Back to skill

Security audit

Openclaw Autoupdate

Security checks for vulnerabilities and agentic risk

Overview

This updater is purpose-aligned, but it silently replaces the OpenClaw app and global CLI from mutable remote sources without adequate disclosure, verification, or rollback.

Install only if you intentionally want this skill to perform unattended OpenClaw upgrades and you trust the publisher, GitHub release source, and npm package path. Before use, require explicit approval for each update, pin or verify release artifacts and npm versions, confirm the expected macOS signing identity, and keep a rollback copy of the existing app and CLI.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/silent-update.sh:47
Finding

Unverified Remote Application Retrieval and Installation

Content
View full analysis
&1 | tee -a "$LOG_FILE" log "安装App..." # 卸载旧版 rm -rf /Applications/OpenClaw.app 2>/dev/null || true # 挂载dmg并安装 hdiutil attach "$DMG_PATH" -nobrowse 2>&1 | tee -a "$LOG_FILE" cp -R "/Volumes/OpenClaw/OpenClaw.app" /Applications/ 2>&1 | tee -a "$LOG_FILE" hdiutil detach "/Volumes/OpenClaw" 2>&1 | tee -a "$LOG_FILE" rm -f "$DMG_PATH" log "App更新完成" ``` ### Technical Analysis The script retrieves a mutable application artifact from the latest GitHub release and installs it without verifying a cryptographic checksum, signed release manifest, macOS code-signing identity, or Gatekeeper assessment. HTTPS protects the connection in transit but does not establish that the release itself is trustworthy if the upstream repository, release account, or publishing workflow is compromised. Because the effective application payload can change after the Skill has been reviewed, the downloaded artifact is outside the audited package. The `curl` invocation uses `-L` but not `--fail`. Consequently, HTTP error responses may be written to the expected DMG path before the existing application is removed. The script deletes `/Applications/OpenClaw.app` before confirming that the downloaded image is valid and contains an authentic application, creating an additional denial-of-service and rollback risk. ### Attack Path 1. An attacker compromises the upstream GitHub repository, maintainer account, release workflow, or release artifact. 2. The attacker publishes a release that matches the expected ...[truncated 1258 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/silent-update.sh:67
Finding

Unpinned Global npm Package Installation

Content
View full analysis
&1 | tee -a "$LOG_FILE" ``` ### Technical Analysis The script globally installs the mutable `latest` version of the `openclaw` npm package. It does not pin an audited version, an integrity digest, package provenance, or an explicit trusted registry. npm installation can execute package lifecycle scripts such as `preinstall`, `install`, and `postinstall`. Therefore, installing a compromised package can cause code execution during the update itself rather than only when the CLI is subsequently invoked. The command also inherits the invoking environment's npm registry and configuration. A modified user or system npm configuration could redirect the package request to an unintended registry. Global installation increases the affected scope by replacing a CLI available outside this individual Skill. ### Attack Path 1. An attacker compromises the npm package maintainer account, publishing token, release pipeline, configured registry, or a registry mirror. 2. The attacker publishes a malicious package version and assigns it to the `latest` distribution tag, or causes the configured registry to return a malicious package. 3. The update script invokes `npm install -g openclaw@latest`. 4. npm retrieves the mutable package and runs any enabled lifecycle scripts. 5. Attacker-controlled code executes with the privileges of the user running the update. 6. The malicious package can also replace the globally available `openclaw` CLI, causing later legitimate-looking CLI invocations to execute attacker-controlled behavior. ### Impact Assessment Successful exploitation permits arbitrary command execution with the privileges of the user running the script. The package can read or modify files available to that user ...[truncated 327 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:25
Finding

Security Documentation Omits Destructive and Network-Enabled Operations

Content
View full analysis
&1 | tee -a "$LOG_FILE" rm -rf /Applications/OpenClaw.app 2>/dev/null || true hdiutil attach "$DMG_PATH" -nobrowse 2>&1 | tee -a "$LOG_FILE" cp -R "/Volumes/OpenClaw/OpenClaw.app" /Applications/ 2>&1 | tee -a "$LOG_FILE" hdiutil detach "/Volumes/OpenClaw" 2>&1 | tee -a "$LOG_FILE" openclaw gateway restart 2>&1 | tee -a "$LOG_FILE" || true ``` ### Technical Analysis The documented command list claims that the Skill only uses a limited set of safe commands. The implementation additionally performs network retrieval, recursive deletion of an installed application, disk-image mounting, application replacement, and a Gateway restart. These are security-relevant side effects and are not equivalent to ordinary file reading and writing. The documentation also characterizes security scanner alerts around global npm installation as false positives without disclosing the lifecycle-script and mutable-dependency risks. The discrepancy can cause users, reviewers, or automated approval systems to authorize execution based on an incomplete representation of the Skill's behavior. ### Attack Path 1. A user or reviewer reads the security documentation and concludes that the Skill only invokes the listed OpenClaw and npm commands plus benign file operations. 2. Based on tha ...[truncated 982 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The README-style description claims the update process is safe and limited, but the detected behavior includes undeclared network access, global package installation, application replacement, service restarts, and local log writes. That mismatch is dangerous because it can mislead users and automation into approving a skill that performs broad system and supply-chain affecting actions beyond what is disclosed.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Suppressing errors with 2>/dev/null and || true around rm -rf hides failures during a destructive operation, reducing operator visibility and making partial-update states harder to detect. In a silent automation context, this increases the risk of unnoticed breakage or unsafe continuation after an unexpected condition.

Content

Scanner excerpt · scripts/silent-update.sh (reported line 54)May include surrounding context.

sh
log "安装App..."
# 卸载旧版
rm -rf /Applications/OpenClaw.app 2>/dev/null || true
# 挂载dmg并安装
hdiutil attach "$DMG_PATH" -nobrowse 2>&1 | tee -a "$LOG_FILE"
cp -R "/Volumes/OpenClaw/OpenClaw.app" /Applications/ 2>&1 | tee -a "$LOG_FILE"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Suppressing errors with 2>/dev/null and || true around rm -rf hides failures during a destructive operation, reducing operator visibility and making partial-update states harder to detect. In a silent automation context, this increases the risk of unnoticed breakage or unsafe continuation after an unexpected condition.

Content

Scanner excerpt · scripts/silent-update.sh (reported line 54)May include surrounding context.

sh
log "安装App..."
# 卸载旧版
rm -rf /Applications/OpenClaw.app 2>/dev/null || true
# 挂载dmg并安装
hdiutil attach "$DMG_PATH" -nobrowse 2>&1 | tee -a "$LOG_FILE"
cp -R "/Volumes/OpenClaw/OpenClaw.app" /Applications/ 2>&1 | tee -a "$LOG_FILE"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Suppressing errors with 2>/dev/null and || true around rm -rf hides failures during a destructive operation, reducing operator visibility and making partial-update states harder to detect. In a silent automation context, this increases the risk of unnoticed breakage or unsafe continuation after an unexpected condition.

Content

Scanner excerpt · scripts/silent-update.sh (reported line 54)May include surrounding context.

sh
log "安装App..."
# 卸载旧版
rm -rf /Applications/OpenClaw.app 2>/dev/null || true
# 挂载dmg并安装
hdiutil attach "$DMG_PATH" -nobrowse 2>&1 | tee -a "$LOG_FILE"
cp -R "/Volumes/OpenClaw/OpenClaw.app" /Applications/ 2>&1 | tee -a "$LOG_FILE"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises shell-executable behavior but does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: an agent or reviewer cannot reliably determine in advance that the skill will execute privileged shell operations like package installation and service control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The visible natural-language content of the skill, including its description and usage documentation, is entirely in Chinese. Under the stated policy, forcing a specific language without user opt-in is a policy violation unless the locale restriction is explicitly justified, which is not provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The package description is written entirely in Chinese and presents the skill as a Chinese-language capability without any indication of optional language selection or a justified region-specific constraint. This can violate language/locale policy when skills implicitly force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The top comments frame the script as a normal 'complete update script' for OpenClaw, while the implementation performs a destructive replacement by removing /Applications/OpenClaw.app before copying in a new bundle. That behavior is more invasive than the benign update framing suggests and the documentation does not reflect that installed software is deleted and reinstalled in place.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/silent-update.sh (reported line 25)May include surrounding context.

sh
log "当前CLI版本: ${CURRENT_CLI}"

# 2. 检查GitHub最新版本
LATEST_GITHUB=$(curl -sL "https://api.github.com/repos/openclaw/openclaw/releases/latest" | grep -oE '"tag_name":\s*"v[0-9]+\.[0-9]+\.[0-9]+"' | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | head -1)
log "GitHub最新版本: ${LATEST_GITHUB}"

# 3. 检查Menu Bar App当前版本

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/silent-update.sh (reported line 29)May include surrounding context.

sh
log "GitHub最新版本: ${LATEST_GITHUB}"

# 3. 检查Menu Bar App当前版本
CURRENT_APP=$(plutil -p /Applications/OpenClaw.app/Contents/Info.plist 2>/dev/null | grep CFBundleShortVersionString | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' || echo "unknown")
log "当前App版本: ${CURRENT_APP}"

# 判断是否需要更新

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/silent-update.sh (reported line 74)May include surrounding context.

sh
log "GitHub最新版本: ${LATEST_GITHUB}"

# 3. 检查Menu Bar App当前版本
CURRENT_APP=$(plutil -p /Applications/OpenClaw.app/Contents/Info.plist 2>/dev/null | grep CFBundleShortVersionString | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' || echo "unknown")
log "当前App版本: ${CURRENT_APP}"

# 判断是否需要更新

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script silently deletes /Applications/OpenClaw.app and replaces it without confirmation, backup, or rollback. In an automated skill context, this can cause destructive changes or leave the app unavailable if the DMG is invalid, tampered with, or the copy operation fails.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Running npm install -g openclaw@latest and restarting the gateway changes globally installed software and service state without explicit user awareness. In a silent-update skill, this can unexpectedly alter runtime behavior, break dependent workflows, or pull a compromised latest package if the supply chain is attacked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language strings throughout the script, including status logs, are presented only in Chinese. This imposes a specific language on users without opt-in or locale selection, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.