Back to skill

Security audit

Auto Updater Backup

Security checks for vulnerabilities and agentic risk

Overview

The skill’s update purpose is clear, but it sets up unattended daily jobs that can change Clawdbot and every installed skill without a fresh approval step.

Install only if you intentionally want Clawdbot to update itself and all installed skills automatically. Prefer changing it to check-only or dry-run mode, review exact versions before installing, limit updates to trusted skills, and confirm the cron timezone and removal path before enabling it.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:27
Finding

Persistent Unattended Update Execution Through a Scheduled Cron Job

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:51
Finding

Unpinned Automatic Installation of Mutable Core and Skill Updates

Content
View full analysis
/dev/null && npm list -g clawdbot &> /dev/null; then npm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v pnpm &> /dev/null && pnpm list -g clawdbot &> /dev/null; then pnpm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v bun &> /dev/null; then bun update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" else log "Running clawdbot update (source install)" clawdbot update 2>&1 | tee -a "$LOG_FILE" || true fi # Run doctor for migrations log "Running doctor..." clawdbot doctor --yes 2>&1 | tee -a "$LOG_FILE" || true # Capture new version CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown") # Update skills log "Updating skills via ClawdHub..." SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true ``` ### Technical Analysis The update workflow resolves the mutable `latest` package version and updates every installed Skill without version pinning, cryptographic integrity verification, source allowlisting, change review, sandbox testing, or an approval gate. A package version that was safe when the Skill was audited can therefore be replaced later by materially different code. The use of global package-manager operations increases the affected scope, while `clawdhub update --all` expands trust to every installed Skill and its current registry publisher. The helper script also uses `|| true` for source updates, migrations, and Skill updates. This suppresses ...[truncated 2110 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Self-Modification

High
Category
Rogue Agent
Confidence
97% confidence
Finding

clawdhub update --all performs self-modification by replacing installed skills from an external source, potentially altering the agent's capabilities and trust boundary on a recurring basis. In the context of a cron-driven auto-updater, this amplifies supply-chain risk because a compromised or malicious skill update would be fetched and activated automatically.

Content

Scanner excerpt · references/agent-guide.md (reported line 61)May include surrounding context.

md
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")

# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the system to automatically perform package-manager and skill updates on a daily schedule, which can modify installed software and write to disk without prominently warning the user about those changes. Auto-updating expands supply-chain risk and can introduce breaking changes or malicious upstream updates with no explicit confirmation step in the described workflow.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/agent-guide.md (reported line 21)May include surrounding context.

bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"

text

## Step 2: Create the Update Script (Optional)

For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs the agent to schedule unattended daily execution of package and migration commands that change the local installation and all installed skills. Because these updates occur automatically and without approval gates, rollback guidance, or pinning, a bad upstream release or compromised package/feed could silently modify the agent environment and affect future behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The example setup command hard-codes the timezone to America/Los_Angeles, which may cause the cron job to run at an unexpected local time for many users. While not directly a code-execution issue, unexpected execution timing makes unattended automatic updates less predictable and can increase operational risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.