Back to skill

Security audit

My Auto Updater

Security checks for vulnerabilities and agentic risk

Overview

This skill openly sets up daily automatic updates, but it gives a recurring job authority to change Clawdbot and every installed skill without review.

Install only if you are comfortable with a daily job automatically changing Clawdbot and every installed skill. Prefer a check-only or approval-before-apply workflow, pin trusted versions or publishers, keep rollback steps, and avoid using sudo for routine update failures unless you have reviewed the exact command.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
references/agent-guide.md:20
Finding

Persistent Scheduled Execution of Unattended System-Wide Updates

Content
View full analysis
> "$LOG_FILE" } log "Starting auto-update..." # Capture starting versions CLAWDBOT_VERSION_BEFORE=$(clawdbot --version 2>/dev/null || echo "unknown") # Update Clawdbot log "Updating Clawdbot..." if command -v npm &> /dev/null && npm list -g clawdbot &> /dev/null; then npm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v pnpm &> /dev/null && pnpm list -g clawdbot &> /dev/null; then pnpm update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" elif command -v bun &> /dev/null; then bun update -g clawdbot@latest 2>&1 | tee -a "$LOG_FILE" else log "Running clawdbot update (source install)" clawdbot update 2>&1 | tee -a "$LOG_FILE" || true fi # Run doctor for migrations log "Running doctor..." clawdbot doctor --yes 2>&1 | tee -a "$LOG_FILE" || true # Capture new version CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown") # Update skills ...[truncated 4099 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Self-Modification

High
Category
Rogue Agent
Confidence
97% confidence
Finding

clawdhub update --all performs self-modification by changing the installed skill set and code without human review, which is especially sensitive in an agent ecosystem where skills can influence future behavior. Combined with automation, this creates a direct supply-chain and integrity risk: a compromised or buggy update can persistently alter what the agent does.

Content

Scanner excerpt · references/agent-guide.md (reported line 61)May include surrounding context.

md
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")

# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs users to create a daily cron job that updates both the core bot and all installed skills without any approval step, staging, rollback guidance, or warning about unattended modifications. This creates a real supply-chain and availability risk: a bad upstream release, compromised registry package, or breaking change could be pulled automatically and applied across the environment without user review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide's core purpose is to automate updates to the bot and all installed skills, but it does so without prominently warning that this causes recurring system and application changes, may introduce breaking changes, and may pull in unreviewed code. Because the updates are unattended, users may enable a persistence mechanism that continuously modifies the environment with little ongoing oversight.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/agent-guide.md (reported line 21)May include surrounding context.

bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"

text

## Step 2: Create the Update Script (Optional)

For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cron configuration schedules unattended execution of clawdbot update, clawdbot doctor --yes, and clawdhub update --all, which together can modify the bot, perform migrations, and change installed skills automatically. Embedding these operations in a recurring isolated session with delivery/reporting increases persistence and reduces human review, making accidental breakage or supply-chain compromise more impactful.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide explicitly suggests using sudo to overcome permission errors during unattended update setup, which can normalize privilege escalation without first requiring a clear justification or narrowing the command scope. In an auto-updater context, this is risky because it may lead users or agents to rerun package-management operations with elevated privileges, increasing the blast radius of mistakes or compromised packages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file includes a setup confirmation stating that daily updates will run automatically and will update both the core application and all installed skills. While it explains what will be updated, it does not warn that automatic updates may change local behavior or system state, which is the kind of user-impacting behavior that should be disclosed in markdown descriptions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The example trigger phrase 'Set up daily auto-updates for yourself and all your skills' is natural language that could overlap with general user requests, and the document does not clarify whether exact phrasing is required or provide exclusion conditions. Without explicit trigger constraints or negative examples, the activation scope is less precise than ideal for a skill manifest/description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The setup confirmation says daily updates will run at 4:00 AM in America/Los_Angeles, which imposes a specific locale/timezone in natural language. There is no indication that this timezone is user-selected or merely an example, so it can be read as forcing a locale-specific default without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.