Back to skill

Security audit

Backup & Recovery Automation

Security checks for vulnerabilities and agentic risk

Overview

This backup skill is purpose-aligned, but it asks for broad sensitive backup access and installs ongoing automation with weak safeguards.

Install only after narrowing the backup sources, enabling encrypted storage, reviewing exactly what will be uploaded to Google Drive, and changing setup so cron and global helper installation are explicit opt-in steps with an uninstall path. Do not run setup with sudo unless you intentionally want root-owned credentials and scheduled execution.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/backup_manager.js:154
Finding

Shell Command Injection Through Configuration and Restore Arguments

Content
View full analysis
`--exclude "${pattern}"`) .join(' '); // Construir comando rClone - UN solo comando para todas las fuentes let command = `rclone sync \\\n`; if (incremental) { command += ` --backup-dir "${this.config.remote}:${this.config.basePath}/incremental-${backupDate}" \\\n`; } command += ` ${excludeArgs} \\\n`; command += ` --progress \\\n`; command += ` --log-file ${LOG_FILE} \\\n`; command += ` -L \\\n`; // Combinar todas las fuentes en un solo comando const allSources = this.config.sources.join(' '); command += ` ${allSources} \\\n`; command += ` "${this.config.remote}:${backupPath}"`; const { stdout, stderr } = await execAsync(command, { shell: true }); ``` The restore command also incorporates direct CLI input: ```javascript async function handleRestoreBackup(manager, args) { const backupName = args[0]; const targetPath = args[1] || '/tmp/restore-backup'; // ... const result = await manager.restoreBackup(backupName, targetPath); } ``` ```javascript const sourcePath = `${this.config.remote}:${this.config.basePath}/${backupName}`; const command = `rclone copy "${sourcePath}" "${targetPath}" --progress`; const startTime = Date.now(); const { stdout, stderr } = await execAsync(command, { shell: true }); ``` ### Technical Analysis The application constructs shell commands by interpolating values from `backup_config.json` and direct command-line arguments. It then executes the resulting strings using `child_process.exec` with `shell: true`. Quoting a value with double quotes does not make it safe for shell execution. An input containing an embedded double quote can terminate the quoted argument and ...[truncated 1784 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
src/backup_manager.js:169
Finding

Overbroad Backup of Sensitive Agent State and Symbolic-Link Targets

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
setup_rclone.sh:37
Finding

OAuth Client Secret Is Echoed and Exposed Through Process Arguments

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
setup_rclone.sh:113
Finding

Unconditional Cron Persistence and Privileged Global File Installation

Content
View full analysis
&1 | tee -a /var/log/openclaw_backup_cron.log" # Agregar al crontab del usuario actual (crontab -l 2>/dev/null | grep -v "backup-recovery"; echo "${CRON_JOB}") | crontab - if [ $? -eq 0 ]; then echo "✅ Cron job configurado:" echo " ${CRON_JOB}" else echo "❌ Error configurando cron job" fi # Crear script de monitoreo echo "" echo "📊 Creando script de monitoreo..." cat > /usr/local/bin/check-backup-status << 'EOF' ``` The generated global executable is subsequently made executable: ```bash chmod +x /usr/local/bin/check-backup-status ``` ### Technical Analysis Daily cron execution is consistent with the Skill's declared automatic-backup functionality and is not a hidden backdoor. However, the implementation introduces avoidable persistence and privilege risks: - The cron job is installed unconditionally without explicit confirmation. - No uninstall or rollback operation is supplied. - Existing crontab content is filtered using a broad substring match, potentially removing unrelated entries containing `backup-recovery`. - The setup then writes to `/usr/local/bin`, which normally requires elevated privileges. - If setup is run with `sudo` to satisfy the global write, the rclone configuration and cron job may be installed for root rather than the intended user. - The cron job executes JavaScript from a mutable project directory. - Because `set -e` is active, failure during global installation can leave the already-created cron entry in place, resulting in a partial installation. - The cron pipeline writes into `/ ...[truncated 1611 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes shell-capable backup and recovery operations but does not declare any tool scope or allowed-tools boundary. In an agent environment, undeclared shell use increases the chance that the skill can invoke filesystem and remote-transfer commands with broader access than a user expects, especially for backup, deletion, and restore workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill proposes backing up highly sensitive files, including agent configs, sessions, workspace content, identity files, and contact/environment data, to Google Drive without a prominent privacy and data-handling warning. This creates a real risk of sensitive data exfiltration to a third-party cloud provider, especially since optional encryption is not enabled by default and the backup scope includes secrets and personal/system metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents rotation and recovery actions that can delete old backups or overwrite current files, but it lacks prominent safeguards or warnings about destructive consequences. In backup systems, silent deletion and restore-overwrite behavior can cause irreversible data loss, and the included examples like force-rotate and recover operations make that risk operationally immediate.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup_rclone.sh (reported line 13)May include surrounding context.

sh
# Verificar rClone instalado
if ! command -v rclone &> /dev/null; then
    echo "❌ rClone no encontrado. Instalar primero:"
    echo "   sudo apt install rclone"
    exit 1
fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script collects Google Drive client credentials without warning how they will be used, where rclone will store them, or what access they grant. This creates a meaningful risk of users entering sensitive secrets without understanding storage, reuse, or exposure implications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The backup configuration includes /workspace as a source, which is broader than the stated OpenClaw backup purpose and may capture unrelated projects, secrets, tokens, and source code. In a backup skill that uploads data to Google Drive, this scope expansion materially increases the risk of unintended data exfiltration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script goes beyond one-time backup configuration by installing persistent automation in the user's crontab and creating a monitoring executable under /usr/local/bin. Even if intended for backup operations, these host-level persistent changes expand the skill's footprint and can create ongoing execution and trust risks if the skill code later changes or is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script installs a cron job into the current user's crontab without explicit consent, creating ongoing scheduled execution. In the context of a skill that invokes node code from a workspace path, this persistence can be abused by later code changes and may surprise users who intended only one-time configuration.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

The script programmatically modifies the user's crontab to ensure recurring execution, which is a classic persistence mechanism. In a backup skill, scheduled execution is functionally relevant, but it still creates durable behavior that can continue running future code from /workspace without further review.

Content

Scanner excerpt · setup_rclone.sh (reported line 120)May include surrounding context.

sh
CRON_JOB="0 3 * * * cd /workspace/skills/backup-recovery && node src/index.js run 2>&1 | tee -a /var/log/openclaw_backup_cron.log"

# Agregar al crontab del usuario actual
(crontab -l 2>/dev/null | grep -v "backup-recovery"; echo "${CRON_JOB}") | crontab -

if [ $? -eq 0 ]; then
    echo "✅ Cron job configurado:"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script writes an executable file to /usr/local/bin without prior warning, which is a system-wide modification requiring elevated trust. Silent installation of host-level artifacts increases the chance of unintended persistence and broadens the attack surface beyond the backup skill's core purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Writing an executable to /usr/local/bin creates a host-level capability outside the skill directory and affects the wider system environment. This is risky because it establishes durable system modification that is not strictly necessary for configuring a cloud backup remote and could be abused if the installed script or referenced paths are later altered.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · setup_rclone.sh (reported line 159)May include surrounding context.

sh
# Verificar cron job
echo ""
echo "⏰ Verificando cron job..."
crontab -l | grep "backup-recovery"

# Verificar configuración
echo ""

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The inline comments say the code builds 'UN solo comando para todas las fuentes' by combining all sources into one rclone sync invocation. However, the generated command appends multiple source paths before one destination, which contradicts the stated intent of a valid all-sources backup command and does not align with standard rclone sync behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The backup skill shells out to an external alerting skill and interpolates backupName and errorMessage directly into a shell command. This expands the trust boundary beyond backup/restore functionality and creates command-injection risk if those values contain shell metacharacters, while also allowing a backup operation to trigger unrelated side effects in another component.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The restore function writes files to any caller-supplied targetPath and creates the directory recursively without confirmation, path restrictions, or safety checks. In this skill context, restoring backup contents into arbitrary filesystem locations can overwrite application data or place attacker-controlled files in sensitive paths if an untrusted caller can influence the destination.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The restore command accepts a user-supplied target path and proceeds to restore data there without any confirmation, overwrite warning, or safety checks. In a backup/recovery tool, this can lead to accidental overwriting or modification of important local files, especially because restore is a destructive/high-impact operation by nature.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README is written entirely in Spanish, including section headings and operational warnings, with no indication that users may choose another language or that the skill is intended only for a Spanish-speaking region. Under the policy, a fixed language choice without user opt-in or documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The natural-language instructions and descriptions are presented in Spanish, but there is no indication that users can choose another language or that the locale is intentionally restricted. This may violate a language/locale policy when no user opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-facing comments and runtime messages are consistently written in Spanish, which forces a specific language without offering an opt-in or documenting a justified locale restriction. This matches the language/locale policy concern for natural-language behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This section creates /workspace/skills/backup-recovery/config/backup_config.json and records backup source paths such as /home/rhandus/.openclaw and /workspace. While the code logs that the file was saved, there is no prior user disclosure that local configuration containing data-source details will be created as part of setup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill presents its descriptive comments and console/log messages in a single language, which can violate a language or locale policy when no user opt-in or justification is provided. The file does not indicate that Spanish is optional or that the skill is intended only for a Spanish-speaking or region-specific environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Nearly all user-facing comments and CLI output strings are in Spanish, and the file does not indicate that the skill is intended only for Spanish-speaking users or a Spanish-specific deployment. This can violate language/locale policy when a skill imposes a language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.