T09 · Insecure Skill Coding Practices
- Location
scripts/init-model.mjs:143- Finding
Automatic Disabling of TLS Certificate Verification for Proxy Downloads
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears intended to set up local OpenClaw embeddings, but its model download path weakens transport security and persists proxy information in ways users should review before installing.
Review this skill before installing, especially in shared, corporate, or proxied environments. Prefer a trusted CA configuration or manual verified model transfer instead of disabling TLS checks, avoid authenticated proxy URLs unless they will be protected, and confirm any OpenClaw config or gateway restart commands before running them.
scripts/init-model.mjs:143Automatic Disabling of TLS Certificate Verification for Proxy Downloads
scripts/init-model.mjs:323Downloaded Model Is Not Cryptographically Verified
scripts/init-model.mjs:288Proxy URLs May Be Logged and Persisted with Embedded Credentials
SKILL.md:126Unpinned CMake Package Installation from the Active Python Package Index
scripts/init-model.mjs:158Broad Pattern-Based SIGKILL Command Is Presented as a Gateway Restart Procedure
The script unconditionally disables TLS certificate verification when a proxy is used by setting NODE_TLS_REJECT_UNAUTHORIZED=0. This allows man-in-the-middle interception or tampering of the model download, defeating transport authentication and creating a supply-chain risk for the downloaded artifact.
The skill contains multiple shell commands that read environment variables, set proxy-related env vars, invoke external programs, and modify local configuration, but it declares no explicit tool scope or permissions boundary. In an agent ecosystem, that omission increases the chance the skill is executed with broader-than-necessary capabilities, making accidental misuse or overreach more likely.
The skill persists a working proxy address in a dotfile under the skill workspace, creating cross-session state that may expose internal network topology or cause later runs to silently reuse a sensitive proxy. If another user or process can read that file, it can leak infrastructure details or steer future downloads through an unintended intermediary.
mkdir -p ~/.openclaw/workspace/skills/openclaw-local-embedding
echo "http://the-working-proxy:port" > ~/.openclaw/workspace/skills/openclaw-local-embedding/.proxy
The skill recommends setting NODE_TLS_REJECT_UNAUTHORIZED=0, which disables certificate verification for Node.js HTTPS connections in that process. Even if described as temporary, this enables man-in-the-middle attacks during model download, allowing a malicious proxy or network adversary to tamper with downloaded artifacts or serve malicious content.
export HTTPS_PROXY="http://the-working-proxy:port" # use the confirmed proxy address export HTTP_PROXY="$HTTPS_PROXY" export NODE_USE_ENV_PROXY=1 export NODE_TLS_REJECT_UNAUTHORIZED=0 # set only if the proxy performs TLS inspection (MITM)
These environment variables are process-scoped. They do not affect other processes or the gateway.
This section reiterates use of NODE_TLS_REJECT_UNAUTHORIZED=0 and normalizes a dangerous fallback despite the warning text. The context makes the risk real because the same document directs users to download a model over that channel, so integrity and authenticity of the artifact cannot be relied upon once TLS checks are disabled.
These environment variables are process-scoped. They do not affect other processes or the gateway.
**Important:** `NODE_TLS_REJECT_UNAUTHORIZED=0` disables TLS certificate verification. Only set it in the download script/process. Never persist it to shell profiles.
### Step 3: Download and verify model
The troubleshooting section again advises disabling TLS verification when downloads fail behind a proxy. Repeating this in troubleshooting increases the likelihood operators adopt the insecure setting under pressure, exposing the software supply chain to interception and malicious model or dependency substitution.
(If `HTTPS_PROXY` is not set, try the Kuaishou cloud default: `curl --proxy http://10.74.176.8:11080 https://huggingface.co`)
- Check if a proxy was recorded from a previous run: `cat ~/.openclaw/workspace/skills/openclaw-local-embedding/.proxy`
- Ensure `NODE_USE_ENV_PROXY=1` is set in the download process.
- If the download still fails with TLS errors, set `NODE_TLS_REJECT_UNAUTHORIZED=0` — this is needed when the proxy performs TLS inspection (common in corporate/cloud environments).
### llama.cpp compilation fails
Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.
## Security notes
- Never persist `NODE_TLS_REJECT_UNAUTHORIZED=0` in shell profiles or system-wide configuration. It disables TLS verification for all Node.js processes.
- The proxy environment variables (`HTTPS_PROXY`, `NODE_USE_ENV_PROXY`) should only be set in the download script, not in the gateway runtime.
- After model download completes, the gateway runs fully offline. No proxy or network configuration is needed.
The script documentation states proxy settings are only process-scoped, but it also persists a working proxy URL to a file under the user's home directory for reuse across runs. That discrepancy can expose internal proxy infrastructure details and causes users to make trust decisions based on inaccurate security expectations.
Setting NODE_TLS_REJECT_UNAUTHORIZED to 0 creates an unsafe default that disables certificate validation for all HTTPS requests made by this process. In the context of downloading a model from a remote repository, this materially increases the risk of accepting tampered content from a hostile proxy or network attacker.
process.env.NODE_USE_ENV_PROXY = "1";
// Corporate/cloud proxies often perform TLS inspection (MITM); disable cert verification
// for this download process only. Never persist this in shell profiles.
process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0";
}
// ─── Print config instructions ──────────────────────────────────────────────
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
console.log();
console.log("Then restart the gateway:");
console.log(" pkill -9 -f openclaw-gateway || true");
console.log(" nohup openclaw gateway run --bind loopback --port 18789 --force > /tmp/openclaw-gateway.log 2>&1 &");
console.log(" (or: cd ~/.openclaw && ./manage.sh restart if manage.sh exists)");
console.log();
console.log("The first memory_search call will load the model (~1.6s).");
This markdown file includes direct modification of ~/.openclaw/openclaw.json, which can affect gateway behavior and potentially break the installation if edited incorrectly. While validation is mentioned, there is no explicit user-facing warning that manual JSON editing is risky and should be backed up or performed carefully.
Detected: suspicious.dangerous_exec, suspicious.insecure_tls_verification