T06 · System Persistence
- Location
references/setup-guide.md:19- Finding
Administrator-Level Persistent OpenClaw Node Service
- Content
View full analysis
Vulnerability Details
File Location:
references/setup-guide.md:19-23
Vulnerability Type: Persistent privileged service installation
Risk Level: HighVulnerable Code
powershell openclaw node install --host 127.0.0.1 --port 18789Technical Analysis
The setup guide presents installation of the OpenClaw Node as a service from an administrator PowerShell session. A system service persists after the initiating terminal closes and can remain active across user logouts and system restarts.
Persistent service installation is not necessary for the Skill's core screenshot, OCR, mouse, and keyboard automation features. The guide already documents a less-privileged foreground alternative:
bash openclaw node run --host 127.0.0.1 --port 18789The installed node exposes capabilities that the same guide describes as screen capture, keyboard and mouse control, and local script execution. Although the configured address is restricted to localhost, pairing a controller with this persistent node creates a durable control channel. A compromised paired controller, Gateway, or local process able to access the service could consequently exercise these capabilities beyond the session in which the user intended to run the Skill.
Attack Path
- A user follows the documented second setup method and opens PowerShell with administrator privileges.
- The user runs the documented
openclaw node installcommand. - OpenClaw Node is registered as a persistent service and remains available beyond the current Skill run or terminal session.
- A controller is paired with the node through the documented pairing process.
- If that paired controller, the local Gateway, or another authorized control component is compromised, the attacker can reconnect to the persistent node.
- The attacker can then use the node's documented screen-capture, input-control, and local-execution functionality within the permis ...[truncated 1061 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove persistent service installation from the default setup workflow.
- Use the foreground, loopback-bound
openclaw node runmode for ordinary Skill execution. - Run the node as an unprivileged user and grant only the operating-system permissions required for screen capture and input automation.
- Stop the foreground node automatically when the requested automation task or user session ends.
- If persistent installation is operationally required, place it in a separate advanced section and require explicit, informed user consent.
- Document the service's account, effective privileges, startup behavior, logs, network listeners, and exact uninstall command.
- Require strong authenticated pairing, provide a way to list and revoke paired controllers, and expire inactive pairings.
- Keep the listener bound to loopback unless remote access is explicitly required. If remote access is enabled, require encrypted transport, mutual authentication, and host firewall restrictions.
- Restrict or disable general local command execution when only screenshot and input-control functions are needed.
- Provide a visible status indicator and an emergency mechanism that stops the node and revokes active sessions.
