Back to skill

Security audit

OpenClaw Self-Update (Zero Downtime)

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a real OpenClaw self-upgrade, but its script can modify the installed service without the user-confirmation gate promised in the instructions.

Install only if you intentionally want this skill to upgrade the local OpenClaw runtime. Before use, require a clear manual approval step, pin the exact OpenClaw version and registry, and treat rollback as availability recovery rather than protection from a compromised npm package.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
scripts/upgrade-openclaw.sh:203
Finding

Unconfirmed and Unpinned Global Package Installation

Content
View full analysis
/dev/null || echo "unknown") if [ "$TARGET_VERSION" = "unknown" ]; then TARGET_VERSION=$($NPM_BIN view openclaw version --registry https://registry.npmjs.org 2>/dev/null || echo "unknown") fi log "目标版本: v$TARGET_VERSION" if [ "$TARGET_VERSION" = "unknown" ]; then log "无法获取目标版本号,继续升级" elif [ "$TARGET_VERSION" = "$INSTALLED_VERSION" ]; then log "当前已是最新版 (v$INSTALLED_VERSION)" ok "无需升级,退出" exit 0 else RN=$(curl -sL --connect-timeout 10 \ "https://api.github.com/repos/openclaw/openclaw/releases/tags/v${TARGET_VERSION}" 2>/dev/null \ | python3 -c " import sys, json try: d = json.load(sys.stdin) body = d.get('body', '') name = d.get('name', '') html = d.get('html_url', '') lines = body.strip().split('\n') safe = [l for l in lines[:50] if l.strip()] print(f'--- {name} ---') for l in safe: print(l) if len(lines) > 50: print('...') print(f'--- Full: {html} ---') except: print('ParseError') " 2>/dev/null || echo "API 请求失败") log "=== Release Notes ===" echo "$RN" | while IFS= read -r l; do log "$l"; done log "=== End ===" BREAKING_HINT=$(echo "$RN" | grep -ci "breaking\|BREAKING\|重新.*密码\|密码.*变更\|credential\|re-auth\|reauthenticate\|password.*change\|migration" || true) if [ "$BREAKING_HINT" -gt 0 ]; then log "⚠️ 含疑似 breaking change 关键词,升级后留意" fi fi # ──────────────────────────────────────────────────────────────────────── step "阶段 3: 旁路备份" # ──────────────────────────────────────────────────────────────────────── BAKDIR="${RUN_DIR}-fallback" rm -rf "$BAKDIR" log "备份 $RUN_DIR → $BAKDIR ..." cp -r "$RUN_DIR" "$BAKDIR ...[truncated 4487 chars]
Remediation
View remediation
` and verify that it matches the resolved version. 2. **Pin the exact package version** - Validate `TARGET_VERSION` against a strict SemVer pattern. - Install the exact resolved version instead of the mutable default tag: ```bash "$NPM_BIN" install -g "openclaw@$TARGET_VERSION" \ --registry=https://registry.npmjs.org ``` 3. **Use one explicitly trusted registry** - Specify `https://registry.npmjs.org` for both metadata resolution and installation. - Do not silently use an arbitrary registry from user or project npm configuration. - Record and display the effective registry before approval. 4. **Verify package identity and integrity** - Retrieve the package manifest and expected `dist.integrity` value for the exact version. - Download the package tarball, verify its integrity before installation, and ensure the installed artifact corresponds to the approved version. - Where available, verify npm provenance or upstream release signatures. 5. **Control lifecycle-script execution** - Assess whether OpenClaw requires npm lifecycle scripts. - If it does not, install with `--ignore-scripts`. - If lifecycle scripts are required, inspect and verify the exact package artifact before allowing those scripts to execute. 6. **Fail closed** - Do not continue when `TARGET_VERSION` is `unknown`. - Abort if release metadata cannot be retrieved or parsed. - Abort if the resolved package version changes between review and installation. - Verify that the installed version exactly equals `TARGET_VERSION`, ...[truncated 765 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (10)

Self-Modification

High
Category
Rogue Agent
Confidence
96% confidence
Finding

This skill is explicitly designed for self-modification: it updates the running OpenClaw installation via 'npm install -g', manipulates service configuration, and restarts the service. Even with confirmation and rollback steps, self-updating code from remote registries is inherently high risk because it changes the trusted execution base and can introduce malicious or compromised releases.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
# self-update-zero-downtime

## 用途

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are very broad and include common conversational requests like '帮我更新' and '帮我升级一下'. That can cause the skill to activate in contexts where the user did not clearly intend a self-update operation, increasing the chance of unintended execution of a high-risk maintenance workflow.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
{
  "name": "self-update-zero-downtime",
  "version": "1.0.3",
  "description": "Zero-downtime OpenClaw upgrade with backup/rollback, release notes check, user confirmation. Auto-detects install type (npm vs git), path consistency check, prefix writability check.",
  "keywords": ["openclaw", "update", "upgrade", "zero-downtime", "blue-green"],

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · package.json (reported line 2)May include surrounding context.

json
{
  "name": "self-update-zero-downtime",
  "version": "1.0.3",
  "description": "Zero-downtime OpenClaw upgrade with backup/rollback, release notes check, user confirmation. Auto-detects install type (npm vs git), path consistency check, prefix writability check.",
  "keywords": ["openclaw", "update", "upgrade", "zero-downtime", "blue-green"],

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The script performs a destructive operation, rm -rf "$RUN_DIR"/*, on a path derived from service metadata and runtime discovery. If RUN_DIR is misdetected, attacker-influenced, symlink-manipulated, or unexpectedly points to a sensitive directory, this can recursively delete arbitrary user files before copying replacement content, causing severe data loss or destructive overwrite.

Content

Scanner excerpt · scripts/upgrade-openclaw.sh (reported line 305)May include surrounding context.

sh
# 需要把新代码同步到 RUN_DIR
if [ "$(cd "$RUN_DIR" && pwd)" != "$(cd "$ACTUAL_DIR" && pwd)" ]; then
    log "npm 更新了 $ACTUAL_DIR,但进程跑的是 $RUN_DIR,需同步..."
    rm -rf "$RUN_DIR"/*
    cp -r "$ACTUAL_DIR"/* "$RUN_DIR/"
    ok "已同步到 $RUN_DIR"
fi

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation condition allows '任何涉及 OpenClaw 自身升级的对话', which is ambiguous and lacks firm boundaries. In a skill that performs package installation, service restarts, backup, and rollback, ambiguous invocation materially raises the risk of accidental or premature self-modification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instruction uses the mandated form of address "主公确认," which implies a fixed interaction style and language choice rather than adapting to the user's preference. The file does not offer opt-in or alternative language/register behavior, so it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file's title, usage guidance, and operational messages are written entirely in Chinese, and the script continues this language choice throughout user-visible logs. This imposes a specific language on all users without opt-in or explanation, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/upgrade-openclaw.sh (reported line 217)May include surrounding context.

sh
exit 0
else
    RN=$(curl -sL --connect-timeout 10 \
        "https://api.github.com/repos/openclaw/openclaw/releases/tags/v${TARGET_VERSION}" 2>/dev/null \
        | python3 -c "
import sys, json
try:

External Script Fetching

Low
Category
Supply Chain
Confidence
15% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/upgrade-openclaw.sh (reported line 216)May include surrounding context.

sh
ok "无需升级,退出"
    exit 0
else
    RN=$(curl -sL --connect-timeout 10 \
        "https://api.github.com/repos/openclaw/openclaw/releases/tags/v${TARGET_VERSION}" 2>/dev/null \
        | python3 -c "
import sys, json

Static analysis

No suspicious patterns detected.