Back to skill

Security audit

Auto Updater Hold

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly says it will auto-update Clawdbot and all skills, but it sets up unattended recurring changes to the agent and installed skills without enough approval, pinning, or rollback controls.

Install only if you intentionally want unattended daily updates to Clawdbot and every installed skill. Prefer configuring it as notify-only or dry-run first, review proposed versions before applying them, keep a rollback path, and remove the cron job if you do not want recurring agent sessions changing your installation.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:29
Finding

Persistent Autonomous Update Task Across Agent Sessions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:51
Finding

Unpinned and Unattended Bulk Supply-Chain Updates

Content
View full analysis
/dev/null && npm list -g clawdbot &> /dev/null; then npm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v pnpm &> /dev/null && pnpm list -g clawdbot &> /dev/null; then pnpm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v bun &> /dev/null; then bun update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" else log "Running clawdbot update (source install)" clawdbot update 2>&1 | tee -a "$LOG_FILE" || true fi # Run doctor for migrations log "Running doctor..." clawdbot doctor --yes 2>&1 | tee -a "$LOG_FILE" || true # Capture new version CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown") # Update skills log "Updating skills via ClawdHub..." SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true ``` ### Technical Analysis The update process selects the mutable `latest` package release and updates every installed Skill without pinning versions or immutable artifact digests. The documented process does not require package signatures, checksum validation, publisher verification, an update allowlist, changelog review, sandbox testing, or user approval. The implementation also invokes `clawdbot doctor --yes`, allowing migrations to proceed non-interactively. Several significant operations append `|| ...[truncated 2013 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Self-Modification

High
Category
Rogue Agent
Confidence
93% confidence
Finding

clawdhub update --all causes the agent environment to self-modify by replacing installed skills, potentially including the currently trusted behavior, from an external source. In context, this is more dangerous because it is part of an automated daily updater, so any compromised package, malicious skill update, or accidental breaking release can propagate persistently without manual review.

Content

Scanner excerpt · references/agent-guide.md (reported line 61)May include surrounding context.

md
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")

# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly automates updating Clawdbot itself and all installed skills on a daily schedule, which can change system state, installed packages, and trusted code without an explicit user-facing warning about the risks of unattended updates. Even if sourced from legitimate registries, automatic bulk updates increase supply-chain and operational risk because a compromised package, breaking release, or privilege-sensitive package-manager action could be applied without timely human review.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/agent-guide.md (reported line 21)May include surrounding context.

bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"

text

## Step 2: Create the Update Script (Optional)

For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The cron-delivered instructions direct the agent to perform unattended package and skill updates plus clawdbot doctor --yes, which can change software state and apply migrations without an explicit warning, approval checkpoint, or rollback plan. This is dangerous because automatic updates modify trusted code and configuration on a schedule, increasing the risk of supply-chain compromise, breaking changes, or destructive migrations occurring without the user noticing beforehand.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown example specifies daily updates at 4:00 AM in "America/Los_Angeles," which imposes a locale-specific setting in natural language. Under the policy, forcing a specific locale without user opt-in can be a violation unless the constraint is documented as justified or optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.