Back to skill

Security audit

Auto Updater.Tmp

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it sets up unattended daily updates that can change Clawdbot and every installed skill without per-update review.

Install only if you intentionally want a recurring background task that can modify Clawdbot and all installed skills. Prefer dry-run notifications, reviewing each update before applying it, limiting updates to trusted skills, avoiding `sudo` or forced updates for routine recovery, and confirming you know how to remove the cron job.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:25
Finding

Persistent Unattended Replacement of Agent and Skill Code

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/agent-guide.md:19
Finding

Persistent Update Helper Suppresses Failures and Encourages Unsafe Recovery

Content
View full analysis
> "$LOG_FILE" } log "Starting auto-update..." # Capture starting versions CLAWDBOT_VERSION_BEFORE=$(clawdbot --version 2>/dev/null || echo "unknown") # Update Clawdbot log "Updating Clawdbot..." if command -v npm &> /dev/null && npm list -g clawdbot &> /dev/null; then npm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v pnpm &> /dev/null && pnpm list -g clawdbot &> /dev/null; then pnpm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v bun &> /dev/null; then bun update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" else log "Running clawdbot update (source install)" clawdbot update 2>&1 | tee -a "$LOG_FILE" || true fi # Run doctor for migrations log "Running doctor..." clawdbot doctor --yes 2>&1 | tee -a "$LOG_FILE" || true # Capture new version CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown") # Update skills log "Updating skills via ClawdHub..." SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true echo "$SKILL_OUTPUT" >> "$LOG_FILE" log "Auto-update complete." ``` It then schedules unattended execution: ```bash clawdbot cron add \ --name "Daily Auto-Update" \ --cron "0 4 * * *" \ --tz "America/Los_Angeles" \ --session isolated \ --wake now \ --deliver \ --message "Run the daily auto-update routine: 1. Check and update Clawdbot: - For npm installs: npm update -g clawdbot@latest - For source installs: clawdbot update - Then run: clawdbot doctor --yes 2. Update all skills: ...[truncated 3601 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Self-Modification

High
Category
Rogue Agent
Confidence
97% confidence
Finding

The command clawdhub update --all causes the agent environment to self-modify by pulling and applying updates to all installed skills, which can change future agent behavior without granular review. In this context it is especially dangerous because it is combined with unattended scheduling, so new or compromised skill releases could be deployed automatically and persistently.

Content

Scanner excerpt · references/agent-guide.md (reported line 61)May include surrounding context.

md
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")

# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs users to configure unattended daily updates for both the core tool and all installed skills, which can cause automatic code changes without review or rollback planning. In a skill ecosystem, this increases supply-chain and stability risk because any compromised, malicious, or simply broken upstream release could be pulled and applied automatically across the installation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Creating a helper script at a stable path under ~/.clawdbot/scripts/auto-update.sh introduces session persistence by establishing a reusable artifact intended for future automated execution. In combination with the later cron instructions, this persistence increases risk because the update logic remains on disk and can continue making changes over time or be modified and reused unexpectedly.

Content

Scanner excerpt · references/agent-guide.md (reported line 21)May include surrounding context.

bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"

text

## Step 2: Create the Update Script (Optional)

For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The helper script creates persistent files under ~/.clawdbot/logs and performs update and migration commands, yet the guide presents it as an optional setup step without clearly disclosing these filesystem and software-modifying side effects up front. This is risky because users may authorize or copy the script without understanding that it writes logs, changes installed components, and runs maintenance commands automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs the agent to create a daily cron-driven auto-update routine that will repeatedly modify the installed bot and all skills in the background, but it does not prominently warn about the ongoing side effects or require explicit user acknowledgment at execution time. This is dangerous because it normalizes persistent, unattended system changes and can silently introduce new code or behavior after initial setup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The setup command specifies --tz "America/Los_Angeles", which imposes a locale-specific configuration in the primary usage example. The document does not clearly tell the user to choose their own timezone at setup time or label this value as merely illustrative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown example states that daily updates will run at "4:00 AM (America/Los_Angeles)", which implies a fixed locale/time zone in user-facing text. Under the policy, forcing a specific locale without user opt-in can be a natural-language policy violation unless it is clearly justified or optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.