Back to skill

Security audit

Auto-Watchdog

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed watchdog, but it asks users to set up silent persistent auto-remediation that can restart services and alter or delete files without enough scoping or control.

Review this carefully before installing. Only use it with explicit process allowlists, monitor-only or alert-only testing first, visible logs, least-privileged service accounts, reviewed guardian scripts, safe shutdown behavior, cleanup exclusions, and clear disable/removal steps. Avoid the hidden PowerShell and execution-policy-bypass setup unless you have a specific administrative reason and understand the persistence risk.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
SKILL.md:57
Finding

Persistent Hidden Execution Through Task Scheduler and systemd

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 57-76
Vulnerability Type: Cross-session execution persistence
Risk Level: High

The Skill directs users to configure either a recurring Windows Task Scheduler job that launches hidden PowerShell with execution-policy bypass or a Linux systemd service configured to restart continuously.

Complete vulnerable code:

vbs
' guardian-silent.vbs — zero flash process monitor
Set oShell = CreateObject("WScript.Shell")
oShell.Run "powershell.exe -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -File ""C:\path\to\guardian.ps1""", 0, True
text
Register as Task Scheduler job running every 1-5 minutes.
bash
# /etc/systemd/system/openclaw-watchdog.service
[Service]
ExecStart=/usr/bin/node /path/to/guardian.js
Restart=always
RestartSec=60

Technical Analysis

Windows Task Scheduler and Linux systemd are operating-system persistence mechanisms that survive the original Skill invocation and user session. The Windows configuration is particularly risky because it combines frequent scheduled execution with -WindowStyle Hidden and -ExecutionPolicy Bypass, reducing execution visibility and bypassing PowerShell's configured script-execution policy.

The systemd example establishes similar persistence by executing guardian.js as a service and setting Restart=always. The actual guardian.ps1 and guardian.js implementations are not included in the reviewed project, so their commands, input validation, privilege requirements, and integrity cannot be audited. Consequently, the persistent mechanisms would repeatedly execute code whose security properties are unknown.

Attack Path

  1. A user follows the setup instructions in SKILL.md.
  2. On Windows, the user creates a recurring Task Scheduler entry that invokes the VBS wrapper every one to five minutes; on Linux, the user installs and enables the systemd service.

...[truncated 1238 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the default instructions for recurring Task Scheduler and systemd installation. Prefer an explicit, foreground health-check command that terminates after each user-authorized run.
  • Remove -WindowStyle Hidden and -ExecutionPolicy Bypass. Use a signed PowerShell script and an appropriate execution policy instead of bypassing policy controls.
  • Include guardian.ps1 and guardian.js in the reviewed Skill package rather than referring to unspecified external implementations.
  • Pin guardian scripts to fixed, administrator-owned paths and prevent modification by the service account or unprivileged users.
  • Configure the scheduled task or service under a dedicated least-privileged account. For systemd, specify User, Group, NoNewPrivileges=true, restrictive filesystem access, capability restrictions, and other applicable sandboxing controls.
  • Require explicit user approval before terminating processes, restarting services, rotating logs, or deleting temporary files.
  • Add visible audit logging for every execution and remediation action. Avoid silent operation for security-relevant changes.
  • Verify script integrity before execution using signatures or cryptographic hashes stored in a protected location.
  • Document installation, disablement, and complete removal procedures for every scheduled task and service.
  • Restrict restart frequency and implement failure limits to avoid persistent crash loops or denial-of-service conditions.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The wording 'fixes what it can — silently' and 'Fix first, alert second' promotes autonomous system changes without prior human review or prominent warning. This is dangerous because silent remediation can mask root causes, restart the wrong component, or alter system state before an operator can assess whether the action is safe.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Instructing users to 'kill + restart' processes based solely on log freshness creates a real risk of service interruption, data loss, or corruption if a process is busy, blocked on I/O, or intentionally quiet. Because this is framed as automatic remediation for 'any Node.js process,' the blast radius is broader and the heuristic may be too weak for safe termination decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises autonomous restarts, log rotation, and temp file cleanup as core behavior but does not clearly disclose that these actions can interrupt services or modify/delete files. In an agent skill context, operators may deploy it expecting passive monitoring, so undocumented self-healing behavior increases the chance of unsafe automation and accidental disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic log rotation and temp file cleanup can modify or remove files, potentially destroying evidence needed for debugging or deleting files that were misclassified as temporary. Without warnings, retention guidance, or scope limits, operators may enable behavior that causes unintended data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup instructions operationalize automatic process restarts and log rotation without any cautionary guidance, making disruptive actions easy to deploy as copy-paste configuration. In context, this increases risk because the skill is positioned as 'set it and forget it,' which may discourage careful review of the consequences.

Content

No source excerpt is available for this finding.