Back to skill

Security audit

Openclaw Auto Updater 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly an auto-updater, but it sets up recurring unattended changes to Clawdbot and all installed skills without tight approval or version controls.

Install only if you are comfortable with Clawdbot automatically modifying itself and all installed skills on a schedule. Prefer a dry-run or notify-first setup, pin or approve specific updates where possible, and verify you know how to inspect and remove the cron job before enabling it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
references/agent-guide.md:72
Finding

Persistent Daily Update Task Executes Across Sessions

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
references/agent-guide.md:31
Finding

Unpinned Remote Updates Permit Mutable Upstream Code Installation

Content
View full analysis
/dev/null && npm list -g clawdbot &> /dev/null; then npm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v pnpm &> /dev/null && pnpm list -g clawdbot &> /dev/null; then pnpm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v bun &> /dev/null; then bun update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" else log "Running clawdbot update (source install)" clawdbot update 2>&1 | tee -a "$LOG_FILE" || true fi # Run doctor for migrations log "Running doctor..." clawdbot doctor --yes 2>&1 | tee -a "$LOG_FILE" || true # Capture new version CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown") # Update skills log "Updating skills via ClawdHub..." SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true echo "$SKILL_OUTPUT" >> "$LOG_FILE" ``` ### Technical Analysis The update routine installs `clawdbot@latest` or invokes an unconstrained source update, then updates every installed Skill. The effective payload can change after this Skill has been reviewed because neither the package version nor the downloaded artifact is immutable. The workflow does not require: - An approved version allowlist. - Cryptographic digest or signature verification. - Publisher or repository identity validation. - Inspection of package or Skill changes. - Staging in an isolated environment. - User approval before installation. - A tested rollback mechanism. Using `@latest` explicitly delegates release selection to mutable registry metadata. Likewise, `clawdhub update --all` broadens the supply-chain exposure from one component to every installed Skill. ### Attack Path 1. A ...[truncated 1277 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/agent-guide.md:43
Finding

Suppressed Update Failures Can Leave a Partially Modified Installation

Content
View full analysis
&1 | tee -a "$LOG_FILE" || true fi # Run doctor for migrations log "Running doctor..." clawdbot doctor --yes 2>&1 | tee -a "$LOG_FILE" || true # Capture new version CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown") # Update skills log "Updating skills via ClawdHub..." SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true echo "$SKILL_OUTPUT" >> "$LOG_FILE" ``` ### Technical Analysis The helper script begins with `set -e`, but the most security-sensitive operations append `|| true`. This forces failed update, migration, and Skill-update commands to return a successful status to the surrounding script. The pattern suppresses failures after a command may already have changed files. The script can consequently proceed from a failed core update to migrations and Skill updates, creating an inconsistent combination of versions. It later logs completion without returning a reliable aggregate failure status. Capturing command output is useful for reporting, but it should not discard the exit code. Output and status must be captured independently. ### Attack Path 1. A core or Skill update starts replacing files. 2. The command fails because of interruption, malformed content, permission errors, dependency conflicts, or a hostile upstream artifact. 3. `|| true` converts the nonzero exit status into success. 4. The routine continues with migrations or additional updates. 5. The installation is left with partially updated or incompatible components. 6. The normal completion flow can cause operators or monitoring systems to treat the run as successful. 7. The inconsistent state may produce availability failures or expose defects in mismatched components. ### Impact A ...[truncated 462 chars]
Remediation
View remediation
&1) SKILL_STATUS=$? set -e if [ "$SKILL_STATUS" -ne 0 ]; then log "Skill update failed with status $SKILL_STATUS" exit "$SKILL_STATUS" fi ``` - Stop the workflow after a failed core update or migration. - Report distinct statuses for core update, migration, and each Skill update. - Return a nonzero final status whenever any required stage fails. - Perform updates transactionally where possible. - Preserve a known-good backup and automatically roll back partial changes. - Run post-update integrity and health checks before reporting success. - Quarantine failed updates and suspend recurring execution until the user reviews the failure. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

clawdhub update --all performs self-modification by updating all installed skills automatically, which can introduce unreviewed code or changed behavior into the agent environment. In the context of a cron-driven auto-updater, this is especially dangerous because it repeatedly applies remote changes without interactive verification, amplifying supply-chain compromise risk.

Content

Scanner excerpt · references/agent-guide.md (reported line 61)May include surrounding context.

md
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")

# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description emphasizes convenience but does not prominently warn that it will automatically and repeatedly modify the local Clawdbot installation and all installed skills. Missing upfront disclosure weakens informed consent and increases the chance a user enables unattended code changes from external sources without understanding the persistence and supply-chain risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The quick-start phrase is broad enough that a normal user request about setting up updates could invoke a skill that creates a scheduled task and later performs software-modifying actions. Because the skill establishes persistent automation and updates both the bot and all installed skills, accidental triggering has a higher-than-normal security impact compared with a read-only helper skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs an agent to set up unattended daily updates that modify the installed bot and all skills, including running maintenance commands like clawdbot doctor --yes, without requiring explicit per-run user approval or emphasizing the risks of automatic system changes. This creates a supply-chain and integrity risk: a compromised package, malicious skill update, or unexpected migration could be applied automatically and persistently.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The guide directs creation of a persistent helper script under ~/.clawdbot/scripts/auto-update.sh, establishing reusable automation that survives beyond the immediate session. Persistence itself is not inherently malicious, but here it supports recurring unattended privileged actions and broadens the blast radius if the script or its execution path is later tampered with.

Content

Scanner excerpt · references/agent-guide.md (reported line 21)May include surrounding context.

bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"

text

## Step 2: Create the Update Script (Optional)

For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:

Static analysis

No suspicious patterns detected.