Back to skill

Security audit

Agent Migration

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent agent-migration purpose, but its helper scripts handle high-impact local OpenClaw data without enough input validation.

Review before installing. Use only with trusted, simple agent IDs, back up OpenClaw config and session data first, and patch or avoid the helper scripts until they validate IDs, quote paths, use fixed-string or structured config checks, and prevent path traversal. Do not run cleanup deletion unless the user explicitly confirms it after migration is verified.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/copy_session_content.sh:4
Finding

Path Traversal Enables Session Disclosure and Unintended File Writes

Content
View full analysis
[copy|summary]" exit 1 fi OLD_DIR="$HOME/.openclaw/agents/$OLD_ID/sessions" NEW_DIR="$HOME/.openclaw/agents/$NEW_ID/sessions" mkdir -p "$NEW_DIR" if [[ ! -d "$OLD_DIR" ]]; then echo "Old session dir not found: $OLD_DIR" exit 2 fi mapfile -t FILES < <(find "$OLD_DIR" -maxdepth 1 -type f \( -name '*.jsonl' -o -name 'sessions.json' \) | sort) if [[ ${#FILES[@]} -eq 0 ]]; then echo "No session files found in $OLD_DIR" exit 3 fi case "$MODE" in copy) for f in "${FILES[@]}"; do base=$(basename "$f") cp "$f" "$NEW_DIR/migrated-from-$OLD_ID-$base" echo "COPIED $f -> $NEW_DIR/migrated-from-$OLD_ID-$base" done ;; summary) OUT="$NEW_DIR/migration-summary-from-$OLD_ID.txt" { echo "Migration summary from $OLD_ID to $NEW_ID" echo "Generated: $(date -Is)" echo printf 'Files:\n' printf '%s\n' "${FILES[@]}" } > "$OUT" echo "WROTE $OUT" ;; ``` ### Technical Analysis The script accepts `OLD_ID` and `NEW_ID` as positional arguments and interpolates them directly into filesystem paths. It does not enforce an agent-ID character allowlist, canonicalize the resulting paths, or verify that they remain beneath `$HOME/.openclaw/agents`. Traversal sequences such as `../` can therefore cause the source or destination to resolve outside the intended agent directory. The destination is created with `mkdir -p`, after which `cp` or shell redirection writes files into the resolved location. Existing destination files may be overwritten. A pre-existing symbolic link within the destination path could also redi ...[truncated 1639 chars]
Remediation
View remediation
&2 exit 1 } } validate_id "$OLD_ID" validate_id "$NEW_ID" ``` 2. Define and canonicalize a trusted base directory: ```bash AGENT_ROOT="$(realpath -- "$HOME/.openclaw/agents")" OLD_DIR="$(realpath -- "$AGENT_ROOT/$OLD_ID/sessions")" ``` 3. For a destination that may not exist, canonicalize its existing parent and construct the final path only after validating the ID. 4. Verify that resolved paths remain direct descendants of the trusted root: ```bash [[ "$OLD_DIR" == "$AGENT_ROOT/"* ]] || exit 1 [[ "$NEW_DIR" == "$AGENT_ROOT/"* ]] || exit 1 ``` 5. Reject symbolic links in the destination path and verify ownership and permissions before writing. 6. Avoid silent overwrites by using `cp --no-clobber`, generating collision-resistant filenames, or requiring explicit overwrite confirmation. 7. Set restrictive permissions, such as `umask 077`, before creating directories or files containing session data. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/inspect_agent_migration.sh:12
Finding

Regular Expression Injection Can Expose Unrelated Configuration Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/inspect_agent_migration.sh:16
Finding

Unquoted Agent Paths Permit Wildcard Expansion and Cross-Agent Enumeration

Content
View full analysis
/dev/null || true echo echo "== Session files ==" find ~/.openclaw/agents/$OLD_ID ~/.openclaw/agents/$NEW_ID -maxdepth 3 \( -name '*.jsonl' -o -name '*.json' -o -name '*.lock' \) 2>/dev/null | sort || true ``` ### Technical Analysis The paths passed to `ls` and `find` are not quoted. After parameter expansion, the shell performs pathname expansion on wildcard characters contained in `OLD_ID` or `NEW_ID`. For example, an ID containing `*` may expand to every matching agent directory beneath `~/.openclaw/agents`. Those expanded paths are then supplied to `ls` and `find`, causing the script to enumerate directories and session-related filenames belonging to agents outside the requested migration. This issue is distinct from command injection: shell metacharacters stored in a variable are not reparsed as command separators. The confirmed behavior is glob expansion and over-broad enumeration. ### Attack Path 1. An attacker supplies an agent ID containing a shell glob, such as `*` or a targeted wildcard pattern. 2. The variable is expanded in an unquoted command argument. 3. The shell resolves the wildcard against entries under `~/.openclaw/agents`. 4. Multiple unrelated agent paths are passed to `ls` and `find`. 5. Directory details and session-related filenames for those agents are printed. 6. The resulting metadata may be retained in terminal logs or agent conversation history. ### Impact Assessment The vulnerability permits reconnaissance of agent directories and session filenames accessible to the executing account. It can reveal agent identifiers, directory metadata, session file names, lock-file presence, and aspects of local agent ...[truncated 201 chars]
Remediation
View remediation
/dev/null || true find "$OLD_AGENT_DIR" "$NEW_AGENT_DIR" \ -maxdepth 3 \ \( -name '*.jsonl' -o -name '*.json' -o -name '*.lock' \) \ 2>/dev/null | sort || true ``` 3. Use `--` where supported to prevent values beginning with `-` from being interpreted as options. 4. Canonicalize and verify both paths against the trusted agent root before enumeration. 5. Minimize diagnostic output so that only migration-relevant paths are displayed. ]]>
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a comprehensive agent rename/migration workflow, including config updates, metadata repair, restart, verification, and cautious deletion handling. The supplied code chunk performs only a limited file operation on session data: it locates .jsonl and sessions.json files in the old agent's sessions directory and either copies them into the new agent's sessions directory under prefixed filenames or generates a migration summary text file. This is only a partial implementation of the declared workflow and does not itself carry out most of the stated actions. Because the actual behavior is materially narrower than the declared purpose, the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description describes an active migration/rename utility that changes OpenClaw state and manages a full migration workflow. The supplied code is a read-only inspection script: it accepts old/new IDs and uses grep, ls, and find to display relevant files and directories under ~/.openclaw and ~/claw-workspace. This is materially different from the declared purpose because the primary behavior is inspection rather than migration. While inspection could support verification, the code does not implement the main declared actions such as updating config, renaming, moving session data, fixing metadata, restarting, or asking before deletion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description presents a full migration/rename workflow with mutation steps and safety confirmation around deletion. The supplied code is a read-oriented verification script: it checks config text matches, lists directories and files, and runs a diagnostic command. This is a materially narrower and different primary purpose than the declared behavior. While verification is one component of the description, the script does not implement the core migration actions it claims to support.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
- Confirm old id, new id, new workspace, and whether model also changes.
- Migrate prior session content by default unless the user explicitly says not to.
- Do not skip migration just because a session does not look active.
- Do not hard-edit active lock files or force-rewrite a live session shell.
- Restart is required after migration.
- Never delete the old agent without a separate user confirmation.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's operational instructions are written entirely in Chinese, which imposes a specific language on users reading or following the checklist. There is no indication that the skill is region-specific, nor any opt-in or alternative language option, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all operational guidance in Chinese, which can impose a language requirement on users without opt-in. The file does not indicate that the skill is region-specific or provide an alternative language/localization choice, so it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.