T03 · Remote Payload Retrieval and Execution
- Location
scripts/install.sh:35- Finding
Unaudited Remote Source Is Retrieved and Executed During Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Webclaw is a real web-dashboard admin skill, but its installer fetches unaudited code and installs privileged persistent services, so it needs careful review before installation.
Install only on a dedicated host or VM where you are comfortable granting sudo, changing nginx, running persistent services, and trusting code fetched from the publisher's GitHub tag and package registries. Review the retrieved release contents, templates, dependency manifests, nginx changes, and service units before running the installer, and avoid sharing reset passwords through chat or stored logs.
scripts/install.sh:35Unaudited Remote Source Is Retrieved and Executed During Installation
scripts/install.sh:154Downloaded Service Definitions Are Installed as Persistent System Services
scripts/install.sh:54Unverified Python and npm Dependencies Can Execute Installation Scripts
scripts/install.sh:96Unvalidated Domain Value Is Inserted into a Root-Owned nginx Configuration
scripts/db_query.py:369Passwords Are Exposed in Process Arguments and Plaintext Action Output
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
The database is auto-created on first API request at ~/.openclaw/webclaw/webclaw.sqlite. To reset it:
rm -f ~/.openclaw/webclaw/webclaw.sqlite
# Restart the API server — tables will be recreated
The skill is presented primarily as a browser-based dashboard, but the documented behavior includes privileged host administration actions such as restarting services, configuring nginx/Let's Encrypt, and directly manipulating authentication/session data. This mismatch is dangerous because users or orchestrators may approve or auto-invoke the skill under a lower-risk mental model, while it actually performs sensitive system and credential-management operations.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Security Model
- **HTTPS enforced** via Let's Encrypt (setup-ssl action)
- **JWT authentication** — access tokens (15 min) + refresh tokens (7 days, httpOnly cookies)
- **RBAC** — role-based permission checks before every skill action
- **Rate limiting** — 5/min auth, 30/min writes, 100/min general (nginx)
- **Audit logging** — all mutating actions logged to audit_log table
The restart-services action can restart host systemd services via sudo, giving the skill host-level operational control not clearly justified by a dashboard UI feature set. If this action is reachable through an agent or chat-triggered path, an attacker who gains access can disrupt service availability and potentially chain this privileged control with other weaknesses.
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
EXISTING_CONF="/etc/nginx/sites-enabled/webclaw"
fi
if [ -n "$EXISTING_CONF" ] && sudo nginx -t 2>/dev/null; then
sudo systemctl reload nginx
log "Nginx: reusing existing config at $EXISTING_CONF"
else
The script forcefully removes /etc/nginx/sites-enabled/default under sudo as part of installation. This is dangerous because it modifies or disables unrelated host configuration outside the skill's own namespace and can break existing web services or weaken an operator's intended server posture.
"$NGINX_CONF" > "$TEMP_CONF"
sudo cp "$TEMP_CONF" /etc/nginx/sites-enabled/webclaw
rm -f "$TEMP_CONF"
sudo rm -f /etc/nginx/sites-enabled/default 2>/dev/null || true
if sudo nginx -t 2>/dev/null; then
sudo systemctl reload nginx
The documentation instructs contributors to delete the SQLite database file to reset state, but it does not clearly warn that this permanently destroys local data. Even in a development context, destructive commands without explicit caution can cause unintended data loss, especially in a web admin product handling users, auth, and configuration.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill declares executable install and runtime behavior that clearly depends on shell, network, and environment/system capabilities, but it does not explicitly constrain or disclose tool scope via permissions or allowed-tools. In an infrastructure/admin skill that can install packages, clone code, configure nginx/certbot, and restart services, missing scope boundaries increases the chance of over-broad execution and unsafe agent invocation.
The activation triggers are broad and overlap with common administrative language such as 'login page,' 'users,' 'roles,' 'nginx,' and 'web admin.' For a skill that can create users, reset passwords, clear sessions, configure SSL, and restart services, loose triggering raises the risk of accidental or contextually inappropriate invocation leading to unauthorized or surprising state changes.
The skill explicitly supports password resets and even setting a user-supplied password, but it does not require secure handling guidance at the action point. This can lead to weak passwords being set in chat, passwords being exposed in logs/transcripts, or temporary credentials being transmitted insecurely, creating a direct account-compromise risk in an administrative web system.
This script exposes user management, session control, SSL management, and service operations through a Telegram-invoked management interface, which expands the attack surface beyond the stated browser-dashboard role. Hidden or weakly governed out-of-band admin channels are dangerous because they can bypass the primary UI's expected authentication, audit, and authorization controls.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
setup-ssl — Configure HTTPS with Let's Encrypt (--domain required)
renew-ssl — Check and renew SSL certificate
list-users — List web dashboard user accounts
create-user — Create a user (--email, --full-name, --role)
reset-password — Generate new password for a user (--email)
disable-user — Disable a user account (--email)
list-sessions — Show active sessions
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""Run a command and return (stdout, returncode). cmd is a list of args."""
if isinstance(cmd, str):
cmd = cmd.split()
result = subprocess.run(cmd, capture_output=True, text=True)
if check and result.returncode != 0:
_fail(f"Command failed: {' '.join(cmd)}\n{result.stderr[:500]}")
return result.stdout.strip(), result.returncode
The password reset flow accepts an operator-supplied password directly and immediately applies it, which enables silent credential setting rather than a safer reset-and-notify workflow. In a remotely invoked admin channel, this increases the risk of unauthorized account takeover, especially if actions are triggered through chat automation or insufficiently verified operators.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Webclaw post-install script.
# Sets up backend (venv), frontend (npm build), database, nginx, and systemd.
#
# Privileges required: sudo (for nginx config, systemd services, certbot)
# What this script does:
# 1. Clones full source from GitHub if api/web dirs are missing
# 2. Creates Python venv + installs pip dependencies
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Webclaw post-install script.
# Sets up backend (venv), frontend (npm build), database, nginx, and systemd.
#
# Privileges required: sudo (for nginx config, systemd services, certbot)
# What this script does:
# 1. Clones full source from GitHub if api/web dirs are missing
# 2. Creates Python venv + installs pip dependencies
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Webclaw post-install script.
# Sets up backend (venv), frontend (npm build), database, nginx, and systemd.
#
# Privileges required: sudo (for nginx config, systemd services, certbot)
# What this script does:
# 1. Clones full source from GitHub if api/web dirs are missing
# 2. Creates Python venv + installs pip dependencies
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Webclaw post-install script.
# Sets up backend (venv), frontend (npm build), database, nginx, and systemd.
#
# Privileges required: sudo (for nginx config, systemd services, certbot)
# What this script does:
# 1. Clones full source from GitHub if api/web dirs are missing
# 2. Creates Python venv + installs pip dependencies
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Webclaw post-install script.
# Sets up backend (venv), frontend (npm build), database, nginx, and systemd.
#
# Privileges required: sudo (for nginx config, systemd services, certbot)
# What this script does:
# 1. Clones full source from GitHub if api/web dirs are missing
# 2. Creates Python venv + installs pip dependencies
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Webclaw post-install script.
# Sets up backend (venv), frontend (npm build), database, nginx, and systemd.
#
# Privileges required: sudo (for nginx config, systemd services, certbot)
# What this script does:
# 1. Clones full source from GitHub if api/web dirs are missing
# 2. Creates Python venv + installs pip dependencies
No suspicious patterns detected.