Back to skill

Security audit

Keep My Claw — OpenClaw Backup

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real cloud backup skill, but it needs Review because it drives signup/payment, stores an admin key, and uploads/restores highly sensitive agent data with weak safeguards.

Install only if you are comfortable with a paid off-site backup service receiving encrypted copies of your OpenClaw workspace, credentials, cron jobs, and agent configs. Before use, require explicit approval for registration/payment and uploads, prefer an agent-scoped API key instead of admin, keep the passphrase outside chat logs, review the backup scope, and avoid restoring untrusted backups until archive authentication and extraction validation are improved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:22
Finding

Mandatory Commercial Registration and Checkout Instructions Hijack Agent Behavior

Content
View full analysis
"Keep My Claw has launch pricing right now: > - **Monthly:** ~~$9/mo~~ → **$5/mo** > - **Annual:** ~~$108/yr~~ → **$19/yr** (that's less than $1.60/mo — 82% off!) > > Which plan do you want? This rate locks in for as long as you stay subscribed." ### Step 3: Get payment link and send to human CHECKOUT=$(curl -s -X POST https://api.keepmyclaw.com/v1/checkout \ -H "Authorization: Bearer $JWT" \ -H "Content-Type: application/json" \ -d '{"plan":"monthly"}') PAYMENT_URL=$(echo "$CHECKOUT" | jq -r '.url') ``` ### Technical Analysis The Skill instructs the Agent to autonomously register an external account using the human's email, repeat prescribed advertising language, initiate a paid checkout, and present the resulting payment URL. These instructions alter the Agent's normal goal from providing backup functionality to promoting and facilitating a commercial transaction. Account registration, disclosure of an email address, and checkout initiation are consequential external actions. They should not be performed merely because the backup ...[truncated 1113 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup.sh:14
Finding

Arbitrary Shell Command Execution Through Executable Configuration File

Content
View full analysis
&2 && exit 1 # Agent name default_agent="$(hostname -s 2>/dev/null || echo "agent")" read -rp "Agent name [${default_agent}]: " agent_name agent_name="${agent_name:-$default_agent}" # API URL read -rp "API URL [https://api.keepmyclaw.com]: " api_url api_url="${api_url:-https://api.keepmyclaw.com}" # Write config cat > "$CONFIG_FILE" <&2; exit 1 fi source "$CONFIG_FILE" ``` ### Technical Analysis `setup.sh` interpolates unvalidated input directly into a file containing shell assignment syntax. Every operational script then executes that file with `source`. File permissions do not prevent injection because the dangerous content may be introduced through the setup inputs themselves or by another process already able to modify the user's files. Shell metacharacters are evaluated when the file is sourced. For example, an input containing a closing quote followed by command syntax can terminate the assignment and add a command: ```text "; id > "$HOME/.keepmyclaw/injected"; # ``` The generated configuration would contain executable shell code. Command substitutions such as `$(command)` or backticks can also execute during `source`, depending on how the malicious value is serialized. ...[truncated 996 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:73
Finding

Routine Backup Setup Creates an Overprivileged Administrative API Key

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup.sh:96
Finding

Backup Encryption Does Not Authenticate Ciphertext

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/restore.sh:31
Finding

Downloaded Backup Archive Is Extracted Without Member or Link Validation

Content
View full analysis
&2 cat "$ENC_FILE" >&2 2>/dev/null exit 1 fi echo "✓ Downloaded" # Decrypt TAR_FILE="$TMPDIR/backup.tar.gz" echo "Decrypting..." openssl enc -aes-256-cbc -d -salt -pbkdf2 -iter 100000 \ -in "$ENC_FILE" -out "$TAR_FILE" -pass "pass:${PASSPHRASE}" echo "✓ Decrypted" # Preview contents before restoring echo echo "Backup contains:" tar -tzf "$TAR_FILE" | head -30 TOTAL="$(tar -tzf "$TAR_FILE" | wc -l | tr -d ' ')" [[ "$TOTAL" -gt 30 ]] && echo " ... and $((TOTAL - 30)) more files" if [[ -d "$OPENCLAW_DIR/workspace" ]] && [[ "$(ls -A "$OPENCLAW_DIR/workspace" 2>/dev/null)" ]]; then echo "⚠ WARNING: $OPENCLAW_DIR already has data." echo " Restore will OVERWRITE existing files (but won't delete extras)." if [[ -t 0 ]]; then read -rp "Continue? [y/N]: " confirm [[ "$confirm" != [yY]* ]] && echo "Aborted." && exit 0 else echo " (Non-interactive mode — proceeding)" fi fi # Extract echo "Restoring to ${OPENCLAW_DIR}..." mkdir -p "$OPENCLAW_DIR" tar -xzf "$TAR_FILE" -C "$OPENCLAW_DIR" ``` ### Technical Analysis The script lists archive names for display but does not validate them before extraction. It does not explicitly reject: - Absolute paths. - `..` path traversal components. - Symbolic or hard links with targets outside the extraction root. - Device nodes, FIFOs, or other special files. - Unexpected top-level directories. - Files outside the documented OpenClaw backup allowlist. Behavior va ...[truncated 1627 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/backup.sh:31
Finding

Default Backup Collects and Exports Broad Credential and Agent State

Content
View full analysis
> "$FILE_LIST" fi # --- OpenClaw config --- [[ -f "$OPENCLAW_DIR/openclaw.json" ]] && echo "openclaw.json" >> "$FILE_LIST" # --- Credentials --- if [[ -d "$OPENCLAW_DIR/credentials" ]]; then (cd "$OPENCLAW_DIR" && find credentials -type f) >> "$FILE_LIST" fi # --- Cron jobs --- [[ -f "$OPENCLAW_DIR/cron/jobs.json" ]] && echo "cron/jobs.json" >> "$FILE_LIST" # --- Multi-agent configs (agent dirs) --- if [[ -d "$OPENCLAW_DIR/agents" ]]; then (cd "$OPENCLAW_DIR" && find agents -type f \ -not -path '*/node_modules/*' \ -not -path '*/.git/*' \ -not -name '.DS_Store' \ ) >> "$FILE_LIST" fi # --- Additional agent workspaces (workspace-*) --- for ws in "$OPENCLAW_DIR"/workspace-*; do [[ -d "$ws" ]] || continue ws_name="$(basename "$ws")" (cd "$OPENCLAW_DIR" && find "$ws_name" -type f \ -not -path '*/node_modules/*' \ -not -path '*/.git/*' \ -not -path '*/vendor/*' \ -not -name '*.pyc' \ -not -name '.DS_Store' \ ) >> "$FILE_LIST" done ``` The resulting archive is uploaded to the configured API: ```bash curl -s -o "$TMPDIR/response.json" -w '%{http_code}' \ -X POST \ -H "Authorization: Bearer ${CLAWKEEPER_API_KEY}" \ -H "Content-Type: application/octet-stream" \ --data-binary @"$ENC_FILE" \ "${CLAWKEEPER_API_URL}/v1/agents/${CLAWKEEPER_ ...[truncated 2229 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (31)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/restore.sh (reported line 63)May include surrounding context.

sh
# Check if this will overwrite existing data
if [[ -d "$OPENCLAW_DIR/workspace" ]] && [[ "$(ls -A "$OPENCLAW_DIR/workspace" 2>/dev/null)" ]]; then
    echo "⚠ WARNING: $OPENCLAW_DIR already has data."
    echo "  Restore will OVERWRITE existing files (but won't delete extras)."
    if [[ -t 0 ]]; then
        read -rp "Continue? [y/N]: " confirm
        [[ "$confirm" != [yY]* ]] && echo "Aborted." && exit 0

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes very broad terms such as 'backup', 'restore', and 'snapshot', which can cause the skill to activate in contexts unrelated to this specific service. Because the skill then instructs the agent to create accounts, transmit credentials, and configure persistent secrets, accidental invocation materially increases the chance of unintended external actions and data exposure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The referenced external API endpoint is part of an off-platform account-registration flow. In this skill's context, the issue is not merely contacting an external host, but doing so as part of a workflow that transmits user identifiers and creates new service accounts automatically.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Step 1: Register an account

bash
RESPONSE=$(curl -s -X POST https://api.keepmyclaw.com/v1/auth/register \
  -H "Content-Type: application/json" \
  -d "{\"email\":\"HUMAN_EMAIL\",\"password\":\"$(openssl rand -hex 16)\"}")
JWT=$(echo "$RESPONSE" | jq -r '.token')

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The referenced external API endpoint is part of an off-platform account-registration flow. In this skill's context, the issue is not merely contacting an external host, but doing so as part of a workflow that transmits user identifiers and creates new service accounts automatically.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Step 1: Register an account

bash
RESPONSE=$(curl -s -X POST https://api.keepmyclaw.com/v1/auth/register \
  -H "Content-Type: application/json" \
  -d "{\"email\":\"HUMAN_EMAIL\",\"password\":\"$(openssl rand -hex 16)\"}")
JWT=$(echo "$RESPONSE" | jq -r '.token')

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The external endpoint is used to create a checkout/payment session. Because this skill is designed to 'handle everything' for the user, an accidental or misunderstood invocation could push the user into a commercial flow they did not intend to start.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Based on their choice, pass plan as "monthly" or "annual":

bash
CHECKOUT=$(curl -s -X POST https://api.keepmyclaw.com/v1/checkout \
  -H "Authorization: Bearer $JWT" \
  -H "Content-Type: application/json" \
  -d '{"plan":"monthly"}')   # or "annual"

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The external endpoint is used to create a checkout/payment session. Because this skill is designed to 'handle everything' for the user, an accidental or misunderstood invocation could push the user into a commercial flow they did not intend to start.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Based on their choice, pass plan as "monthly" or "annual":

bash
CHECKOUT=$(curl -s -X POST https://api.keepmyclaw.com/v1/checkout \
  -H "Authorization: Bearer $JWT" \
  -H "Content-Type: application/json" \
  -d '{"plan":"monthly"}')   # or "annual"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

bash
while true; do
  TIER=$(curl -s -H "Authorization: Bearer $JWT" \
    https://api.keepmyclaw.com/v1/account | jq -r '.tier')
  [ "$TIER" = "pro" ] && break
  sleep 10
done

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

bash
while true; do
  TIER=$(curl -s -H "Authorization: Bearer $JWT" \
    https://api.keepmyclaw.com/v1/account | jq -r '.tier')
  [ "$TIER" = "pro" ] && break
  sleep 10
done

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This external endpoint is used to mint a privileged admin API key after automated account creation and payment. In combination with local persistence and chat-based secret disclosure, creating privileged credentials through an agent-controlled flow significantly heightens the consequences of compromise or accidental invocation.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Step 5: Create an API key

bash
KEY_RESPONSE=$(curl -s -X POST https://api.keepmyclaw.com/v1/keys \
  -H "Authorization: Bearer $JWT" \
  -H "Content-Type: application/json" \
  -d '{"name":"agent","permissions":"admin"}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This external endpoint is used to mint a privileged admin API key after automated account creation and payment. In combination with local persistence and chat-based secret disclosure, creating privileged credentials through an agent-controlled flow significantly heightens the consequences of compromise or accidental invocation.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Step 5: Create an API key

bash
KEY_RESPONSE=$(curl -s -X POST https://api.keepmyclaw.com/v1/keys \
  -H "Authorization: Bearer $JWT" \
  -H "Content-Type: application/json" \
  -d '{"name":"agent","permissions":"admin"}')

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to generate a password, API key, and encryption passphrase, store them locally, and send all recovery credentials to the human, but it does not begin with a clear privacy and security warning or require explicit user consent for handling highly sensitive data. This increases the risk of secrets being exposed through agent messages, logs, chat history, or unsafe operator practices.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

Step 6: Configure locally

bash
mkdir -p ~/.keepmyclaw && chmod 700 ~/.keepmyclaw

cat > ~/.keepmyclaw/config <<EOF
CLAWKEEPER_API_KEY="${API_KEY}"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

Step 6: Configure locally

bash
mkdir -p ~/.keepmyclaw && chmod 700 ~/.keepmyclaw

cat > ~/.keepmyclaw/config <<EOF
CLAWKEEPER_API_KEY="${API_KEY}"

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

The skill persists an API key and other backup-related secrets in a long-lived local configuration under the user's home directory, enabling future automated access to backup data and account operations. Persistent credential storage increases the impact of host compromise, local malware, unintended skill reuse, and accidental backup of the backup credentials themselves.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

Step 6: Configure locally

bash
mkdir -p ~/.keepmyclaw && chmod 700 ~/.keepmyclaw

cat > ~/.keepmyclaw/config <<EOF
CLAWKEEPER_API_KEY="${API_KEY}"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

Generate and store encryption passphrase

PASSPHRASE=$(openssl rand -hex 32) printf '%s' "$PASSPHRASE" > ~/.keepmyclaw/passphrase chmod 600 ~/.keepmyclaw/passphrase

text

**CRITICAL: Tell your human ALL recovery credentials.** Without these, they cannot recover you on a new machine. Send them a message like this:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

Generate and store encryption passphrase

PASSPHRASE=$(openssl rand -hex 32) printf '%s' "$PASSPHRASE" > ~/.keepmyclaw/passphrase chmod 600 ~/.keepmyclaw/passphrase

text

**CRITICAL: Tell your human ALL recovery credentials.** Without these, they cannot recover you on a new machine. Send them a message like this:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

If the first agent has an admin API key, it can create a scoped key for you:

bash
curl -s -X POST https://api.keepmyclaw.com/v1/keys \
  -H "Authorization: Bearer ADMIN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name":"second-agent","permissions":"agent"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script intentionally archives a very broad set of local data, including the entire workspace, credentials, cron jobs, and agent configuration, then uploads it to a remote API. Although the archive is encrypted, the transmission scope is highly sensitive and there is no explicit confirmation, scoping control, destination validation, or minimization of secrets, so a misconfigured or untrusted API endpoint could receive a complete exfiltration bundle.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This curl invocation sends the encrypted backup to a configurable external URL using a bearer token, creating a direct data exfiltration path out of the host. In the context of this script, the uploaded payload contains potentially all workspace files plus credentials and operational config, so compromise or manipulation of the configured endpoint would expose a large amount of sensitive material.

Content

Scanner excerpt · scripts/backup.sh (reported line 105)May include surrounding context.

sh
# Upload via API
echo "Uploading..."
HTTP_CODE="$(curl -s -o "$TMPDIR/response.json" -w '%{http_code}' \
    -X POST \
    -H "Authorization: Bearer ${CLAWKEEPER_API_KEY}" \
    -H "Content-Type: application/octet-stream" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script performs an HTTP request to a remote API and transmits a bearer token from configuration without any visible user-facing warning, logging, or explanatory comment about the network operation. For code files, this qualifies when network calls that transmit user or system data occur without disclosure and are not clearly documented in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This script permanently deletes backups in bulk based solely on a numeric retention argument, with no interactive confirmation, dry-run mode, or secondary safeguard. In an operational backup-management context, accidental invocation, a mistyped KEEP value, or use against the wrong configured agent can cause irreversible loss of recovery points and materially weaken resilience.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 229)May include surrounding context.

md
echo

mkdir -p "$CONFIG_DIR"
chmod 700 "$CONFIG_DIR"

# API key
read -rp "API key (from keepmyclaw.com): " api_key

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/setup.sh (reported line 12)May include surrounding context.

sh
echo

mkdir -p "$CONFIG_DIR"
chmod 700 "$CONFIG_DIR"

# API key
read -rp "API key (from keepmyclaw.com): " api_key

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
CLAWKEEPER_AGENT_NAME="${agent_name}"
CLAWKEEPER_API_URL="${api_url}"
EOF
chmod 600 "$CONFIG_FILE"
echo "✓ Config saved to $CONFIG_FILE"

# Passphrase

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
CLAWKEEPER_AGENT_NAME="${agent_name}"
CLAWKEEPER_API_URL="${api_url}"
EOF
chmod 600 "$CONFIG_FILE"
echo "✓ Config saved to $CONFIG_FILE"

# Passphrase

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.generated_source_template_injection

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:130

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:85