Back to skill

Security audit

Yggdrasil

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Yggdrasil networking purpose, but its install and troubleshooting guidance asks for powerful system and network privileges without enough safety guardrails.

Review before installing. Prefer official or distribution-maintained Yggdrasil packages, verify release keys or checksums, avoid piping remote content into sudo, do not run the full OpenClaw gateway as root, and grant only the minimum network capability needed for the Yggdrasil daemon.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/install.md:23
Finding

Unsafe APT Repository Bootstrap Grants Global Trust to an External Signing Key

Content
View full analysis

Vulnerability Details

File Location: references/install.md:23-31
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable code:

bash
# Add the Yggdrasil apt repo
curl -sL https://www.yggdrasil-network.github.io/apt-key.gpg | sudo apt-key add -
echo "deb http://www.yggdrasil-network.github.io/apt/ debian main" \
  | sudo tee /etc/apt/sources.list.d/yggdrasil.list

sudo apt update
sudo apt install yggdrasil

Technical Analysis

The installation procedure pipes a remotely downloaded signing key directly into the deprecated apt-key utility without verifying its expected fingerprint. Keys registered through apt-key are generally trusted globally by APT rather than being restricted to one repository.

The repository definition also uses plaintext HTTP. APT package signatures prevent a network attacker from simply replacing packages with unsigned content, but HTTP provides no repository-server authentication or transport confidentiality. The overall process remains vulnerable if the key-distribution endpoint, repository infrastructure, DNS resolution, or trusted signing key is compromised.

The installation also does not constrain the accepted package version. This increases exposure to an upstream compromise or unexpectedly changed release, although version pinning alone would not remedy the trust-bootstrap weakness.

Attack Path

  1. An attacker compromises the external key-distribution endpoint or otherwise causes it to serve an attacker-controlled signing key.
  2. The user executes the documented command with sudo.
  3. apt-key add - installs the attacker-controlled key into APT's global trust set without fingerprint validation.
  4. The attacker supplies a malicious Yggdrasil package from the configured repository and signs it with the newly trusted key.
  5. sudo apt update accepts the malicious repository metadata.
  6. sudo apt install yggdrasil executes p ...[truncated 919 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace apt-key with a repository-specific keyring.
  • Download the key over HTTPS using curl --fail --show-error --location.
  • Verify the downloaded key against a fingerprint published through an independently authenticated channel.
  • Store the verified key in a dedicated location such as /usr/share/keyrings/yggdrasil-archive-keyring.gpg.
  • Restrict trust to this repository using the signed-by= option.
  • Configure the repository itself with HTTPS.
  • Consider documenting a tested package version or checksum where operationally appropriate.
  • Prefer distribution-maintained packages when a sufficiently current and trusted package is available.

Example hardened repository configuration:

bash
curl --fail --show-error --location \
  https://www.yggdrasil-network.github.io/apt-key.gpg \
  --output /tmp/yggdrasil-key.gpg

gpg --show-keys --with-fingerprint /tmp/yggdrasil-key.gpg
# Compare the displayed fingerprint with an independently published value.

gpg --dearmor < /tmp/yggdrasil-key.gpg \
  | sudo tee /usr/share/keyrings/yggdrasil-archive-keyring.gpg >/dev/null
rm -f /tmp/yggdrasil-key.gpg

echo "deb [signed-by=/usr/share/keyrings/yggdrasil-archive-keyring.gpg] https://www.yggdrasil-network.github.io/apt/ debian main" \
  | sudo tee /etc/apt/sources.list.d/yggdrasil.list

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:43
Finding

Troubleshooting Guidance Recommends Unrestricted Root Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:43
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Vulnerable code:

text
3. **Permission denied**: On Linux, Yggdrasil needs `CAP_NET_ADMIN` to create a TUN interface. Run as root or use `setcap`.

Technical Analysis

Creating and configuring a TUN interface legitimately requires elevated network privileges on Linux. However, recommending that the affected process be run as root grants unrestricted host authority, which exceeds the minimum privilege needed for the declared networking operation.

The instruction is also ambiguous about whether the Yggdrasil daemon, the OpenClaw gateway, or another command should run as root. If interpreted as running the entire gateway as root, every plugin and gateway-facing component would inherit unrestricted privileges. Even assigning CAP_NET_ADMIN with setcap is security-sensitive and should identify the exact trusted executable, since this capability permits broad network administration rather than only TUN creation.

The text does not directly exploit privileges by itself, but it encourages an unsafe deployment configuration that materially increases the consequences of a later software vulnerability or malicious component.

Attack Path

  1. Yggdrasil reports a permission error while attempting to create or configure a TUN interface.
  2. The operator follows the troubleshooting guidance and starts Yggdrasil or the OpenClaw gateway as root.
  3. A network-facing vulnerability, malicious dependency, unsafe configuration, or compromised plugin causes code execution in that process.
  4. Because the process is running as root, the injected code executes with unrestricted system privileges.
  5. The attacker can modify protected files, access other users' data, change security controls, or establish host-level persistence.

If the operator instead assigns CAP_NET_ADMIN t ...[truncated 760 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the generic recommendation to run the daemon or gateway as root.
  • Explicitly state that the complete OpenClaw gateway should not run as root.
  • Run Yggdrasil under a dedicated, unprivileged service account.
  • Grant only the capabilities required by the documented Yggdrasil deployment, and apply them only to the canonical, root-owned binary.
  • Verify that the binary and its containing directories are not writable by unprivileged users before assigning file capabilities.
  • Prefer a hardened service manager configuration that grants bounded capabilities at runtime rather than permanently modifying a binary.
  • Add service hardening such as NoNewPrivileges=true, a restricted capability bounding set, filesystem protections, and syscall restrictions where compatible.
  • Document how to remove assigned capabilities during uninstall or troubleshooting.

Safer guidance should distinguish the Yggdrasil daemon from the OpenClaw gateway and direct users to the upstream platform-specific least-privilege configuration rather than suggesting unrestricted root execution.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (13)

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The Docker guidance advises adding NET_ADMIN and exposing /dev/net/tun, which materially increases container privileges and host networking access. While this may be operationally necessary for TUN-based networking, presenting it without strong guardrails can normalize high-risk container configurations that weaken isolation and increase the blast radius of a compromise.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
1. **Binary not on PATH**: Run `which yggdrasil`. If not found, add to PATH or reinstall.
2. **Gateway not restarted**: The plugin detects the binary at startup. Restart the OpenClaw gateway.
3. **Permission denied**: On Linux, Yggdrasil needs `CAP_NET_ADMIN` to create a TUN interface. Run as root or use `setcap`.
4. **Docker**: Container needs `--cap-add=NET_ADMIN` and `--device=/dev/net/tun`.

## After Install

Chaining Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The command chains a network fetch directly into a privileged command: 'curl ... | sudo apt-key add -'. This is a high-risk pattern because it removes inspection opportunities and allows remote content to influence root-level trust configuration in a single step.

Content

Scanner excerpt · references/install.md (reported line 25)May include surrounding context.

bash
# Add the Yggdrasil apt repo
curl -sL https://www.yggdrasil-network.github.io/apt-key.gpg | sudo apt-key add -
echo "deb http://www.yggdrasil-network.github.io/apt/ debian main" \
  | sudo tee /etc/apt/sources.list.d/yggdrasil.list

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/install.md (reported line 27)May include surrounding context.

md
# Add the Yggdrasil apt repo
curl -sL https://www.yggdrasil-network.github.io/apt-key.gpg | sudo apt-key add -
echo "deb http://www.yggdrasil-network.github.io/apt/ debian main" \
  | sudo tee /etc/apt/sources.list.d/yggdrasil.list

sudo apt update
sudo apt install yggdrasil

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description says to use the skill when "P2P fails" or when the user "asks about connectivity," which is broader than Yggdrasil-specific troubleshooting and could overlap with many ordinary networking requests. It does not clearly bound the trigger to Yggdrasil/OpenClaw IPv6 P2P scenarios or provide exclusions.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill instructs operators to run the service as root or use elevated network capabilities to resolve setup issues. Even though this is framed as legitimate troubleshooting, recommending root execution increases the chance of unnecessary privilege use and can expand damage if the daemon or surrounding workflow is compromised.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
1. **Binary not on PATH**: Run `which yggdrasil`. If not found, add to PATH or reinstall.
2. **Gateway not restarted**: The plugin detects the binary at startup. Restart the OpenClaw gateway.
3. **Permission denied**: On Linux, Yggdrasil needs `CAP_NET_ADMIN` to create a TUN interface. Run as root or use `setcap`.
4. **Docker**: Container needs `--cap-add=NET_ADMIN` and `--device=/dev/net/tun`.

## After Install

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The guide states that restarting the OpenClaw gateway will automatically start the daemon, but it does not clearly warn the user that this will trigger service startup and configuration generation on the host. This can surprise users and cause unintended system-affecting behavior, especially in environments where daemon startup or network changes require explicit approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The Debian/Ubuntu instructions direct users to add a third-party APT repository and install software with root privileges, but they do not clearly warn that this modifies system package trust and package sources. This is dangerous because users may execute privileged commands without understanding they are granting trust to an external repository and making persistent system-wide changes.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

This command pipes data fetched over the network directly into a privileged key-management command using sudo. That pattern is risky because any compromise of the source, transport, or command sequence could result in trusting a malicious signing key with root authority.

Content

Scanner excerpt · references/install.md (reported line 25)May include surrounding context.

bash
# Add the Yggdrasil apt repo
curl -sL https://www.yggdrasil-network.github.io/apt-key.gpg | sudo apt-key add -
echo "deb http://www.yggdrasil-network.github.io/apt/ debian main" \
  | sudo tee /etc/apt/sources.list.d/yggdrasil.list

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

Using sudo tee to write a repository definition into /etc/apt/sources.list.d creates a persistent system-wide package source under root control. While package installation commonly requires privilege, the document does not provide sufficient warning or validation guidance before making that trusted configuration change.

Content

Scanner excerpt · references/install.md (reported line 27)May include surrounding context.

md
# Add the Yggdrasil apt repo
curl -sL https://www.yggdrasil-network.github.io/apt-key.gpg | sudo apt-key add -
echo "deb http://www.yggdrasil-network.github.io/apt/ debian main" \
  | sudo tee /etc/apt/sources.list.d/yggdrasil.list

sudo apt update
sudo apt install yggdrasil

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
73% confidence
Finding

sudo apt update refreshes package metadata with elevated privileges after adding a new repository. By itself this is standard administration, but in this context it compounds the risk of trusting a newly added third-party source without strong validation guidance.

Content

Scanner excerpt · references/install.md (reported line 29)May include surrounding context.

echo "deb http://www.yggdrasil-network.github.io/apt/ debian main"
| sudo tee /etc/apt/sources.list.d/yggdrasil.list

sudo apt update sudo apt install yggdrasil

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
74% confidence
Finding

sudo apt install yggdrasil installs software system-wide with root privileges. This is normal for package management, but when preceded by adding an external repository, it can lead to installation of untrusted code if the repository or trust chain is compromised.

Content

Scanner excerpt · references/install.md (reported line 30)May include surrounding context.

| sudo tee /etc/apt/sources.list.d/yggdrasil.list

sudo apt update sudo apt install yggdrasil

text

> The plugin manages its own daemon. You do NOT need `systemctl enable yggdrasil` — the gateway controls it.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/install.md (reported line 33)May include surrounding context.

sudo apt install yggdrasil

text

> The plugin manages its own daemon. You do NOT need `systemctl enable yggdrasil` — the gateway controls it.

Verify:
```bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Moving a downloaded binary into /usr/local/bin with sudo performs a privileged system-wide installation. This is not inherently malicious, but without checksum or signature verification guidance it can cause users to place an unverified executable on their PATH.

Content

Scanner excerpt · references/install.md (reported line 60)May include surrounding context.

bash
tar -xzf yggdrasil-*.tar.gz
sudo mv yggdrasil /usr/local/bin/

Static analysis

No suspicious patterns detected.