Back to skill

Security audit

Gia Openclaw Setup Guide

Security checks for vulnerabilities and agentic risk

Overview

This setup guide is coherent, but it sends users through unverified code execution and persistent daemon setup without enough safety boundaries.

Review this skill carefully before installing. It is a setup guide, not an obviously deceptive package, but you should avoid pipe-to-shell installation unless you independently trust and verify the installer, protect bot tokens as secrets, keep personal identity files out of source control, and confirm how the daemon runs, stops, updates, and uninstalls.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:30
Finding

Unverified Remote Installer Executed Directly by Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 30
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://openclaw.ai/install.sh | bash

Technical Analysis

The installation instructions stream a remotely hosted shell script directly into Bash. The downloaded payload is not pinned to a version, saved for inspection, checked against a cryptographic digest, or verified using a trusted signature.

HTTPS protects the connection in transit but does not make the installer immutable. The effective code can change after this Skill has been reviewed. Compromise of the domain, hosting infrastructure, CDN, release process, or installer itself would allow arbitrary commands to be returned and executed with the privileges of the user running the command.

This behavior exceeds the minimum privileges necessary for an instructional setup Skill. The Skill can provide installation guidance without causing mutable external content to be executed immediately and without verification.

Attack Path

  1. An attacker compromises the installer host, its deployment process, or another component serving https://openclaw.ai/install.sh.
  2. The attacker replaces or modifies the installer with malicious shell commands.
  3. A user or agent follows the documented setup procedure.
  4. curl retrieves the attacker-controlled content.
  5. The shell pipeline passes that content directly to Bash without an inspection or integrity-verification step.
  6. Bash executes the payload using the current user's privileges.
  7. The payload can modify user-accessible files, access data and credentials available to that account, install additional components, or prepare persistent execution.

Impact Assessment

Successful exploitation provides arbitrary command execution with the privileges of the invoking user. This can expose files, environment variables ...[truncated 586 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not pipe network content directly into a shell.
  2. Download a version-pinned release artifact as a separate operation.
  3. Publish and verify a cryptographic signature from a trusted release key. A pinned SHA-256 digest may be used as an additional integrity check.
  4. Stop installation if signature or digest verification fails.
  5. Permit the user to inspect the downloaded installer before execution.
  6. Execute the verified artifact in a separate, explicit command only after informed user approval.
  7. Avoid elevated privileges unless a documented installation step specifically requires them.
  8. Prefer a trusted package manager or signed release package with reproducible provenance.
  9. Document the expected files, network endpoints, and system changes made by the installer.

A safer conceptual workflow is:

bash
curl -fSLo openclaw-install.sh "https://openclaw.ai/releases/PINNED_VERSION/install.sh"
sha256sum -c openclaw-install.sh.sha256
# Inspect the downloaded file and verify its publisher signature.
bash openclaw-install.sh

T06 · System Persistence

Error
Location
SKILL.md:31
Finding

Setup Flow Installs a Persistent Daemon Without Documented Security Boundaries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 31
Vulnerability Type: Persistent background service installation
Risk Level: High

Vulnerable Code:

bash
openclaw onboard --install-daemon

Technical Analysis

The onboarding procedure explicitly installs a daemon, causing OpenClaw components to continue operating after the interactive setup session ends. Persistent operation can be legitimate for an always-on automation platform, but the instructions install it as part of the default flow without documenting:

  • The service account or privilege level used by the daemon
  • The startup mechanism and installed service files
  • Network interfaces and ports exposed by the service
  • Files and messaging credentials accessible to the service
  • Whether installation requires elevation
  • How to disable and completely uninstall the daemon
  • Whether daemon installation is optional

The persistence risk is amplified because the openclaw executable is obtained immediately beforehand through an unverified curl | bash command. If that installation channel is compromised, the attacker-controlled executable can use the documented daemon installation step to obtain cross-session execution.

Attack Path

  1. An attacker compromises or alters the remote installer used on line 30.
  2. The installer places an attacker-controlled or modified openclaw executable in the user's environment.
  3. The user follows the next documented command, openclaw onboard --install-daemon.
  4. The modified executable registers itself or another component as a startup service.
  5. The installed service starts automatically and continues running beyond the setup session.
  6. The persistent process can repeatedly access resources available under its service identity, including OpenClaw configuration or channel credentials if those resources are readable by that identity.

The repository does not contain the implementati ...[truncated 971 chars]

Remediation
View remediation

Remediation Suggestions

  1. Separate ordinary onboarding from daemon installation.
  2. Make persistent service installation opt-in rather than part of the default setup path.
  3. Require explicit user confirmation that explains why persistence is needed.
  4. Install only a version-pinned, cryptographically verified executable.
  5. Run the daemon under a dedicated least-privileged account where supported.
  6. Restrict filesystem access to the minimum directories necessary for OpenClaw operation.
  7. Bind network listeners only to required interfaces and avoid public exposure by default.
  8. Store bot tokens and API credentials using restrictive permissions or an appropriate secret store.
  9. Document the service manager, service file location, executable path, process identity, network bindings, logs, and startup conditions.
  10. Provide tested commands for stopping, disabling, and completely uninstalling the daemon.
  11. Display the proposed service definition before installation and require approval for any elevated operation.
  12. Offer a foreground, nonpersistent mode for initial testing before enabling automatic startup.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (6)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

Fetching and immediately executing an external install script is a classic arbitrary code execution risk. The skill context increases danger because it is a setup guide aimed at new users, who are more likely to copy-paste commands without independently validating the source or script contents.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

Step 2: Install OpenClaw

bash
curl -fsSL https://openclaw.ai/install.sh | bash
openclaw onboard --install-daemon

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The use of '| bash' chains network retrieval directly into shell execution, eliminating any opportunity for inspection and making compromise of the remote content immediately exploitable. In a user-facing installation skill, this pattern strongly encourages unsafe operator behavior and amplifies the blast radius of any supply-chain compromise.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

Step 2: Install OpenClaw

bash
curl -fsSL https://openclaw.ai/install.sh | bash
openclaw onboard --install-daemon

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup instructions tell users to execute a remotely fetched installer without any warning, verification step, or explanation of trust assumptions. This is dangerous because a compromised domain, CDN, TLS interception, or malicious script update could lead to arbitrary code execution on the user's machine during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to connect third-party channels using bot tokens but does not warn that these are sensitive credentials or explain safe handling. Users may paste tokens into insecure places, store them in plaintext, or expose them through logs or chat history, enabling account takeover of connected bots and services.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The skill directs users to create persistent identity and user-information files in the workspace, including personality, operating procedures, and human information, without any privacy, minimization, or access-control guidance. This can lead to unnecessary storage of sensitive personal or behavioral data that may later be exposed through source control, backups, or other skills reading the workspace.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

text

### Step 4: Configure Identity
Create these files in the workspace:
- `SOUL.md` — Agent personality and behavior
- `USER.md` — Information about the human
- `AGENTS.md` — Operating procedures

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
79% confidence
Finding

The troubleshooting advice includes a sudo ownership change command without warning about reviewing the target path or understanding why elevated privileges are needed. While common in admin workflows, encouraging copy-paste use of privileged commands can cause misuse or normalize unnecessary root execution.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
### Common Issues
- **Node.js version too old**: `nvm install 22 && nvm use 22`
- **Permission denied**: `sudo chown -R $USER ~/.openclaw`
- **Bot not responding**: Check `openclaw status` and `openclaw gateway logs`
- **Channel connection failed**: Verify token, check firewall/proxy settings

Static analysis

No suspicious patterns detected.