Back to skill

Security audit

Host Hardening

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed server-hardening checklist, but it also includes an optional persistent OpenClaw gateway service that runs as root and is not tightly scoped.

Install only if you are comfortable reviewing and approving each administrative command. The SSH, firewall, fail2ban, and permission steps are consistent with hardening, but treat the OpenClaw gateway service as a separate privileged deployment decision: avoid enabling it as root unless you have a clear need, understand the executable path and configuration, and can add least-privilege service hardening. Run the optional validator as an unprivileged user and pin or review the tool before executing it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:59
Finding

Persistent OpenClaw Gateway Service Runs with Unnecessary Root Privileges

Content
View full analysis
/etc/systemd/system/openclaw-gateway.service << 'EOF' [Unit] Description=OpenClaw Gateway After=network-online.target Wants=network-online.target [Service] Type=simple ExecStart=/usr/bin/env openclaw gateway Restart=always RestartSec=5 User=root WorkingDirectory=/root/.openclaw Environment=HOME=/root [Install] WantedBy=multi-user.target EOF systemctl daemon-reload && systemctl enable openclaw-gateway ``` ### Technical Analysis The optional systemd unit executes the OpenClaw gateway as `root`, automatically restarts it after failure, and enables it to start after reboot. Although persistence is explicitly disclosed and is functionally relevant when the gateway must survive reboots, granting the gateway unrestricted root privileges exceeds the minimum permissions normally required by a network-facing service. Any vulnerability in the gateway, its extensions, configuration parsing, or command-handling logic would consequently execute in a root context. The use of: ```ini ExecStart=/usr/bin/env openclaw gateway ``` also fails to pin the service to a specific, reviewed executable path. The effective executable depends on the systemd service environment's `PATH`, making executable provenance less explicit than an absolute path. No systemd sandboxing controls are configured. In particular, the service lacks controls such as `NoNewPrivileges`, filesystem protections, private temporary storage, restricted capabilities, and system-call filtering. Its working directory and home directory are both under `/root`, potentially exposing root-owned OpenClaw configuration and credentials to a compromised gateway process. ### Attack Path 1. An administrator follows the Skill and installs the systemd unit. 2. The administrator enables the service, causing it to ...[truncated 1166 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:102
Finding

Unpinned External Validation Tool Is Installed and Executed

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: host-hardening
description: Harden an OpenClaw Linux server with SSH key-only auth, UFW firewall, fail2ban brute-force protection, and credential permissions. Use when setting up a new OpenClaw instance, auditing server security, or after a security incident. Requires root/sudo on Linux (Ubuntu/Debian).
---

# Host Hardening

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
---
name: host-hardening
description: Harden an OpenClaw Linux server with SSH key-only auth, UFW firewall, fail2ban brute-force protection, and credential permissions. Use when setting up a new OpenClaw instance, auditing server security, or after a security incident. Requires root/sudo on Linux (Ubuntu/Debian).
---

# Host Hardening

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
60% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
- **Privileges:** Root or sudo required — this skill modifies system-wide security config
- **Pre-check:** Verify you have SSH key-based access before disabling password auth

**⚠️ All commands below modify system configuration. Confirm with the user before running each section.** Do not run these automatically without explicit approval.

## SSH — Key-Only Auth

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

bash
apt-get install -y fail2ban
systemctl enable --now fail2ban

Default config protects SSH. For custom jails: /etc/fail2ban/jail.local.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

OpenClaw Credentials

bash
chmod 700 ~/.openclaw/credentials

OpenClaw Gateway Service (optional)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill’s stated purpose is host hardening, but it also introduces an optional persistent OpenClaw gateway service that runs as root. This expands scope beyond defensive hardening into deployment of an always-on privileged agent component, increasing attack surface and creating an opportunity for persistence if the OpenClaw binary or environment is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The systemd unit runs openclaw gateway as User=root with HOME=/root and a root working directory, granting the service full system privileges and access to root-owned secrets. A compromise of the OpenClaw process, its plugins, or its update path would yield full host compromise and durable privileged execution on reboot.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

Enabling the OpenClaw gateway unit creates reboot-persistent execution of a root-owned service that is not necessary for baseline host hardening. This makes the skill materially more dangerous because it combines persistence with elevated privileges, which could be abused for long-term host control.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

[Install] WantedBy=multi-user.target EOF systemctl daemon-reload && systemctl enable openclaw-gateway

text

## Verify

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

systemctl is-active fail2ban # active grep PasswordAuthentication /etc/ssh/sshd_config # no stat -c %a ~/.openclaw/credentials # 700 systemctl is-enabled openclaw-gateway # enabled

text

## Lessons

Static analysis

No suspicious patterns detected.