Back to skill

Security audit

openclaw-reliable-backup

Security checks for vulnerabilities and agentic risk

Overview

This backup skill is mostly purpose-aligned, but it creates and may email full OpenClaw backups containing credentials and other sensitive state without requiring encryption or tight dependency controls.

Install only if you are comfortable with full OpenClaw state, including credentials and workspace data, being copied into backup archives. Keep email sending disabled unless archives are encrypted first, use a trusted and verified email integration, store backups in a private directory, and review retention/deletion settings carefully.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:84
Finding

Credential Archives Are Stored and Potentially Transmitted Without Encryption

Content
View full analysis
压缩包.sha256` 3. **邮件通知**(如配置了邮件功能): a. 尝试发送邮件附件 ``` The security section acknowledges the sensitivity but does not require encryption: ```text - 备份包含 `credentials/` 目录,请妥善保管备份文件 - 建议对备份存储位置设置适当权限 ``` ### Technical Analysis The Skill directs the Agent to copy the entire `~/.openclaw/credentials/` directory into a standard ZIP archive. It then permits that archive to be sent as an email attachment. ZIP compression alone does not provide confidentiality, and the generated SHA-256 file only verifies integrity; it does not encrypt the archive or prevent unauthorized disclosure. Reading credentials is functionally related to a complete system-state backup. However, including credentials by default and transmitting them through email creates exposure beyond the minimum privileges necessary for ordinary configuration, workspace, or state backup. The Skill provides only advisory language about permissions and does not mandate restrictive filesystem modes, authenticated encryption, secure key management, recipient validation, or explicit consent specifically covering credential export. This is especially dangerous because the archive also contains identity, agent, messaging, workspace, and configuration data. Consequently, one compromised backup can expose several security domains si ...[truncated 1495 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:32
Finding

Unverified User-Selected Third-Party Skill Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README states that backups will be automatically sent to the user's email, but it does not prominently warn that backups may contain sensitive configuration and credentials. This creates a meaningful privacy and exfiltration risk because email is a broad transmission channel and may be stored on third-party servers, inboxes, and synced devices.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill guides installation/configuration of email functionality specifically to send backup files, while the backup set includes credentials/ and other sensitive OpenClaw state. Emailing such archives as attachments creates a serious confidentiality risk because secrets may be exposed through mailbox compromise, SMTP misconfiguration, insecure storage, or accidental forwarding.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The daily backup workflow directs creation of a full archive of sensitive directories and then emailing that archive, effectively transmitting the complete operational state of OpenClaw. In context this is especially dangerous because the archive includes credentials, identity, agents, workspace, and system data, making a single leak highly damaging.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README consistently presents all user-facing instructions and trigger phrases in Chinese, which can functionally force a specific language for use and setup. The file does not mention that the skill is Chinese-only, offer multilingual alternatives, or justify a region-specific language requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented manual trigger phrases are very broad conversational commands such as '执行每日备份' and '创建完整快照'. In an agent skill, vague natural-language activation can cause the skill to run during ordinary discussion or when referenced indirectly, leading to unintended backup creation of potentially sensitive local state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The backup-status examples are highly conversational ('最近有备份吗', '查看备份日志') and may overlap with ordinary user questions. While lower risk than destructive actions, ambiguous triggering can expose backup metadata or logs unexpectedly, especially if logs contain paths or operational details.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Cleanup trigger phrases like '清理本地备份' and '清理邮箱备份' are broad and map to deletion behavior. In an agent context, ambiguous natural-language triggers for destructive operations create a real risk of unintended deletion of local backups or emailed recovery copies, reducing recoverability when needed most.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 169)May include surrounding context.

md
### 常见问题
1. **备份失败:权限不足**
   bash
   sudo chown -R USER:USER /path/to/backup


2. **邮件发送失败**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 209)May include surrounding context.

md
2. **访问控制**:
   bash
   # 设置备份目录权限
   chmod 700 /path/to/backup


3. **多地备份**:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Using a broad trigger like “备份” makes accidental activation likely during ordinary conversation, which is dangerous because this skill performs filesystem operations and can handle sensitive data. In context, mis-triggering could cause unintended backup creation, disclosure prompts, or follow-on actions touching credentials and workspace contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

文件中的用户可见描述、交互提示和响应格式均固定为中文,没有说明这是面向特定中文用户群的区域性技能,也没有提供根据用户偏好切换语言的选项。按规则,这构成未经用户选择的语言/地区策略限制。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase “相关指令” is ambiguous and leaves activation boundaries undefined, increasing the chance that the skill will interpret unrelated requests as authorization to begin backup setup or execution. In a skill with command execution and file operations, unclear dispatch conditions raise the likelihood of unintended sensitive actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill can install an additional mail-management skill by executing clawhub install [技能ID], which expands capabilities beyond backup/restore into package installation. This introduces a supply-chain and privilege-expansion risk because a backup workflow should not dynamically fetch and install other skills based on conversational input.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The privacy statement claims no user data is collected, yet the backup scope explicitly includes credentials/, workspace/, identity, and other highly sensitive user state. This is misleading and can cause users to consent without understanding that secrets and personal working data are being copied and potentially transmitted.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.