Back to skill

Security audit

Openclaw Sys Guardian V4.1 Resurrection

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Review item because it installs a persistent OpenClaw recovery guardian with broad authority to kill processes, rewrite configuration and credential files, delete caches/logs, and reinstall packages globally.

Install only if you intentionally want a persistent local recovery service with authority to restart OpenClaw, alter sessions, restore configs, handle auth profile backups, and perform emergency reinstall steps. Before use, require manual confirmation for destructive scripts, pin and verify package versions, protect the backup vault with restrictive permissions or encryption, and review any restored AGENTS.md or MEMORY.md as untrusted text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
references/Design_V4.5.md:15
Finding

Forced Injection of Restored Rules into the Agent Context

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/lobster-resurrect.sh:52
Finding

Unpinned Global Installation of a Remote Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lobster-snapshot.sh:2
Finding

Authentication Profiles Backed Up Without Enforced Access Controls

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lobster-guardian.sh:72
Finding

Automatic Restoration of Unauthenticated Configuration and Credential Files

Content
View full analysis
> "$LOG_FILE" 2>&1 sleep 30 } ``` The resurrection path also restores configuration and authentication data directly: ```bash LATEST_BKP=$(ls -td $VAULT/* | head -1) if [ -z "$LATEST_BKP" ]; then echo "No valid backup was found." else cp "$LATEST_BKP/openclaw.json" "$HOME/.openclaw/" [ -f "$LATEST_BKP/auth-profiles.json" ] && cp "$LATEST_BKP/auth-profiles.json" "$HOME/.openclaw/agents/main/agent/" 2>/dev/null cp "$LATEST_BKP/"*.md "$HOME/.openclaw/workspace/" fi ``` ### Technical Analysis The scripts select the newest directory and copy its contents into live configuration locations without verifying a cryptographic signature, keyed digest, expected owner, permissions, regular-file status, schema, or semantic safety. The guardian then restarts the gateway, activating the restored configuration. The resurrection script can additionally replace authentication profiles and workspace Markdown files. This creates a trusted restore channel from a directory whose integrity is not established. The implementation also contradicts the README claim that rollback is MD5-verified: no MD5 or stronger integrity check appears in the reviewed scripts. ### Attack Path 1. An attacker gains write access to the backup vault or causes an attacker-controlled directory to become the newest backup. 2. The attacker modifies `openclaw.json`, `auth-profiles.json`, or restored workspace Markdown. 3. A health failure triggers L2 recovery, or a user invokes the resurrection script. 4. Th ...[truncated 654 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lobster-resurrect.sh:28
Finding

Overbroad Forced Process Termination

Content
View full analysis
/dev/null lsof -ti:18789 | xargs kill -9 2>/dev/null pkill -9 -f "openclaw" ``` The validator performs the same broad name-based termination as part of a test: ```bash echo "Step 1/3: Simulating an unexpected process termination." pkill -9 -f "openclaw" ``` The guardian also kills any process occupying the configured port: ```bash self_heal_L1() { log "L1 Recovery: Restarting gateway..." lsof -ti:18789 | xargs kill -9 2>/dev/null /opt/homebrew/bin/openclaw gateway restart --force >> "$LOG_FILE" 2>&1 sleep 30 } ``` ### Technical Analysis `pkill -f "openclaw"` matches the full command line rather than a verified process identity. It can terminate unrelated processes whose arguments happen to contain the string. Similarly, killing every PID returned by `lsof` for port 18789 does not verify the process owner, executable path, start time, or relationship to the managed gateway. The scripts immediately use `SIGKILL`, preventing graceful shutdown, state flushing, or cleanup. The validator executes the destructive operation as part of normal testing rather than isolating the test process. ### Attack Path 1. An unrelated legitimate process has `openclaw` in its command line, or a different service legitimately occupies port 18789. 2. The guardian enters recovery, the user runs resurrection, or the validator is invoked. 3. The broad match selects the unrelated process. 4. `SIGKILL` terminates it immediately. 5. Unsaved data, in-flight work, or service availability is lost. An attacker able to influence command lines or port allocation could also induce termination of targeted ...[truncated 404 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lobster-ultimate-restore.sh:5
Finding

Destructive Mirror Restoration Uses Hard-Coded Paths Without Integrity Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (67)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

These sections describe force-killing processes, enforced session cleanup, configuration rollback, package uninstall/reinstall, and full mirror restore, all of which are destructive or system-altering actions. Without prominent warnings, authorization requirements, rollback validation, and operator confirmation, an agent or user could execute them in the wrong environment and cause outages, loss of state, or recovery from a compromised or stale backup.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill is actually a validator/test harness that intentionally kills OpenClaw processes and reads backups/logs while posing as a remediation service, it creates outage risk under false pretenses. The context increases danger because a user seeking availability improvements could unknowingly deploy something that simulates failures or manipulates backups on a live host.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes automatic optimization, doctor fixes, persistent background execution, port purging, rollback, and reinstallation guidance without prominent warnings about system-modifying behavior. This is dangerous because users may enable it expecting routine monitoring, while it can alter services, processes, files, and potentially critical host state.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automatic rollback copies a backup openclaw.json over the live configuration with no integrity check, version check, or user confirmation. In this context, a stale or tampered backup could silently replace valid settings, disrupt service, erase user changes, or reintroduce insecure configuration, making the self-healing path a high-impact integrity risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's behavior materially exceeds the advertised 'HA guardian/self-healing' role by forcibly uninstalling software, deleting global paths, purging caches, terminating processes, and reinstalling from the network. In a skill context, that mismatch is dangerous because operators may authorize it expecting recovery automation, while it actually performs broad host-level destructive actions that can disrupt unrelated tooling and weaken change-control safeguards.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section modifies system-wide package state and removes global installation paths, which is a privileged host-impacting capability not clearly justified by the stated guardian purpose. If triggered in the wrong environment, it can break shared Node.js tooling, remove packages used by other workloads, and create availability issues beyond OpenClaw itself.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

The exact command rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null performs irreversible recursive deletion of a global package directory while suppressing errors. This combination is dangerous because it hides failures, bypasses safety checks, and changes host software state in a way that can be hard to audit or recover from.

Content

Scanner excerpt · scripts/lobster-resurrect.sh (reported line 39)May include surrounding context.

sh
npm uninstall -g openclaw --force 2>/dev/null
pnpm uninstall -g openclaw 2>/dev/null
# 物理删除 node_modules 中的残留路径 (针对 Mac/Linux)
rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null
rm -rf $(pnpm bin -g)/openclaw 2>/dev/null

# 3. 缓存与环境深度空场

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The exact command rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null performs irreversible recursive deletion of a global package directory while suppressing errors. This combination is dangerous because it hides failures, bypasses safety checks, and changes host software state in a way that can be hard to audit or recover from.

Content

Scanner excerpt · scripts/lobster-resurrect.sh (reported line 39)May include surrounding context.

sh
npm uninstall -g openclaw --force 2>/dev/null
pnpm uninstall -g openclaw 2>/dev/null
# 物理删除 node_modules 中的残留路径 (针对 Mac/Linux)
rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null
rm -rf $(pnpm bin -g)/openclaw 2>/dev/null

# 3. 缓存与环境深度空场

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

The exact command rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null performs irreversible recursive deletion of a global package directory while suppressing errors. This combination is dangerous because it hides failures, bypasses safety checks, and changes host software state in a way that can be hard to audit or recover from.

Content

Scanner excerpt · scripts/lobster-resurrect.sh (reported line 39)May include surrounding context.

sh
npm uninstall -g openclaw --force 2>/dev/null
pnpm uninstall -g openclaw 2>/dev/null
# 物理删除 node_modules 中的残留路径 (针对 Mac/Linux)
rm -rf /usr/local/lib/node_modules/openclaw 2>/dev/null
rm -rf $(pnpm bin -g)/openclaw 2>/dev/null

# 3. 缓存与环境深度空场

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Deleting ~/.npm/_cacache is a destructive operation that wipes shared package cache state for the current user. Although not inherently malicious, it can disrupt unrelated projects, force large redownloads, and create host-wide side effects inconsistent with a narrowly scoped service-repair action.

Content

Scanner excerpt · scripts/lobster-resurrect.sh (reported line 44)May include surrounding context.

sh
# 3. 缓存与环境深度空场
echo "Step 3/5: 排空系统级数据残留与缓存..."
rm -rf ~/.npm/_cacache
rm -rf ~/.pnpm-store
# 注意:这里小心不删除 Vault 备份
# 转移当前损坏的 .openclaw 文件夹名,而不是直接删除,作为最后的反悔机会

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Deleting ~/.npm/_cacache is a destructive operation that wipes shared package cache state for the current user. Although not inherently malicious, it can disrupt unrelated projects, force large redownloads, and create host-wide side effects inconsistent with a narrowly scoped service-repair action.

Content

Scanner excerpt · scripts/lobster-resurrect.sh (reported line 44)May include surrounding context.

sh
# 3. 缓存与环境深度空场
echo "Step 3/5: 排空系统级数据残留与缓存..."
rm -rf ~/.npm/_cacache
rm -rf ~/.pnpm-store
# 注意:这里小心不删除 Vault 备份
# 转移当前损坏的 .openclaw 文件夹名,而不是直接删除,作为最后的反悔机会

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Deleting ~/.pnpm-store removes a user-wide package store shared across projects, creating collateral impact well beyond OpenClaw. In the skill context this is more dangerous because the advertised guardian function does not justify destructive removal of broad development environment state.

Content

Scanner excerpt · scripts/lobster-resurrect.sh (reported line 45)May include surrounding context.

sh
# 3. 缓存与环境深度空场
echo "Step 3/5: 排空系统级数据残留与缓存..."
rm -rf ~/.npm/_cacache
rm -rf ~/.pnpm-store
# 注意:这里小心不删除 Vault 备份
# 转移当前损坏的 .openclaw 文件夹名,而不是直接删除,作为最后的反悔机会
mv ~/.openclaw ~/.openclaw_corrupted_$(date +%s) 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Deleting ~/.pnpm-store removes a user-wide package store shared across projects, creating collateral impact well beyond OpenClaw. In the skill context this is more dangerous because the advertised guardian function does not justify destructive removal of broad development environment state.

Content

Scanner excerpt · scripts/lobster-resurrect.sh (reported line 45)May include surrounding context.

sh
# 3. 缓存与环境深度空场
echo "Step 3/5: 排空系统级数据残留与缓存..."
rm -rf ~/.npm/_cacache
rm -rf ~/.pnpm-store
# 注意:这里小心不删除 Vault 备份
# 转移当前损坏的 .openclaw 文件夹名,而不是直接删除,作为最后的反悔机会
mv ~/.openclaw ~/.openclaw_corrupted_$(date +%s) 2>/dev/null

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's behavior directly contradicts the advertised purpose of a high-availability self-healing guardian: it unloads persistence, kills guardian processes, and deletes related artifacts. In the context of a skill presented as protective infrastructure, this mismatch is dangerous because it can disable monitoring and resilience while appearing legitimate to operators.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The forced deletion of the LaunchAgent plist removes the guardian's ability to restart and survive login sessions, effectively disabling protective functionality. In a skill marketed as HA/self-healing, silent removal of this artifact is especially dangerous because it undermines resilience and may evade casual review.

Content

Scanner excerpt · scripts/lobster-terminate.sh (reported line 9)May include surrounding context.

sh
# 1. 卸载 LaunchAgent (停止系统级常驻)
launchctl unload ~/Library/LaunchAgents/ai.openclaw.lobster.guardian.plist 2>/dev/null
rm -f ~/Library/LaunchAgents/ai.openclaw.lobster.guardian.plist

# 2. 强制杀死正在运行的脚本进程与心跳检测循环
pkill -f "lobster-guardian.sh"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Deleting the primary guardian log without backup or confirmation destroys operational and forensic evidence. This can hinder incident response and make it harder to determine why the guardian stopped or whether tampering occurred.

Content

Scanner excerpt · scripts/lobster-terminate.sh (reported line 16)May include surrounding context.

sh
pkill -f "ai.openclaw.lobster.guardian"

# 3. 清理缓存日志与诊断文件
rm -f "$HOME/.openclaw/lobster-guardian.log"
rm -f "$HOME/.openclaw/lobster-guardian-stdout.log"
rm -f "$HOME/.openclaw/lobster-guardian-stderr.log"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Removing the stdout log erases potentially useful execution history and diagnostic context. Coupled with process termination and persistence removal, this contributes to anti-forensic behavior by reducing visibility into what the guardian did before shutdown.

Content

Scanner excerpt · scripts/lobster-terminate.sh (reported line 17)May include surrounding context.

sh
# 3. 清理缓存日志与诊断文件
rm -f "$HOME/.openclaw/lobster-guardian.log"
rm -f "$HOME/.openclaw/lobster-guardian-stdout.log"
rm -f "$HOME/.openclaw/lobster-guardian-stderr.log"

echo "✅ [LOBSTER-TERMINATOR] 全量清理完成。守护进程已停止,LaunchAgent 已注销,缓存已排空。🦞"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Deleting the stderr log removes error evidence that could be crucial for debugging failures or investigating tampering. In a supposed guardian component, destruction of error telemetry makes the environment less observable and less defensible.

Content

Scanner excerpt · scripts/lobster-terminate.sh (reported line 18)May include surrounding context.

sh
# 3. 清理缓存日志与诊断文件
rm -f "$HOME/.openclaw/lobster-guardian.log"
rm -f "$HOME/.openclaw/lobster-guardian-stdout.log"
rm -f "$HOME/.openclaw/lobster-guardian-stderr.log"

echo "✅ [LOBSTER-TERMINATOR] 全量清理完成。守护进程已停止,LaunchAgent 已注销,缓存已排空。🦞"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manual defines broad autonomous recovery, cleanup, rollback, and restore behaviors but does not clearly constrain when they may be invoked, by whom, or under what preconditions. In an agent skill context, vague activation boundaries increase the risk that destructive maintenance actions are triggered in inappropriate situations, causing unintended service disruption or data modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises potentially destructive maintenance operations such as nightly optimization, session purging, force restarts, port lock clearing, and configuration rollback without clearly warning users about possible data loss, service interruption, or system changes. In an automation/HA skill context, operators may install or enable these behaviors expecting benign monitoring, which increases the chance of unintended destructive actions on live environments.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises persistent background behavior and shell-driven repair actions, but it declares no explicit tool scope or permissions. That mismatch is dangerous because it hides the skill's true execution capabilities from users and reviewers, increasing the chance of unauthorized system modification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.