Back to skill

Security audit

Auto-Updater Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about setting up daily updates, but it can automatically replace Clawdbot and every installed skill without fresh approval.

Install only if you are comfortable allowing a daily job to modify Clawdbot and every installed skill automatically. Prefer dry-run notifications, explicit approval before installation, pinned or verified versions, backups, and a clear rollback and disable process before enabling this in a sensitive environment.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
references/agent-guide.md:75
Finding

Unattended Scheduled Updates Create Persistent Cross-Session Execution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:54
Finding

Unpinned Automatic Updates Permit Supply-Chain Code Execution

Content
View full analysis
&1 | tee -a "$LOG_FILE" || true SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true echo "$SKILL_OUTPUT" >> "$LOG_FILE" ``` ### Technical Analysis The update procedure installs mutable latest releases and bulk-updates every installed skill without version pinning, checksum validation, signature verification, publisher allowlisting, review, or staging. The bytes installed during a scheduled run can therefore differ from those assessed when the auto-updater was reviewed. Global package replacement increases the affected scope because the modified Clawdbot installation may be used by multiple sessions or users. Bulk skill updates also aggregate the trust requirements of every installed skill and its publisher. In the implementation guide, `|| true` converts failures from `clawdbot doctor --yes` and `clawdhub update --all` into successful shell continuation. This can obscure failed migrations or partially completed updates and leave incompatible component versions installed. Although output is logged, the script does not fail closed or roll back the installation. ### Attack Path 1. An attacker compromises an upstream publisher account, dependency registry, update endpoint, or skill release channel. 2. The attacker publishes a malicious Clawdbot or skill release as the newest eligible version. 3. The automatic process resolves `clawdbot@latest`, `clawdbot update`, or `clawdhub update --all` to the attacker-controlled release. 4. No trus ...[truncated 1101 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

This is a real self-modification risk: the skill instructs the system to run clawdhub update --all, which changes installed skills automatically, and also updates Clawdbot itself. In an auto-update cron context, this is more dangerous because it repeatedly imports remote code changes without human review, amplifying supply-chain compromise and persistence risks.

Content

Scanner excerpt · references/agent-guide.md (reported line 61)May include surrounding context.

md
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")

# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide instructs the agent to enable unattended updates of both the core tool and all installed skills, but it does not include a clear user-facing warning that this grants remote packages ongoing authority to change code and behavior automatically. In this context, that increases supply-chain risk and can introduce breaking or malicious changes without fresh user review.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The guide recommends creating a persistent helper script in ~/.clawdbot/scripts and scheduling it for recurring use, which establishes durable behavior beyond the immediate session. In a security context, persistence increases the blast radius of any unsafe update logic because the behavior continues automatically and may be overlooked after initial setup.

Content

Scanner excerpt · references/agent-guide.md (reported line 21)May include surrounding context.

bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"

text

## Step 2: Create the Update Script (Optional)

For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The optional helper script creates a persistent log file under ~/.clawdbot/logs without clearly disclosing that ongoing artifacts will be written to disk. While not severe by itself, silent persistence can expose update history, package names, errors, and potentially sensitive command output to other local users or future processes depending on filesystem permissions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The setup confirmation example states that daily updates will run at "4:00 AM (America/Los_Angeles)", which imposes a specific locale/time zone in natural-language output. Because the file does not indicate that this is user-configurable or selected by user preference within the example, it can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.