Back to skill

Security audit

Openclaw Command Center

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local monitoring dashboard, but it exposes sensitive dashboard data and control routes too broadly by default.

Only run this on a trusted machine and do not expose port 3333 to a LAN, container bridge, VPN, or public network until the bind address and authorization model are fixed. Treat the dashboard as sensitive: it can reveal sessions, memory summaries, operators, usage, cron/job state, and it can trigger or modify jobs and local dashboard data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/index.js:630
Finding

Default Configuration Exposes an Unauthenticated Dashboard Beyond Loopback

Content
View full analysis
{ const profile = process.env.OPENCLAW_PROFILE; ``` ### Technical Analysis The configuration declares `localhost` as the default host, but the configured host is not supplied to `server.listen`. Calling `server.listen(PORT)` causes Node.js to listen on an unspecified address, commonly all available IPv4 or IPv6 interfaces, rather than enforcing loopback-only access. At the same time, authentication defaults to `none`. The authentication middleware is skipped entirely in this mode. The server exposes sensitive OpenClaw information, including session metadata, memory statistics, token usage, system vitals, cron data, operators, and Server-Sent Events. This behavior is inconsistent with the documented `http://localhost:3333` deployment model and exceeds the minimum network privilege needed for a local monitoring dashboard. ### Attack Path 1. A user installs the Skill and starts it using the documented `node lib/server.js` command. 2. No authentication environment variables are configured, so the mode defaults to `none`. 3. The server calls `listen(PORT)` without the configured `localhost` host. 4. A host with network access to the machine connects to TCP port 3333. 5. The attacker requests endpoints such as: - `GET /api/state` - `GET /api/sessions` - `GET ...[truncated 794 chars]
Remediation
View remediation
{ // Startup logging }); ``` 2. Default to an explicit loopback address such as `127.0.0.1` rather than a hostname that may resolve unexpectedly. 3. Refuse startup when authentication is `none` and the configured host is not loopback. 4. Emit a prominent warning if the server is configured for non-loopback access. 5. Require an authenticated mode for Tailscale, Cloudflare, LAN, container, or public deployments. 6. Add automated tests that verify the default server is unreachable through non-loopback interfaces. 7. Ensure the bundled `lib/server.js` is rebuilt after correcting the source. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/jobs.js:145
Finding

Unauthenticated API Routes Permit Job Execution and Operational State Changes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/auth.js:41
Finding

Tailscale and Cloudflare Authentication Trust Spoofable Identity Headers

Content
View full analysis
{ if (allowed === "*") return true; if (allowed === login) return true; if (allowed.startsWith("*@")) { const domain = allowed.slice(2); return login.endsWith("@" + domain); } return false; }); if (isAllowed) { return { authorized: true, user: { type: "tailscale", login, name, pic } }; } } ``` ```js if (mode === "cloudflare") { const email = (req.headers[AUTH_HEADERS.cloudflare.email] || "").toLowerCase(); if (!email) { return { authorized: false, reason: "Not accessed via Cloudflare Access" }; } const isAllowed = authConfig.allowedUsers.some((allowed) => { if (allowed === "*") return true; if (allowed === email) return true; if (allowed.startsWith("*@")) { const domain = allowed.slice(2); return email.endsWith("@" + domain); } return false; }); if (isAllowed) { return { authorized: true, user: { type: "cloudflare", email } }; } } ``` ### Technical Analysis The authentication logic treats reverse-proxy-provided headers as authoritative ident ...[truncated 1853 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/cerebro.js:168
Finding

Encoded Topic Identifier Allows Filesystem Path Traversal and File Modification

Content
View full analysis
{ body += chunk; }); ``` ```js // src/cerebro.js function updateTopicStatus(cerebroDir, topicId, newStatus) { const topicDir = path.join(cerebroDir, "topics", topicId); const topicFile = path.join(topicDir, "topic.md"); // Check if topic exists if (!fs.existsSync(topicDir)) { return { error: `Topic '${topicId}' not found`, code: 404 }; } // If topic.md doesn't exist, create it with basic frontmatter if (!fs.existsSync(topicFile)) { const content = `--- title: ${topicId} status: ${newStatus} category: general created: ${new Date().toISOString().split("T")[0]} --- # ${topicId} ## Overview *Topic tracking file.* ## Notes `; fs.writeFileSync(topicFile, content, "utf8"); ``` ```js // src/cerebro.js // Write updated content fs.writeFileSync(topicFile, content, "utf8"); ``` ### Technical Analysis The topic identifier comes from the URL and is decoded before being passed to the filesystem layer. It is then appended to the topics directory with `path.join` without validating its syntax or checking the canonical result. `path.join` normalizes `..` components. Therefore, a value containing encoded path separators and parent-directory components can cause `topicDir` to resolve outside the intended Cerebro topics root. The target directory must already exist because the function checks `fs.existsSync(topicDir)`. However, if an attacker identifies a reachable existing directory, the handler can create a new `topic.md` there or modify an existing one. T ...[truncated 1445 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (147)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Persisting privacy settings to local files, including hidden topics, sessions, crons, and hostname privacy options, is a write-capable feature not clearly disclosed in the summary. Because these settings influence what sensitive operational data is shown or hidden, undisclosed persistence affects both privacy expectations and local state integrity.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lib/server.js:461

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install-system-deps.sh:50

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/linear-sync.js:495

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/llm-usage.js:19

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/openclaw.js:46

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/iostat-leak.test.js:16

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/server.test.js:14