T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/post-upgrade-verify.md:51- Finding
Full Runtime Configuration Is Retrieved Before Sensitive Fields Are Redacted
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent upgrade-checking purpose, but it needs Review because it can pull full runtime configuration that may include secrets and it documents some real-world changes/messages more broadly than its report-only framing suggests.
Install only if you are comfortable with a verification skill that can access full OpenClaw configuration, send test messages to configured channels, and propose approved config or cron repairs. Prefer a metadata-only config path if available, use dedicated ops/test channels for liveness checks, review any repair plan before approving it, and pin OpenClaw or skill versions for production upgrades.
scripts/post-upgrade-verify.md:51Full Runtime Configuration Is Retrieved Before Sensitive Fields Are Redacted
scripts/UPGRADE_SOP.md:10Upgrade Procedure Permits Installation of an Unpinned Global Dependency
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# Post-Upgrade Verification — Agent Instructions
<!-- Execution prompt for post-upgrade verification. -->
<!-- Source of truth: MODEL_GROUND_TRUTH.md (index) in workspace root + refs/ground-truth/*.md (sub-files) -->
<!-- Trigger: after openclaw upgrade, or manual /verify command -->
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# MODEL_GROUND_TRUTH.md
<!-- Machine-readable model configuration ground truth for OpenClaw. -->
<!-- Snapshot: YYYY-MM-DDTHH:MM TZ | OpenClaw vX.X.X -->
<!-- Usage: After each upgrade, run /verify against this file. -->
<!-- Format: YAML code blocks for AI parsing, Markdown for human readability. -->
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# These checks run after each upgrade
# Add or remove checks based on your setup
checks:
- name: primary_model
command: "gateway config.get → agents.defaults.model.primary"
The README explicitly states that Phase 5 sends a test message to each configured channel, which can contact external recipients and create side effects outside the local system. Even though this is framed as a liveness check, the lack of a prominent warning, recipient scoping guidance, or approval requirement for outbound test messages can lead to accidental notifications, information leakage through message content, or unintended contact with real users.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Setup
### 1. Create your ground truth
Copy `templates/MODEL_GROUND_TRUTH.md` to your workspace root:
The recommended activation wording is "Install the ground-control skill," which is a natural-language phrase that could overlap with ordinary requests to install or use the skill. The file does not provide narrower trigger constraints, alternative exact invocation forms, or negative examples clarifying when this skill should and should not activate.
The documented procedure exceeds the declared scope of the skill by including repair behavior in an upgrade verification workflow that is supposed to be verification-only. This creates a trust and control problem: users may invoke the skill expecting read-only integrity checks, while the SOP normalizes state-changing actions that could alter configs, remove artifacts, or affect evidence needed to diagnose upgrade problems.
The skill metadata says this capability is report-only and requires explicit approval before applying repairs, but the SOP instructs operators to run openclaw doctor --fix, which performs automatic remediation. That mismatch can cause unreviewed system changes before or during an upgrade, undermining the stated safety boundary and potentially masking configuration or state issues that should instead be surfaced for approval.
The principle section says to use OpenClaw native tools such as gateway, cron, sessions_spawn, and message for all checks and never bypass OpenClaw to test things it manages. Phase 5 then instructs use of openclaw directory groups list --channel discord --json, which is a broader CLI capability not listed in the native toolset and is not clearly justified by the manifest's verification scope.
The guidance claims all checks should use native tools and that the agent should never bypass OpenClaw to test what it manages. Later instructions require openclaw directory groups list, which contradicts that documented constraint by introducing a separate direct command path for verification.
The manifest says the skill is for report-only verification and explicitly requires approval before applying repairs. This file goes beyond pure verification by defining concrete mutation steps using gateway config.patch and cron update, making repair behavior part of the operational instructions rather than just an external follow-up. Although approval is required, the behavior still exceeds a strictly report-only implementation.
No suspicious patterns detected.