Back to skill

Security audit

Security Network Hardening

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent OpenClaw security-hardening guide with expected firewall and configuration authority, but users should review commands before applying changes.

Install only if you want an agent to help audit and harden an OpenClaw Linux host. Review and explicitly approve any sudo, UFW, chmod, or /etc/ufw rollback action, especially on remote systems where a firewall mistake could interrupt access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (21)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
Success means:
- no critical audit findings
- no warning audit findings when practical
- gateway reachable
- required ports reachable only from approved sources

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/openclaw-fix-patterns.md (reported line 32)May include surrounding context.

Recommended fix pattern:

bash
chmod 700 <openclaw-credentials-dir>

Missing gateway auth rate limiting

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 8)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 9)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 17)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 18)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 19)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 20)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 28)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 42)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 43)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 49)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 55)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/ufw-playbook.md (reported line 56)May include surrounding context.

Use this on Ubuntu hosts that should accept only explicitly approved inbound traffic.

bash
sudo ufw default deny incoming
sudo ufw default allow outgoing

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/rollback-firewall.sh (reported line 7)May include surrounding context.

sh
STAMP="${1:-}"

if [[ -z "$STAMP" ]]; then
  echo "Usage: sudo bash $0 <timestamp>"
  echo "Example: sudo bash $0 20260316_164132"
  exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/rollback-firewall.sh (reported line 8)May include surrounding context.

sh
STAMP="${1:-}"

if [[ -z "$STAMP" ]]; then
  echo "Usage: sudo bash $0 <timestamp>"
  echo "Example: sudo bash $0 20260316_164132"
  exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/rollback-firewall.sh (reported line 13)May include surrounding context.

sh
STAMP="${1:-}"

if [[ -z "$STAMP" ]]; then
  echo "Usage: sudo bash $0 <timestamp>"
  echo "Example: sudo bash $0 20260316_164132"
  exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/verify-firewall.sh (reported line 15)May include surrounding context.

sh
STAMP="${1:-}"

if [[ -z "$STAMP" ]]; then
  echo "Usage: sudo bash $0 <timestamp>"
  echo "Example: sudo bash $0 20260316_164132"
  exit 1
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/rollback-firewall.sh (reported line 13)May include surrounding context.

sh
fi

if [[ "${EUID}" -ne 0 ]]; then
  echo "Please run as root: sudo bash $0 $STAMP"
  exit 1
fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script performs safety-critical file writes into /etc/ufw and reloads the firewall as root, which can affect system connectivity. Although the usage lines describe how to run the script, they do not warn the user that it will overwrite active firewall configuration and immediately apply the restored rules.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.