Back to skill

Security audit

Security Audit for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local security-audit helper, though its logs may retain sensitive command details if users enable or use detailed logging.

Install only if you want local audit logging. Do not pass API keys, bearer tokens, private key contents, full request bodies, or secret-bearing commands into the log detail field, and review permissions on logs/security-audit.log if the machine is shared. Enable message notifications or cron-based periodic audits only when you understand which channel will receive alerts and when they will run.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/log_event.sh:25
Finding

Plaintext Sensitive-Data Logging and JSONL Log Injection

Content
View full analysis
/dev/null || date +"%Y-%m-%dT%H:%M:%S+00:00") # Build JSON (portable, no jq required) ENTRY=$(printf '{"ts":"%s","level":"%s","category":"%s","summary":"%s","detail":"%s","action":"%s"}\n' \ "$TS" "$LEVEL" "$CATEGORY" \ "$(echo "$SUMMARY" | sed 's/"/\\"/g')" \ "$(echo "$DETAIL" | sed 's/"/\\"/g')" \ "$ACTION") echo "$ENTRY" >> "$LOG_FILE" echo "[security-audit] Logged: $LEVEL $CATEGORY — $SUMMARY" ``` ### Technical Analysis The logger accepts a full command, file path, or payload in the `DETAIL` argument and writes it verbatim to a persistent log. Commands commonly contain credentials in authorization headers, URL query parameters, environment-variable assignments, API arguments, or embedded request bodies. The implementation has no secret-redaction or data-minimization step. The script also creates the log directory and file without explicitly applying restrictive permissions. Their resulting modes therefore depend on the process environment and inherited `umask`. In an environment with permissive defaults, other local users or processes may be able to read sensitive event details. The handwritten JSON encoding only escapes double quotes in `SUMMARY` and `DETAIL`. It does not correctly encode backslashes, carriage returns, newlines, tabs, or other control characters. In addition, `LEVEL`, `CATEGORY`, and `ACTION` are not escaped or validated at all. A caller able to influence these arguments can p ...[truncated 1766 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (45)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: security-audit
description: Security logging, periodic auditing, and config security review for OpenClaw agents. Use when: (1) logging potentially risky operations (rm -rf, curl | bash, sensitive file writes, external network requests), (2) user asks for an activity audit or wants to review recent agent actions, (3) user asks to audit the current OpenClaw configuration for security risks, (4) setting up periodic security checks or notifications.
---

# Security Audit Skill

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
1. **Log risky actions** → call `./scripts/log_event.sh` after notable operations

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
1. **Log risky actions** → call `./scripts/log_event.sh` after notable operations

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
1. **Log risky actions** → call `./scripts/log_event.sh` after notable operations

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
1. **Log risky actions** → call `./scripts/log_event.sh` after notable operations

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Example:

bash
./scripts/log_event.sh WARN exec "bulk delete outside workspace" "rm -rf /tmp/build" flagged
./scripts/log_event.sh CRITICAL credential "SSH key read" "cat ~/.ssh/id_rsa" allowed

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Example:

bash
./scripts/log_event.sh WARN exec "bulk delete outside workspace" "rm -rf /tmp/build" flagged
./scripts/log_event.sh CRITICAL credential "SSH key read" "cat ~/.ssh/id_rsa" allowed

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Example:

bash
./scripts/log_event.sh WARN exec "bulk delete outside workspace" "rm -rf /tmp/build" flagged
./scripts/log_event.sh CRITICAL credential "SSH key read" "cat ~/.ssh/id_rsa" allowed

Running Activity Audits

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/audit-guide.md (reported line 13)May include surrounding context.

md
"session": "main",
  "level": "WARN",
  "category": "exec",
  "summary": "curl piped to bash",
  "detail": "curl https://example.com/install.sh | bash",
  "action": "blocked_soft",
  "user_approved": false

YARA rule 'agent_skill_destructive_autonomous_actions': Autonomous destructive filesystem, shell history, or repository actions in AI agent skills [agent_skills]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/audit-guide.md (reported line 45)May include surrounding context.

md
CAL (always flag + notify)
- Remote code execution patterns
- Credential or key exfiltration
- Persistence mechanism writes (cron, authorized_keys, launchd)
- Privilege escalation

### WARN (flag, log, proceed if context is clear)
- Bulk file deletion (non-temp)
- Sensitive file reads without obvious user intent
- External requests with dynamic URLs
- Shell environment modification

### INFO (log silently)
- Normal workspace file operations
- Standard dev tool execution
- OpenClaw-internal tool calls

---

## Audit Workflow

### Per-Action Soft Check (Real-time)

Before executing a high-risk action, the agent should:

1. **Classify** the action against `dangerous-patterns.md`
2. **Check context**: Was this explicitly requested by the user in this session?
3. **If CRITICAL and NOT explicitly requested**:
   - Decline or request explicit confirmation
   - Log as `blocked_soft`
   - Notify via configured channel
4. **If WARN**:
   - Proceed, but log as `flagged`
   - Mention the action cl

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/audit-guide.md (reported line 69)May include surrounding context.

md
- Mention the action clearly in the reply
5. **If INFO**: Proceed, log silently (or skip logging for high-frequency noise)

**Key principle**: Do not add friction to clearly user-requested actions. A user who types "rm -rf ./dist" is explicitly requesting it — no block needed. A skill that autonomously decides to `rm -rf` something the user didn't ask about is a red flag.

### Periodic Audit

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Destructive Operations

text
rm -rf /
rm -rf ~
rm -rf /*
dd if=... of=/dev/...        # disk overwrite

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 9)May include surrounding context.

Destructive Operations

text
rm -rf /
rm -rf ~
rm -rf /*
dd if=... of=/dev/...        # disk overwrite

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 11)May include surrounding context.

Destructive Operations

text
rm -rf /
rm -rf ~
rm -rf /*
dd if=... of=/dev/...        # disk overwrite

YARA rule 'agent_skill_destructive_autonomous_actions': Autonomous destructive filesystem, shell history, or repository actions in AI agent skills [agent_skills]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 9)May include surrounding context.

Dangerous Patterns Reference

High-Risk exec Patterns

These shell command patterns require extra scrutiny before execution:

Destructive Operations

text
rm -rf /
rm -rf ~
rm -rf /*
dd if=... of=/dev/...        # disk overwrite
mkfs.*                        # filesystem format
shred / wipe / srm            # secure delete

Remote Code Execution

text
curl ... | bash
curl ... | sh
wget ... | bash
wget -O- ... | sh
eval $(...)
bash <(...)
python -c "import urllib..."  # download+exec one-liner

Credential & Data Exfiltration

text
cat ~/.ssh/*
cat ~/.gnupg/*
cat /etc/shadow
cat /etc/passwd
env | curl ...                # env vars sent out
printenv | ...
git log --all -p | curl ...   # repo history exfil

Persistence / Backdoor

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 10)May include surrounding context.

Destructive Operations

text
rm -rf /
rm -rf ~
rm -rf /*
dd if=... of=/dev/...        # disk overwrite
mkfs.*                        # filesystem format

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 11)May include surrounding context.

text
rm -rf /
rm -rf ~
rm -rf /*
dd if=... of=/dev/...        # disk overwrite
mkfs.*                        # filesystem format
shred / wipe / srm            # secure delete

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 19)May include surrounding context.

Remote Code Execution

text
curl ... | bash
curl ... | sh
wget ... | bash
wget -O- ... | sh

Chaining Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 19)May include surrounding context.

Remote Code Execution

text
curl ... | bash
curl ... | sh
wget ... | bash
wget -O- ... | sh

Chaining Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 21)May include surrounding context.

Remote Code Execution

text
curl ... | bash
curl ... | sh
wget ... | bash
wget -O- ... | sh

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 20)May include surrounding context.

Remote Code Execution

text
curl ... | bash
curl ... | sh
wget ... | bash
wget -O- ... | sh
eval $(...)

Chaining Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 20)May include surrounding context.

Remote Code Execution

text
curl ... | bash
curl ... | sh
wget ... | bash
wget -O- ... | sh
eval $(...)

Chaining Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 22)May include surrounding context.

Remote Code Execution

text
curl ... | bash
curl ... | sh
wget ... | bash
wget -O- ... | sh
eval $(...)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 21)May include surrounding context.

text
curl ... | bash
curl ... | sh
wget ... | bash
wget -O- ... | sh
eval $(...)
bash <(...)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/dangerous-patterns.md (reported line 22)May include surrounding context.

md
curl ... | bash
curl ... | sh
wget ... | bash
wget -O- ... | sh
eval $(...)
bash <(...)
python -c "import urllib..."  # download+exec one-liner

Static analysis

No suspicious patterns detected.