not clearly warn that these actions may modify system state, delete files, restart services, or affect availability. In a system-maintenance skill, omitting impact warnings increases the chance that a user will run potentially disruptive operations without informed consent.
The one-click setup command invokes an installation script without an accompanying warning that it may install scheduled tasks, change maintenance behavior, alter permissions, or modify the host environment. Presenting a privileged, state-changing installer as a simple setup step can lead to unintended persistence and operational changes.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Check cron tasks
crontab -l | grep -i openclaw
# Test monitoring
bash scripts/real-time-monitor.sh --test
The emergency recovery examples include restoring from backup and forcibly restarting services, but they do not warn about possible downtime, rollback of recent changes, or process termination side effects. In an operational context, these commands can interrupt running workloads and create data consistency risks if executed casually.
No suspicious patterns detected.