T01 · Skill Instruction Hijacking
- Location
references/Design_V4.5.md:15- Finding
Forced Injection of Restored Rules into the Agent Context
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a Review item because it installs a persistent OpenClaw recovery guardian with broad authority to kill processes, rewrite configuration and credential files, delete caches/logs, and reinstall packages globally.
Install only if you intentionally want a persistent local recovery service with authority to restart OpenClaw, alter sessions, restore configs, handle auth profile backups, and perform emergency reinstall steps. Before use, require manual confirmation for destructive scripts, pin and verify package versions, protect the backup vault with restrictive permissions or encryption, and review any restored AGENTS.md or MEMORY.md as untrusted text.
references/Design_V4.5.md:15Forced Injection of Restored Rules into the Agent Context
scripts/lobster-resurrect.sh:52Unpinned Global Installation of a Remote Package
scripts/lobster-snapshot.sh:2Authentication Profiles Backed Up Without Enforced Access Controls
scripts/lobster-guardian.sh:72Automatic Restoration of Unauthenticated Configuration and Credential Files
scripts/lobster-resurrect.sh:28Overbroad Forced Process Termination
scripts/lobster-ultimate-restore.sh:5Destructive Mirror Restoration Uses Hard-Coded Paths Without Integrity Validation
These sections describe force-killing processes, enforced session cleanup, configuration rollback, package uninstall/reinstall, and full mirror restore, all of which are destructive or system-altering actions. Without prominent warnings, authorization requirements, rollback validation, and operator confirmation, an agent or user could execute them in the wrong environment and cause outages, loss of state, or recovery from a compromised or stale backup.
If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.
If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.
If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.
If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.
If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.
The skill describes automatic optimization, doctor fixes, persistent background execution, port purging, rollback, and reinstallation guidance without prominent warnings about system-modifying behavior. This is dangerous because users may enable it expecting routine monitoring, while it can alter services, processes, files, and potentially critical host state.
The automatic rollback copies a backup openclaw.json over the live configuration with no integrity check, version check, or user confirmation. In this context, a stale or tampered backup could silently replace valid settings, disrupt service, erase user changes, or reintroduce insecure configuration, making the self-healing path a high-impact integrity risk.
The script's behavior materially exceeds the advertised 'HA guardian/self-healing' role by forcibly uninstalling software, deleting global paths, purging caches, terminating processes, and reinstalling from the network. In a skill context, that mismatch is dangerous because operators may authorize it expecting recovery automation, while it actually performs broad host-level destructive actions that can disrupt unrelated tooling and weaken change-control safeguards.
This section modifies system-wide package state and removes global installation paths, which is a privileged host-impacting capability not clearly justified by the stated guardian purpose. If triggered in the wrong environment, it can break shared Node.js tooling, remove packages used by other workloads, and create availability issues beyond OpenClaw itself.
The exact command rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null performs irreversible recursive deletion of a global package directory while suppressing errors. This combination is dangerous because it hides failures, bypasses safety checks, and changes host software state in a way that can be hard to audit or recover from.
npm uninstall -g openclaw --force 2>/dev/null
pnpm uninstall -g openclaw 2>/dev/null
# 物理删除 node_modules 中的残留路径 (针对 Mac/Linux)
rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null
rm -rf $(pnpm bin -g)/openclaw 2>/dev/null
# 3. 缓存与环境深度空场
The exact command rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null performs irreversible recursive deletion of a global package directory while suppressing errors. This combination is dangerous because it hides failures, bypasses safety checks, and changes host software state in a way that can be hard to audit or recover from.
npm uninstall -g openclaw --force 2>/dev/null
pnpm uninstall -g openclaw 2>/dev/null
# 物理删除 node_modules 中的残留路径 (针对 Mac/Linux)
rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null
rm -rf $(pnpm bin -g)/openclaw 2>/dev/null
# 3. 缓存与环境深度空场
The exact command rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null performs irreversible recursive deletion of a global package directory while suppressing errors. This combination is dangerous because it hides failures, bypasses safety checks, and changes host software state in a way that can be hard to audit or recover from.
npm uninstall -g openclaw --force 2>/dev/null
pnpm uninstall -g openclaw 2>/dev/null
# 物理删除 node_modules 中的残留路径 (针对 Mac/Linux)
rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null
rm -rf $(pnpm bin -g)/openclaw 2>/dev/null
# 3. 缓存与环境深度空场
Deleting ~/.npm/_cacache is a destructive operation that wipes shared package cache state for the current user. Although not inherently malicious, it can disrupt unrelated projects, force large redownloads, and create host-wide side effects inconsistent with a narrowly scoped service-repair action.
# 3. 缓存与环境深度空场
echo "Step 3/5: 排空系统级数据残留与缓存..."
rm -rf ~/.npm/_cacache
rm -rf ~/.pnpm-store
# 注意:这里小心不删除 Vault 备份
# 转移当前损坏的 .openclaw 文件夹名,而不是直接删除,作为最后的反悔机会
Deleting ~/.npm/_cacache is a destructive operation that wipes shared package cache state for the current user. Although not inherently malicious, it can disrupt unrelated projects, force large redownloads, and create host-wide side effects inconsistent with a narrowly scoped service-repair action.
# 3. 缓存与环境深度空场
echo "Step 3/5: 排空系统级数据残留与缓存..."
rm -rf ~/.npm/_cacache
rm -rf ~/.pnpm-store
# 注意:这里小心不删除 Vault 备份
# 转移当前损坏的 .openclaw 文件夹名,而不是直接删除,作为最后的反悔机会
Deleting ~/.pnpm-store removes a user-wide package store shared across projects, creating collateral impact well beyond OpenClaw. In the skill context this is more dangerous because the advertised guardian function does not justify destructive removal of broad development environment state.
# 3. 缓存与环境深度空场
echo "Step 3/5: 排空系统级数据残留与缓存..."
rm -rf ~/.npm/_cacache
rm -rf ~/.pnpm-store
# 注意:这里小心不删除 Vault 备份
# 转移当前损坏的 .openclaw 文件夹名,而不是直接删除,作为最后的反悔机会
mv ~/.openclaw ~/.openclaw_corrupted_$(date +%s) 2>/dev/null
Deleting ~/.pnpm-store removes a user-wide package store shared across projects, creating collateral impact well beyond OpenClaw. In the skill context this is more dangerous because the advertised guardian function does not justify destructive removal of broad development environment state.
# 3. 缓存与环境深度空场
echo "Step 3/5: 排空系统级数据残留与缓存..."
rm -rf ~/.npm/_cacache
rm -rf ~/.pnpm-store
# 注意:这里小心不删除 Vault 备份
# 转移当前损坏的 .openclaw 文件夹名,而不是直接删除,作为最后的反悔机会
mv ~/.openclaw ~/.openclaw_corrupted_$(date +%s) 2>/dev/null
The script's behavior directly contradicts the advertised purpose of a high-availability self-healing guardian: it unloads persistence, kills guardian processes, and deletes related artifacts. In the context of a skill presented as protective infrastructure, this mismatch is dangerous because it can disable monitoring and resilience while appearing legitimate to operators.
The forced deletion of the LaunchAgent plist removes the guardian's ability to restart and survive login sessions, effectively disabling protective functionality. In a skill marketed as HA/self-healing, silent removal of this artifact is especially dangerous because it undermines resilience and may evade casual review.
# 1. 卸载 LaunchAgent (停止系统级常驻)
launchctl unload ~/Library/LaunchAgents/ai.openclaw.lobster.guardian.plist 2>/dev/null
rm -f ~/Library/LaunchAgents/ai.openclaw.lobster.guardian.plist
# 2. 强制杀死正在运行的脚本进程与心跳检测循环
pkill -f "lobster-guardian.sh"
Deleting the primary guardian log without backup or confirmation destroys operational and forensic evidence. This can hinder incident response and make it harder to determine why the guardian stopped or whether tampering occurred.
pkill -f "ai.openclaw.lobster.guardian"
# 3. 清理缓存日志与诊断文件
rm -f "$HOME/.openclaw/lobster-guardian.log"
rm -f "$HOME/.openclaw/lobster-guardian-stdout.log"
rm -f "$HOME/.openclaw/lobster-guardian-stderr.log"
Removing the stdout log erases potentially useful execution history and diagnostic context. Coupled with process termination and persistence removal, this contributes to anti-forensic behavior by reducing visibility into what the guardian did before shutdown.
# 3. 清理缓存日志与诊断文件
rm -f "$HOME/.openclaw/lobster-guardian.log"
rm -f "$HOME/.openclaw/lobster-guardian-stdout.log"
rm -f "$HOME/.openclaw/lobster-guardian-stderr.log"
echo "✅ [LOBSTER-TERMINATOR] 全量清理完成。守护进程已停止,LaunchAgent 已注销,缓存已排空。🦞"
Deleting the stderr log removes error evidence that could be crucial for debugging failures or investigating tampering. In a supposed guardian component, destruction of error telemetry makes the environment less observable and less defensible.
# 3. 清理缓存日志与诊断文件
rm -f "$HOME/.openclaw/lobster-guardian.log"
rm -f "$HOME/.openclaw/lobster-guardian-stdout.log"
rm -f "$HOME/.openclaw/lobster-guardian-stderr.log"
echo "✅ [LOBSTER-TERMINATOR] 全量清理完成。守护进程已停止,LaunchAgent 已注销,缓存已排空。🦞"
The manual defines broad autonomous recovery, cleanup, rollback, and restore behaviors but does not clearly constrain when they may be invoked, by whom, or under what preconditions. In an agent skill context, vague activation boundaries increase the risk that destructive maintenance actions are triggered in inappropriate situations, causing unintended service disruption or data modification.
The README advertises potentially destructive maintenance operations such as nightly optimization, session purging, force restarts, port lock clearing, and configuration rollback without clearly warning users about possible data loss, service interruption, or system changes. In an automation/HA skill context, operators may install or enable these behaviors expecting benign monitoring, which increases the chance of unintended destructive actions on live environments.
The skill advertises persistent background behavior and shell-driven repair actions, but it declares no explicit tool scope or permissions. That mismatch is dangerous because it hides the skill's true execution capabilities from users and reviewers, increasing the chance of unauthorized system modification.
No suspicious patterns detected.