Back to skill

Security audit

LLM NeverDie

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly disclosed OpenClaw resilience monitor, but it needs Review because it installs a recurring background job and handles Telegram credentials with weak storage and cleanup safeguards.

Review this before installing if you use Telegram alerts or care about background jobs. Prefer file-only mode or environment-based secrets where possible, restrict .neverdie-config.json permissions to the owning user, avoid putting bot tokens in shell commands, rotate any token previously supplied on the command line, and manually verify the cron job and credential file are removed after uninstall.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.sh:22
Finding

Telegram bot token is exposed through command-line arguments and stored without enforced restrictive permissions

Content
View full analysis
&1 echo "OK (${CONFIG_FILE})" ``` The README also recommends supplying the secret directly on the command line: ```bash bash ~/.openclaw/workspace/skills/neverdie/scripts/setup.sh \ --telegram-token YOUR_BOT_TOKEN \ --chat-id YOUR_CHAT_ID \ --hostname my-openclaw \ --timezone America/New_York ``` ### Technical Analysis The setup interface accepts the Telegram bot token as a command-line argument. Depending on the operating system and shell configuration, command-line secrets may be exposed through: - Shell history files. - Process listings while setup is running. - Process-monitoring or auditing systems. - Terminal logs and copied command transcripts. The token is subsequently written in plaintext to `.neverdie-config.json`. The `fs.writeFileSync()` call does not specify a restrictive file mode, and the setup script does n ...[truncated 1997 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.sh:65
Finding

Uninstall terminates before removing the persistent monitor because CRON_FILE is not exported to Node.js

Content
View full analysis
!j.name.includes('NeverDie') && !j.name.includes('Fallback Monitor')); const removed = before - data.jobs.length; require('fs').writeFileSync(process.env.CRON_FILE, JSON.stringify(data, null, 2)); console.log(removed > 0 ? 'OK (removed ' + removed + ')' : 'none found'); " 2>&1 fi ``` The script defines `CRON_FILE` as a shell variable: ```bash CRON_FILE="${HOME}/.openclaw/cron/jobs.json" ``` However, the uninstall invocation does not pass it to the Node.js environment. By contrast, installation code correctly uses invocations such as: ```bash CRON_FILE="$CRON_FILE" node -e " ``` ### Technical Analysis A non-exported shell variable is not automatically available through `process.env`. During uninstall, the Node.js expression therefore normally receives `undefined` as `process.env.CRON_FILE`. The subsequent `readFileSync(process.env.CRON_FILE, 'utf8')` call fails instead of opening the intended cron configuration. Because the script begins with: ```bash set -euo pipefail ``` the nonzero Node.js exit status terminates the entire uninstall operation. Execution does not reach the later loop intended to delete: - `.neverdie-config.json` - The deployed `fallback-monitor.js` - Monitor state - The latest alert file The scheduled five-minute `systemEvent` job can consequently remain registered, while the plaintext credential configuration and deployed executable also remain on disk. The persistence itself is documented and required for the monitoring feature, so its installation is not considered a hidden back ...[truncated 1857 chars]
Remediation
View remediation
!j.name.includes('NeverDie') && !j.name.includes('Fallback Monitor') ); fs.writeFileSync(cronFile, JSON.stringify(data, null, 2)); console.log( before !== data.jobs.length ? 'OK (removed ' + (before - data.jobs.length) + ')' : 'none found' ); " ``` Additional hardening should include: 1. Validate that `CRON_FILE` is nonempty and points to the expected path before reading or writing it. 2. Do not allow a cron-removal failure to prevent cleanup of credential and state files. Record the error, continue local cleanup, and return a summarized failure status afterward. 3. Back up and atomically replace `jobs.json` to prevent corruption if the process is interrupted. 4. Verify after modification that no matching enabled job remains. 5. Remove `fallback-monitor.log` during uninstall or explicitly document why it is retained. 6. Report each resource that could not be removed and provide a manual cleanup command. 7. Add an automated install/uninstall test that runs with `CRON_FILE` unset in the parent environment and confirms complete removal. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill markets itself as 'ensuring' resilience, but the documented behavior mainly diagnoses configuration, copies a monitor, writes local config, schedules a cron job, and sends alerts. This mismatch can mislead operators into believing availability is enforced when in reality the skill does not guarantee failover safety and also performs broader local state changes not surfaced in the description.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

  1. Ollama — is the local model reachable?
bash
curl -s --max-time 3 http://localhost:11434/api/tags | node -e "
  let d='';process.stdin.on('data',c=>d+=c);process.stdin.on('end',()=>{
    try{const r=JSON.parse(d);console.log('Ollama:',r.models.map(m=>m.name).join(', '))}
    catch(e){console.log('Ollama: NOT REACHABLE')}

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/fallback-monitor.js (reported line 93)May include surrounding context.

js
state = JSON.parse(fs.readFileSync(STATE_FILE, 'utf8'));
      const now = Date.now();
      for (const [key, ts] of Object.entries(state.reported)) {
        if (now - ts > COOLDOWN_MS) delete state.reported[key];
      }
    } catch (e) {
      state = { lastPosition: 0, reported: {}, lastAlertAt: 0 };

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/setup.sh (reported line 100)May include surrounding context.

sh
fi

echo -n "Checking Ollama... "
if curl -s --max-time 3 http://localhost:11434/api/tags > /dev/null 2>&1; then
  MODELS=$(curl -s http://localhost:11434/api/tags | node -e "
    let d='';process.stdin.on('data',c=>d+=c);process.stdin.on('end',()=>{
      try{console.log(JSON.parse(d).models.map(m=>m.name).join(', '))}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to run shell and Node commands, read local configuration, copy files, modify permissions, and write persistent config, but it declares no tool/permission scope. That creates an authority gap where reviewers and users cannot accurately assess what the skill is allowed to do, increasing the chance of unintended command execution or filesystem access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill persists Telegram credentials in ~/.openclaw/workspace/.neverdie-config.json, creating durable local secret storage. If file permissions are weak, backups are exposed, or the workspace is shared, those credentials could be recovered and abused to send messages or access bot-related data.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
### 5. Configure Alerts

Ask the user for their Telegram bot token and chat ID, then write `~/.openclaw/workspace/.neverdie-config.json`.

To get these:
1. Message `@BotFather` on Telegram → `/newbot` → copy the token

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

The skill directs use of Telegram and references the Telegram API endpoint, which introduces external transmission of operational alerts and requires handling credentials for a third-party service. While the feature is optional and the documented payload is limited, it still expands the data boundary beyond the local system.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
To get these:
1. Message `@BotFather` on Telegram → `/newbot` → copy the token
2. Message the bot, then visit `https://api.telegram.org/bot<TOKEN>/getUpdates` to find the chat ID

Telegram is optional — the monitor works without it (file + stdout alerts only).

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill tells the agent to ask for a Telegram bot token and chat ID and write them to a local config file without an explicit warning at the action point about handling sensitive credentials. This can lead users to disclose secrets without understanding storage location, file permissions, retention, or exposure risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.