Back to skill

Security audit

OpenClaw Multi-Instance

Security checks for vulnerabilities and agentic risk

Overview

The skill is aimed at linking OpenClaw instances, but it sets up broad persistent SSH/API trust and automatic memory sharing with insufficient safeguards.

Use this only between machines you own and trust. Avoid root accounts, do not expose the gateway over plaintext HTTP, verify SSH host keys and public-key fingerprints out of band, and do not let an agent automatically append keys to authorized_keys. Treat memory, identity, tools, and config files as sensitive data; keep synchronization manual or reviewed until the script is hardened with filename validation, safe argument passing, allowlists, backups, and a clear disable/removal procedure.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T06 · System Persistence

Error
Location
SKILL.md:69
Finding

Persistent Unrestricted SSH Authorization

Content
View full analysis
Append it to ~/.ssh/authorized_keys and run chmod 600" ``` ```bash echo "" >> ~/.ssh/authorized_keys ``` ### Technical Analysis The Skill directs either the local user or a remote agent to append a supplied SSH public key to `~/.ssh/authorized_keys`. This creates persistent, cross-session shell access to the target account. Passwordless SSH supports the declared file-transfer functionality, but an unrestricted authorized key grants substantially more permission than is required to synchronize specific memory files. The key is not constrained by source address, permitted command, file path, port-forwarding policy, or expiration. The public key may be communicated through the remote agent API. If that API session, bearer token, prompt, or response is compromised, an attacker can substitute their own key. The associated configuration template also uses `root` as its example SSH user, which could turn this persistent access into complete host control. ### Attack Path 1. The user asks an OpenClaw instance to establish multi-instance connectivity. 2. A public key is sent to the remote agent through the API or copied manually. 3. An attacker controlling or tampering with the API interaction substitutes an attacker-owned public key. 4. The remote agent appends the key to the target account's `authorized_keys`. 5. The attacker connects over SSH during any later session. 6. The attacker executes commands, accesses files, and uses all privileges granted to the target account. 7. If the target account is `root`, the a ...[truncated 537 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
SKILL.md:99
Finding

Recurring Agent Task Creates Persistent Bidirectional Memory Synchronization

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sync-memory.sh:9
Finding

Python Source Injection Through Interpolated Paths and Remote Filenames

Content
View full analysis
\n') f.writelines(remote_new) " 2>&1 fi done ``` ### Technical Analysis The script constructs Python source code inside a shell string and directly interpolates `LOCAL_WS`, `fname`, and `f` into single-quoted Python string literals. Shell quoting does not protect the generated Python program. If an interpolated path contains a single quote, newline, backslash sequence, or Python syntax, it can terminate the intended Python string and alter the generated program. `LOCAL_WS` is supplied through the third command-line argument. More importantly, `fname` is derived from files downloaded from the remote peer. Linux filenames can contain quotes and newline characters, allowing a malicious peer to ...[truncated 1791 chars]
Remediation
View remediation
\n") local_file.writelines(remote_new) PY ``` Additional hardening should include: - Validate remote memory filenames against `^[0-9]{4}-[0-9]{2}-[0-9]{2}\.md$`. - Reject filenames containing control characters, newlines, quotes, path separators, or unexpected encodings. - Canonicalize every source and destination path and verify that it remains inside the intended workspace. - Replace every `python3 -c` block that contains shell interpolation with a quoted heredoc and positional arguments. - Run synchronization as a dedicated unprivileged account. - Add automated tests covering quotes, newlines, spaces, traversal sequences, symlinks, and malformed filenames. - Avoid suppressing errors that could reveal failed validation or partial synchronization. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:43
Finding

Complete-Control Bearer Token Transmitted Over Plaintext HTTP

Content
View full analysis
:/v1/chat/completions \ -H 'Authorization: Bearer ' \ -H 'Content-Type: application/json' \ -d '{"model":"openclaw:main","messages":[{"role":"user","content":"ping"}]}' ``` The accompanying instructions state that the token is obtained from `gateway.auth.token` or the `OPENCLAW_GATEWAY_TOKEN` environment variable and warn that the token grants complete control. ### Technical Analysis The documented API request uses plain `http://` while transmitting a bearer token in the `Authorization` header. HTTP provides neither transport confidentiality nor server authenticity. Any party capable of observing network traffic can recover the bearer token. An active network attacker may also modify requests and responses or impersonate the remote OpenClaw gateway. The recommendation to use a private overlay network is advisory and is not enforced by the setup procedure. Because possession of a bearer token is sufficient for authentication, interception directly transfers the token's authority to the attacker. ### Attack Path 1. The user enables the remote Chat Completions endpoint. 2. The user follows the documented `http://` request example over a shared, routed, or otherwise untrusted network. 3. An attacker positioned on the network captures the `Authorization` header or redirects the connection to an impersonated gateway. 4. The attacker extracts the bearer token. 5. The attacker sends authenticated requests to the exposed OpenClaw endpoint. 6. The attacker exercises the remote-control capabilities available to that OpenClaw instance. 7. The token remains usable until it is rotated or revoked. ### Impact Assessment The documentation identifies the token as granting complete control. Token disclosure can therefor ...[truncated 414 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

描述强调多实例互联,包含互相通信、传文件、共享记忆等较广泛能力;但给出的代码块仅是一个“记忆同步脚本”。它接受远程主机和远程 workspace 路径,拉取远程 MEMORY.md 与 memory/ 目录中的 markdown 文件,在本地做简单的追加/去重合并,再把缺失的记忆文件和合并后的 MEMORY.md 推回远程。代码没有提供实例间消息通信、连接管理、服务发现、网络协议处理,也没有提供任意文件共享/传输功能,仅针对固定路径下的记忆文件。因此其实际行为只覆盖“同步记忆/共享记忆”的一部分,与声明中的“多实例互联、实例通信、传文件”不完全一致,属于描述大于实际能力的功能性不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

text
通过 API 告诉远程实例:
"请把以下公钥加到 authorized_keys:
<本地 cat ~/.ssh/id_ed25519.pub 的内容>
追加到 ~/.ssh/authorized_keys,chmod 600"

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Directing an agent to append keys to ~/.ssh/authorized_keys modifies a system trust boundary and grants persistent login capability to another principal. If the remote instance, API channel, or supplied key is malicious or spoofed, this creates durable unauthorized access that survives the immediate session.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

通过 API 告诉远程实例: "请把以下公钥加到 authorized_keys: <本地 cat ~/.ssh/id_ed25519.pub 的内容> 追加到 ~/.ssh/authorized_keys,chmod 600"

text

**如果远程有公钥**,本地加:

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Appending a remotely obtained public key into local ~/.ssh/authorized_keys grants persistent inbound access to the local machine. Because the key is fetched via another instance/API and not independently verified, an attacker controlling that channel could implant their own key and establish backdoor access.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

bash
# 获取远程公钥(通过 API 问远程实例要)
# 然后本地:
echo "<公钥内容>" >> ~/.ssh/authorized_keys

测试:ssh <用户>@<远程IP> "echo OK"

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
98% confidence
Finding

The pattern is correctly triggered because the skill explicitly instructs adding a key into authorized_keys, which is a classic persistence mechanism. In this context it is framed as convenience for multi-instance linkage, but it still enables silent, durable remote access and becomes especially dangerous because the same skill also promotes broad data sync and remote control between instances.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

Step 2: 配置 SSH 免密登录

如果本地有公钥,直接让远程实例帮忙加:

text
通过 API 告诉远程实例:
"请把以下公钥加到 authorized_keys:
<本地 cat ~/.ssh/id_ed25519.pub 的内容>
追加到 ~/.ssh/authorized_keys,chmod 600"

如果远程有公钥,本地加:

bash
# 获取远程公钥(通过 API 问远程实例要)
# 然后本地:
echo "<公钥内容>" >> ~/.ssh/authorized_keys

测试:ssh <用户>@<远程IP> "echo OK"

Step 3: 同步核心文件

通过 scp 把身份和记忆同步过去:

bash
scp IDENTITY.md SOUL.md USER.md MEMORY.md TOOLS.md AGENTS.md \
    <用户>@<远程IP>:<远程workspace路径>/

scp -r memory/ <用户>@<远程IP>:<远程workspace路径>/memory/

注意权限:远程文件要 chown 给正确的用户。

Step 4: 设置定期记忆同步

创建 cron job,定期执行记忆合并。

合并原则(核心):

  • 叠加,不覆盖 — 只增不减
  • M

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs broad synchronization and additive merging of sensitive memory and identity data across instances, including files that may contain secrets, personal history, and operational context. This creates a serious confidentiality risk and can also spread poisoned or untrusted memory across systems, amplifying compromise between instances.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
| `SKILL.md` | 本文件,给 OpenClaw 的搭建指南 |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes automatic cross-instance memory sharing and periodic synchronization, but it does not clearly explain that conversation memory may contain sensitive personal data, credentials, prompts, operational history, or other confidential context that will be transmitted and duplicated across machines. In a multi-host agent environment, this increases the attack surface and risk of privacy leakage, especially if one instance is less trusted or less secured than the others.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README describes workflows for pulling files, pushing scripts to servers, and remotely executing deployments, but it does not prominently warn users that these actions can modify or damage remote systems, overwrite files, execute unreviewed code, or expose sensitive data. Because the skill is specifically designed to let one OpenClaw instance control another, the lack of strong warnings and guardrails makes accidental or unsafe remote operations more likely.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs file reads and writes involving sensitive local and remote state, but it declares no explicit tool scope or permission boundaries. That increases the chance an agent can access or modify files beyond what a user expects during setup and synchronization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Broad trigger phrases can cause the skill to activate in ordinary conversations about servers, sync, or another machine, leading to unintended execution of highly sensitive setup steps. In this skill, accidental activation is more dangerous because it handles remote connectivity, memory sharing, and SSH trust establishment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill instructs exposing and using a remote chat-completions API over a network endpoint, with a bearer token used for full remote control. If this endpoint is exposed insecurely or over plain HTTP, interception, misuse, or unauthorized access could lead to full compromise of the remote OpenClaw instance.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

然后重启 Gateway:openclaw gateway restart

验证:用 curl 测试:

bash
curl -sS http://<远程IP>:<端口>/v1/chat/completions \
  -H 'Authorization: Bearer <TOKEN>' \

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

通过 API 告诉远程实例: "请把以下公钥加到 authorized_keys: <本地 cat ~/.ssh/id_ed25519.pub 的内容> 追加到 ~/.ssh/authorized_keys,chmod 600"

text

**如果远程有公钥**,本地加:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

L113 在定时配置中直接指定 tz: "Asia/Shanghai",属于自然语言/配置层面的固定 locale 约束,但文档没有说明这是可选项,也未限定该 skill 仅适用于该地区用户。对于通用技能,这会造成语言/地区策略上的不必要默认强制。

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON5 template contains user-facing natural-language comments entirely in Chinese, including setup guidance and warnings. Because the file does not offer an alternative language or indicate that the skill is intentionally region-specific, it creates a language/locale restriction that may conflict with organizational language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script's title, usage comments, and all user-facing output are written only in Chinese, which imposes a language choice on users without offering an alternative or documenting a locale-specific constraint. This matches the policy category for language or locale restrictions expressed in natural language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.