Back to skill

Security audit

openclaw-all-backup

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward OpenClaw backup skill, but users should remember it copies sensitive OpenClaw data into another local directory.

Install only if you want a full local snapshot of ~/.openclaw. Treat the backup directory as sensitive because it may contain credentials, logs, workspace files, and agent state; protect its permissions, avoid sharing it, and verify backup integrity before relying on it for restore.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/openclaw-backup.sh:36
Finding

Suppressed Copy Failures Can Produce Incomplete Backups Reported as Successful

Content
View full analysis
/dev/null || true # 再拷贝隐藏文件 cp -a "$SOURCE_DIR"/.* "$BACKUP_PATH/" 2>/dev/null || true fi if [ $? -eq 0 ]; then echo "备份完成: $BACKUP_PATH" ``` ### Technical Analysis The fallback implementation suppresses diagnostics from both `cp` operations with `2>/dev/null` and unconditionally converts their exit status to success with `|| true`. The status evaluated by the subsequent `if [ $? -eq 0 ]` condition is therefore always zero in this branch, regardless of whether either copy operation failed. Failures can occur because of unreadable source files, insufficient destination capacity, filesystem errors, permission restrictions, or files changing during the backup. The script will nevertheless print a successful completion message and leave the partial destination in place. Using separate `*` and `.*` globs also makes the copy more fragile than copying the source directory contents through `"$SOURCE_DIR/."`. Dot-file glob behavior can vary between environments and may involve special directory entries on shells or platforms without protective behavior. ### Attack Path 1. The system does not have `rsync`, causing execution to enter the `cp` fallback branch. 2. An attacker with local influence over the source tree makes selected files unreadable, or an environmental condition such as insufficient disk capacity causes a copy operation to fail. 3. The affected `cp` command returns a nonzero status. 4. `2>/dev/null` hides the diagnostic, while `|| true` replaces the failure status with zero. 5. The final status check evaluates as successful and reports that the backup completed. 6. The user trusts the incomplete backup and may delete, replace, or damage the original ...[truncated 538 chars]
Remediation
View remediation
&2 exit 1 fi if ! cp -a "$SOURCE_DIR/." "$BACKUP_PATH/"; then echo "Error: backup failed" >&2 rm -rf -- "$BACKUP_PATH" exit 1 fi ``` Additional hardening measures: - Do not redirect copy errors to `/dev/null`; retain actionable diagnostics. - Check `mkdir` explicitly rather than continuing after destination creation fails. - For the `rsync` branch, explicitly test its exit status and clean up incomplete output on failure. - Consider copying into a temporary sibling directory and renaming it to the final timestamped name only after successful completion. - Optionally verify the result using an `rsync` dry run, file manifest, or checksums before reporting success. - Ensure cleanup paths remain constrained to a validated destination beneath `$HOME` before invoking `rm -rf`. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly states that backups include credentials, logs, workspace data, and all hidden files, but it does not clearly warn users that this creates a second copy of sensitive material on disk. That increases exposure to credential theft, unintended sharing, or retention of confidential logs if the backup directory has weaker controls or is later overlooked.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The duplicated RA2 finding refers to the same backup and restore flow, which preserves and reintroduces prior session/configuration state. Restoring such a snapshot can revive stale credentials, outdated trust decisions, or previously persisted sensitive context, making the copied state security-relevant rather than purely operational.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

TIMESTAMP=$(date +"%Y%m%d%H%M%S")

创建目录并拷贝

mkdir -p ~/.openclaw${TIMESTAMP} rsync -av ~/.openclaw/ ~/.openclaw${TIMESTAMP}/

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The duplicated RA2 finding refers to the same backup and restore flow, which preserves and reintroduces prior session/configuration state. Restoring such a snapshot can revive stale credentials, outdated trust decisions, or previously persisted sensitive context, making the copied state security-relevant rather than purely operational.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

TIMESTAMP=$(date +"%Y%m%d%H%M%S")

创建目录并拷贝

mkdir -p ~/.openclaw${TIMESTAMP} rsync -av ~/.openclaw/ ~/.openclaw${TIMESTAMP}/

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The restore steps rename the live configuration and replace it with a backup, which can disrupt active sessions, revert settings, or overwrite expected state if performed carelessly. Although the text says to act cautiously, it does not clearly warn about downtime, data divergence, or the need to stop dependent processes before restoring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content of the skill is fully Chinese, and the file does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking environment. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language content, including the header comment and all status/error messages, is written only in Chinese. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.