Back to skill

Security audit

Gateway Power Tools

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent OpenClaw administration reference, but it includes powerful commands that should only be run deliberately in a trusted admin environment.

Install this only if you administer OpenClaw. Treat --fix, delete/remove/rm, gateway restart/stop, memory index, chmod, SSH, and token commands as live operational actions: confirm targets, protect secrets from logs or shared terminals, back up important configuration, and prefer read-only status or audit commands before making changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description contains broad trigger phrases such as general admin tasks and generic requests like 'set up OpenClaw' or 'check OpenClaw status,' which can cause the skill to activate in loosely related contexts. In an administrative skill that includes operational and security-changing commands, overbroad invocation increases the chance that high-impact guidance is surfaced or followed when a narrower, task-specific skill would be more appropriate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation recommends state-changing auto-fix commands like 'openclaw doctor --fix' and 'openclaw security audit --deep --fix' without prominently warning that they modify system configuration or runtime state. In an ops skill, this is dangerous because an agent may treat them as routine diagnostics and execute remediation automatically, potentially causing unintended configuration drift, service disruption, or destructive changes during troubleshooting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file includes openclaw channels remove --channel telegram --delete, which appears to remove a channel and explicitly delete it, but the surrounding documentation does not warn that the action may be destructive or irreversible. Under the markdown-file criteria, user-facing instructions should disclose behaviors that could affect system integrity or data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The cheat sheet documents openclaw agents delete <agent-id> with no accompanying warning about deleting an agent. In markdown guidance, destructive operations that can affect user data or system configuration should be explicitly called out so users understand the risk before executing them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file lists authentication and token-handling commands, including token setup and paste operations, without any warning about secret exposure, shell history, terminal logging, or least-privilege handling. In an ops-focused skill, this increases the chance that administrators will paste sensitive credentials into insecure environments or share captured terminal output, leading to credential compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Commands like openclaw doctor --fix and openclaw security audit --fix imply automatic remediation, yet the cheat sheet provides no warning that they may change configuration or system state. Markdown documentation should disclose potentially system-altering behavior so users can make an informed decision before running it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The command openclaw cron rm <id> removes a scheduled task, but the cheat sheet does not warn that the action deletes an existing automation and may disrupt expected behavior. This is a system-affecting operation that should be explicitly disclosed in markdown guidance.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/security-audit.md (reported line 16)May include surrounding context.

md
### High

4. **Control UI wildcard origins** (`allowedOrigins: ["*"]`) — CSRF risk. Restrict to localhost.
5. **World-readable credentials** — WhatsApp session files at 644. Fix: `chmod 600`.
6. **Unencrypted node communication** — Set `tls: true` in `node.json`.

### Medium

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/security-audit.md (reported line 38)May include surrounding context.

md
### High

4. **Control UI wildcard origins** (`allowedOrigins: ["*"]`) — CSRF risk. Restrict to localhost.
5. **World-readable credentials** — WhatsApp session files at 644. Fix: `chmod 600`.
6. **Unencrypted node communication** — Set `tls: true` in `node.json`.

### Medium

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

This is a true vulnerability described by the document: world-readable credential files allow any local user or process with filesystem access to read session material, tokens, or secrets and impersonate the service. In the context of an administrative OpenClaw skill, this is especially dangerous because the referenced files likely grant access to bots, accounts, and gateway operations.

Content

Scanner excerpt · references/security-audit.md (reported line 16)May include surrounding context.

md
### High

4. **Control UI wildcard origins** (`allowedOrigins: ["*"]`) — CSRF risk. Restrict to localhost.
5. **World-readable credentials** — WhatsApp session files at 644. Fix: `chmod 600`.
6. **Unencrypted node communication** — Set `tls: true` in `node.json`.

### Medium

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/security-audit.md (reported line 21)May include surrounding context.

md
### Medium

7. **Permissive directory modes** — `credentials/`, `identity/`, `logs/`, `browser/`, `skills/` at 755. Fix: `chmod 700`.
8. **Unrestricted subagent access** — `allowAgents: ["*"]` lets any agent spawn as any other. Scope to specific lists.
9. **Group bots not requiring @mention** — Responds to every message, wasting tokens.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/security-audit.md (reported line 38)May include surrounding context.

md
### Medium

7. **Permissive directory modes** — `credentials/`, `identity/`, `logs/`, `browser/`, `skills/` at 755. Fix: `chmod 700`.
8. **Unrestricted subagent access** — `allowAgents: ["*"]` lets any agent spawn as any other. Scope to specific lists.
9. **Group bots not requiring @mention** — Responds to every message, wasting tokens.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The example openclaw config unset tools.web.search.apiKey modifies a credential-related setting, but the document does not explain that this may disable integrations or alter authentication behavior. While not necessarily destructive, it affects security-sensitive configuration and would benefit from explicit disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.