Back to skill

Security audit

ground-control

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent upgrade-checking purpose, but it needs Review because it can pull full runtime configuration that may include secrets and it documents some real-world changes/messages more broadly than its report-only framing suggests.

Install only if you are comfortable with a verification skill that can access full OpenClaw configuration, send test messages to configured channels, and propose approved config or cron repairs. Prefer a metadata-only config path if available, use dedicated ops/test channels for liveness checks, review any repair plan before approving it, and pin OpenClaw or skill versions for production upgrades.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/post-upgrade-verify.md:51
Finding

Full Runtime Configuration Is Retrieved Before Sensitive Fields Are Redacted

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/UPGRADE_SOP.md:10
Finding

Upgrade Procedure Permits Installation of an Unpinned Global Dependency

Content
View full analysis
Remediation
View remediation
`. 2. Pin the Skill installation to a specific release where the platform supports version-qualified installation. 3. Publish and verify cryptographic checksums or signed provenance for release artifacts. 4. Review release notes and package provenance before upgrading. 5. Prefer a restricted per-user or isolated installation over a global installation where operationally possible. 6. Disable or tightly control package lifecycle scripts when supported. 7. Test upgrades in a sandbox or staging environment before deployment. 8. Document a rollback procedure tied to a known-good immutable version. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (11)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/post-upgrade-verify.md (reported line 3)May include surrounding context.

md
# Post-Upgrade Verification — Agent Instructions

<!-- Execution prompt for post-upgrade verification. -->
<!-- Source of truth: MODEL_GROUND_TRUTH.md (index) in workspace root + refs/ground-truth/*.md (sub-files) -->
<!-- Trigger: after openclaw upgrade, or manual /verify command -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/MODEL_GROUND_TRUTH.md (reported line 2)May include surrounding context.

md
# MODEL_GROUND_TRUTH.md
<!-- Machine-readable model configuration ground truth for OpenClaw. -->
<!-- Snapshot: YYYY-MM-DDTHH:MM TZ | OpenClaw vX.X.X -->
<!-- Usage: After each upgrade, run /verify against this file. -->
<!-- Format: YAML code blocks for AI parsing, Markdown for human readability. -->

Self-Modification

High
Category
Rogue Agent
Confidence
70% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · templates/MODEL_GROUND_TRUTH.md (reported line 83)May include surrounding context.

yaml
# These checks run after each upgrade
# Add or remove checks based on your setup
checks:
  - name: primary_model
    command: "gateway config.get → agents.defaults.model.primary"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly states that Phase 5 sends a test message to each configured channel, which can contact external recipients and create side effects outside the local system. Even though this is framed as a liveness check, the lack of a prominent warning, recipient scoping guidance, or approval requirement for outbound test messages can lead to accidental notifications, information leakage through message content, or unintended contact with real users.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 81)May include surrounding context.

md
## Setup

### 1. Create your ground truth

Copy `templates/MODEL_GROUND_TRUTH.md` to your workspace root:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The recommended activation wording is "Install the ground-control skill," which is a natural-language phrase that could overlap with ordinary requests to install or use the skill. The file does not provide narrower trigger constraints, alternative exact invocation forms, or negative examples clarifying when this skill should and should not activate.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented procedure exceeds the declared scope of the skill by including repair behavior in an upgrade verification workflow that is supposed to be verification-only. This creates a trust and control problem: users may invoke the skill expecting read-only integrity checks, while the SOP normalizes state-changing actions that could alter configs, remove artifacts, or affect evidence needed to diagnose upgrade problems.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata says this capability is report-only and requires explicit approval before applying repairs, but the SOP instructs operators to run openclaw doctor --fix, which performs automatic remediation. That mismatch can cause unreviewed system changes before or during an upgrade, undermining the stated safety boundary and potentially masking configuration or state issues that should instead be surfaced for approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The principle section says to use OpenClaw native tools such as gateway, cron, sessions_spawn, and message for all checks and never bypass OpenClaw to test things it manages. Phase 5 then instructs use of openclaw directory groups list --channel discord --json, which is a broader CLI capability not listed in the native toolset and is not clearly justified by the manifest's verification scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guidance claims all checks should use native tools and that the agent should never bypass OpenClaw to test what it manages. Later instructions require openclaw directory groups list, which contradicts that documented constraint by introducing a separate direct command path for verification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest says the skill is for report-only verification and explicitly requires approval before applying repairs. This file goes beyond pure verification by defining concrete mutation steps using gateway config.patch and cron update, making repair behavior part of the operational instructions rather than just an external follow-up. Although approval is required, the behavior still exceeds a strictly report-only implementation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.