Back to skill

Security audit

Openclaw Local Embedding

Security checks for vulnerabilities and agentic risk

Overview

The skill appears intended to set up local OpenClaw embeddings, but its model download path weakens transport security and persists proxy information in ways users should review before installing.

Review this skill before installing, especially in shared, corporate, or proxied environments. Prefer a trusted CA configuration or manual verified model transfer instead of disabling TLS checks, avoid authenticated proxy URLs unless they will be protected, and confirm any OpenClaw config or gateway restart commands before running them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/init-model.mjs:143
Finding

Automatic Disabling of TLS Certificate Verification for Proxy Downloads

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/init-model.mjs:323
Finding

Downloaded Model Is Not Cryptographically Verified

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/init-model.mjs:288
Finding

Proxy URLs May Be Logged and Persisted with Embedded Credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:126
Finding

Unpinned CMake Package Installation from the Active Python Package Index

Content
View full analysis
= 3.19 ``` ### Technical Analysis The troubleshooting procedure directs users to install `cmake` through pip without pinning an audited version, requiring hashes, or specifying a trusted package index. The exact package installed therefore depends on mutable index state and the user’s pip configuration. A custom or compromised package index, dependency-confusion condition, or compromise of the expected package can cause arbitrary package installation code to run. The lack of version pinning also makes setup behavior non-reproducible and allows future incompatible or vulnerable versions to be selected. ### Attack Path 1. A user encounters the documented CMake version issue. 2. The user runs `pip3 install cmake` as instructed. 3. Pip resolves the package from the currently configured index or mirror. 4. An attacker controlling that source, or a compromised package release, supplies malicious package content. 5. Pip installs the package and executes any applicable installation-time behavior. 6. The malicious behavior runs with the privileges of the user executing pip. ### Impact Assessment A malicious package can read or alter files accessible to the installer account, execute commands, access that account’s environment and credentials, and establish further compromise. If the command is run with elevated privileges, the impact may extend system-wide; elevation is not instructed by the Skill and is not assumed. Even without malicious content, unpinned resolution can introduce incompatible or newly vulnerable versions into the environment. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/init-model.mjs:158
Finding

Broad Pattern-Based SIGKILL Command Is Presented as a Gateway Restart Procedure

Content
View full analysis
/tmp/openclaw-gateway.log 2>&1 &"); console.log(" (or: cd ~/.openclaw && ./manage.sh restart if manage.sh exists)"); ``` ### Technical Analysis The script instructs the user to run `pkill -9 -f openclaw-gateway`. The `-f` option matches the pattern against the full command line, potentially selecting more than the intended gateway instance. Signal 9 cannot be caught and prevents graceful shutdown, cleanup, state flushing, or lock release. This guidance differs from the safer documented command, `openclaw gateway restart`, which delegates process management to OpenClaw’s supported service mechanism. The use of `--force` when launching a replacement process may further conceal lifecycle or port-conflict problems rather than resolving them safely. The script only prints these commands; it does not execute them automatically. Exploitation therefore requires the user or automation to follow the emitted instructions. ### Attack Path 1. The script completes and displays the restart instructions. 2. A user or automation copies and executes the recommended `pkill` command. 3. Ev ...[truncated 778 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script unconditionally disables TLS certificate verification when a proxy is used by setting NODE_TLS_REJECT_UNAUTHORIZED=0. This allows man-in-the-middle interception or tampering of the model download, defeating transport authentication and creating a supply-chain risk for the downloaded artifact.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill contains multiple shell commands that read environment variables, set proxy-related env vars, invoke external programs, and modify local configuration, but it declares no explicit tool scope or permissions boundary. In an agent ecosystem, that omission increases the chance the skill is executed with broader-than-necessary capabilities, making accidental misuse or overreach more likely.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill persists a working proxy address in a dotfile under the skill workspace, creating cross-session state that may expose internal network topology or cause later runs to silently reuse a sensitive proxy. If another user or process can read that file, it can leak infrastructure details or steer future downloads through an unintended intermediary.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

  1. Once a working proxy is confirmed, record it for future runs:
bash
mkdir -p ~/.openclaw/workspace/skills/openclaw-local-embedding
echo "http://the-working-proxy:port" > ~/.openclaw/workspace/skills/openclaw-local-embedding/.proxy

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
96% confidence
Finding

The skill recommends setting NODE_TLS_REJECT_UNAUTHORIZED=0, which disables certificate verification for Node.js HTTPS connections in that process. Even if described as temporary, this enables man-in-the-middle attacks during model download, allowing a malicious proxy or network adversary to tamper with downloaded artifacts or serve malicious content.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

export HTTPS_PROXY="http://the-working-proxy:port" # use the confirmed proxy address export HTTP_PROXY="$HTTPS_PROXY" export NODE_USE_ENV_PROXY=1 export NODE_TLS_REJECT_UNAUTHORIZED=0 # set only if the proxy performs TLS inspection (MITM)

text

These environment variables are process-scoped. They do not affect other processes or the gateway.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
93% confidence
Finding

This section reiterates use of NODE_TLS_REJECT_UNAUTHORIZED=0 and normalizes a dangerous fallback despite the warning text. The context makes the risk real because the same document directs users to download a model over that channel, so integrity and authenticity of the artifact cannot be relied upon once TLS checks are disabled.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
These environment variables are process-scoped. They do not affect other processes or the gateway.

**Important:** `NODE_TLS_REJECT_UNAUTHORIZED=0` disables TLS certificate verification. Only set it in the download script/process. Never persist it to shell profiles.

### Step 3: Download and verify model

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
95% confidence
Finding

The troubleshooting section again advises disabling TLS verification when downloads fail behind a proxy. Repeating this in troubleshooting increases the likelihood operators adopt the insecure setting under pressure, exposing the software supply chain to interception and malicious model or dependency substitution.

Content

Scanner excerpt · SKILL.md (reported line 239)May include surrounding context.

md
(If `HTTPS_PROXY` is not set, try the Kuaishou cloud default: `curl --proxy http://10.74.176.8:11080 https://huggingface.co`)
- Check if a proxy was recorded from a previous run: `cat ~/.openclaw/workspace/skills/openclaw-local-embedding/.proxy`
- Ensure `NODE_USE_ENV_PROXY=1` is set in the download process.
- If the download still fails with TLS errors, set `NODE_TLS_REJECT_UNAUTHORIZED=0` — this is needed when the proxy performs TLS inspection (common in corporate/cloud environments).

### llama.cpp compilation fails

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

md
## Security notes

- Never persist `NODE_TLS_REJECT_UNAUTHORIZED=0` in shell profiles or system-wide configuration. It disables TLS verification for all Node.js processes.
- The proxy environment variables (`HTTPS_PROXY`, `NODE_USE_ENV_PROXY`) should only be set in the download script, not in the gateway runtime.
- After model download completes, the gateway runs fully offline. No proxy or network configuration is needed.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script documentation states proxy settings are only process-scoped, but it also persists a working proxy URL to a file under the user's home directory for reuse across runs. That discrepancy can expose internal proxy infrastructure details and causes users to make trust decisions based on inaccurate security expectations.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

Setting NODE_TLS_REJECT_UNAUTHORIZED to 0 creates an unsafe default that disables certificate validation for all HTTPS requests made by this process. In the context of downloading a model from a remote repository, this materially increases the risk of accepting tampered content from a hostile proxy or network attacker.

Content

Scanner excerpt · scripts/init-model.mjs (reported line 152)May include surrounding context.

js
process.env.NODE_USE_ENV_PROXY = "1";
  // Corporate/cloud proxies often perform TLS inspection (MITM); disable cert verification
  // for this download process only. Never persist this in shell profiles.
  process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0";
}

// ─── Print config instructions ──────────────────────────────────────────────

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/init-model.mjs (reported line 173)May include surrounding context.

js
console.log();
  console.log("Then restart the gateway:");
  console.log("  pkill -9 -f openclaw-gateway || true");
  console.log("  nohup openclaw gateway run --bind loopback --port 18789 --force > /tmp/openclaw-gateway.log 2>&1 &");
  console.log("  (or: cd ~/.openclaw && ./manage.sh restart  if manage.sh exists)");
  console.log();
  console.log("The first memory_search call will load the model (~1.6s).");

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file includes direct modification of ~/.openclaw/openclaw.json, which can affect gateway behavior and potentially break the installation if edited incorrectly. While validation is mentioned, there is no explicit user-facing warning that manual JSON editing is risky and should be backed up or performed carefully.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.insecure_tls_verification

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/init-model.mjs:73

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/init-model.mjs:152