Back to skill

Security audit

Openclaw Security Audit

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed, read-only OpenClaw security audit skill, but it can expose sensitive host security details to the active agent session.

Install only if you want the agent to perform a local security audit and are comfortable with it seeing host metadata such as processes, ports, OpenClaw configuration, credential file paths, cron entries, services, and logs. Run it from a trusted session, avoid root unless necessary, and review any proposed remediation commands before approving them.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:30
Finding

Overly Broad Host and Sensitive-Resource Reconnaissance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 30-127
Vulnerability Type: Excessive read access and host reconnaissance
Risk Level: Medium

Vulnerable Code Snippet

markdown
### 0) Identify Environment
1. Determine OS and host context:
   - `uname -a`
   - `cat /etc/os-release`
   - `hostname`
2. Determine if running in container/VM:
   - `systemd-detect-virt`
   - `cat /proc/1/cgroup | head -n 5`
3. Determine working dir and user:
   - `pwd`
   - `whoami`

### 1) Identify OpenClaw Presence & Version
1. Check gateway process:
   - `ps aux | grep -i openclaw-gateway | grep -v grep`
2. Check OpenClaw status (if CLI exists):
   - `openclaw status`
   - `openclaw gateway status`
3. Record versions:
   - `openclaw --version` (if available)

### 2) Network Exposure & Listening Services
1. List open ports:
   - `ss -tulpen`

### 3) Gateway Bind & Auth Configuration
1. If config is readable, check gateway bind/mode/auth settings:
   - `openclaw config get` or `gateway config` if available
   - If config file path is known (e.g., `~/.openclaw/config.json`), read it **read-only**.

### 7) Credentials & Secret Storage
1. Check for plaintext secrets locations:
   - `~/.openclaw/` directories
   - `.env` files, token dumps, backups
2. Identify world-readable or group-readable secret files:
   - `find ~/.openclaw -type f -perm -o+r -maxdepth 4 2>/dev/null | head -n 50`
3. Report only **paths**, never contents.

### 8) File Permissions & Privilege Escalation Risks
1. Check for risky permissions on key dirs:
   - `ls -ld ~/.openclaw`
   - `ls -l ~/.openclaw | head -n 50`
2. Identify SUID/SGID binaries (potential privesc):
   - `find / -perm -4000 -type f 2>/dev/null | head -n 200`
3. Flag if OpenClaw runs as root or with unnecessary sudo.

### 9) Process & Persistence Indicators
1. Check for unexpected cron jobs:
   - `crontab -l`
...[truncated 3711 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit user authorization before inspecting logs, credential locations, cron entries, system services, or privileged binaries.
  2. Split the workflow into a minimal default audit and clearly labeled advanced host-security checks.
  3. Scope filesystem searches to OpenClaw-owned directories by default. Do not run find / -perm -4000 unless the user explicitly requests a host-wide privilege-escalation review.
  4. Run all checks under a dedicated unprivileged account and prohibit automatic use of sudo or root execution.
  5. Prefer narrowly filtered process, socket, service, and log queries rather than unrestricted enumeration.
  6. Never print configuration values that may contain credentials. Report setting names and safe status summaries instead.
  7. Add mandatory redaction for tokens, authorization headers, cookies, API keys, session identifiers, credential-bearing URLs, usernames, and sensitive command arguments.
  8. Limit journal queries to fields and events needed for the stated check, and sanitize every returned line before including it in a report.
  9. Preserve the current read-only treatment of cron and systemd. Explicitly prohibit creating, modifying, enabling, or deleting scheduled tasks or services without separate informed approval.
  10. Document the exact access scope before execution and mark checks as UNKNOWN when the required information cannot be obtained without broader privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (6)

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
entify world‑readable or group‑readable secret files:
   - `find ~/.openclaw -type f -perm -o+r -maxdepth 4 2>/dev/null | head -n 50`
3. Report only **paths**, never contents.

### 8) File Permissions & Privilege Escalation Risks
1. Check for risky permissions on key dirs:
   - `ls -ld ~/.openclaw`
   - `ls -l ~/.openclaw | head -n 50`
2. Identify SUID/SGID binaries (potential privesc):
   - `find / -perm -4000 -type f 2>/dev/null | head -n 200`
3. Flag if OpenClaw runs as root or with unnecessary sudo.

### 9) Process & Persistence Indicators
1. Check for unexpected cron jobs:
   - `crontab -l`
   - `ls -la /etc/cron.* 2>/dev/null`
2. Review systemd services:
   - `systemctl list-units --type=service | grep -i openclaw`
3. Flag unknown services related to OpenClaw or skills.

### 10) Logs & Audit Trails
1. Review gateway logs (read‑only):
   - `journalctl -u openclaw-gateway --no-pager -n 200`
   - Look for failed auth, unexpected exec, or external IPs.

## Common Findings & Fix

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
- **Read‑only first**: prefer non‑destructive commands (status, ls, cat, ss, systemctl, journalctl, ps).
- **No exfiltration**: never send secrets off the host. If you detect secrets, **redact** them in your report.
- **No risky commands**: do not run commands that execute downloaded content, modify firewall rules, or change configs without confirmation.
- **Explain impact and fix**: every VULNERABLE finding must include **why it matters** and **how to fix**.

## Required Output Format

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
- Is `exec` enabled? Is approval required?
   - Are dangerous tools enabled (shell, browser, file I/O) without prompts?
2. Flag if:
   - `exec` runs without approvals in main session.
   - Tools can run on gateway/host with high privileges.

### 6) Skills & Supply‑Chain Risk Review

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
### 8) File Permissions & Privilege Escalation Risks
1. Check for risky permissions on key dirs:
   - `ls -ld ~/.openclaw`
   - `ls -l ~/.openclaw | head -n 50`
2. Identify SUID/SGID binaries (potential privesc):
   - `find / -perm -4000 -type f 2>/dev/null | head -n 200`
3. Flag if OpenClaw runs as root or with unnecessary sudo.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
### 9) Process & Persistence Indicators
1. Check for unexpected cron jobs:
   - `crontab -l`
   - `ls -la /etc/cron.* 2>/dev/null`
2. Review systemd services:
   - `systemctl list-units --type=service | grep -i openclaw`

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
- **Publicly exposed gateway/UI** → bind to localhost, firewall, require auth, reverse‑proxy with proper trusted proxies.
- **Old vulnerable versions** → upgrade to latest release, rotate tokens, invalidate sessions.
- **Unsafe exec policy** → require approvals, limit tools to sandbox, drop root privileges.
- **Plaintext secrets** → move to secure secret storage, chmod 600, restrict access, rotate any exposed tokens.
- **Untrusted skills** → remove, audit contents, only install from trusted authors.

## Report Completion

Static analysis

No suspicious patterns detected.