T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:10- Finding
Watchdog Design Requires Excessive Root Privileges
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is purpose-aligned but should be reviewed because it directs a root/systemd watchdog to automatically restart a service without a bundled, auditable implementation or tight controls.
Install only if you expect this skill to run a privileged watchdog that may automatically restart openclaw-gateway. Before use, require an auditable watchdog.sh, explicit confirmation for restart-capable monitoring, strict parameter validation, and narrowly scoped service permissions instead of unrestricted root operation.
SKILL.md:10Watchdog Design Requires Excessive Root Privileges
The skill description and usage guidance do not prominently warn users that the watchdog can automatically restart a systemd service, which is a material system-state change. In a root/systemd context, missing disclosure is risky because users may invoke the skill without realizing it can disrupt service availability, alter process state, or interfere with troubleshooting and production operations.
The trigger phrase "帮我启动 openclaw-watchdog" is close to ordinary conversational language and does not define clear invocation boundaries, increasing the chance of accidental or context-confused activation. In this skill, unintended invocation is more dangerous than usual because the documented behavior includes monitoring, service checks, and automatic restarts that can change system state on a privileged host.
The custom-port example remains broadly phrased and accepts a free-form parameter without clear trigger scoping, which can cause the skill to activate from normal conversation and apply user-supplied operational settings. Because this skill may monitor arbitrary ports and trigger systemctl restarts, ambiguous activation combined with parameter parsing increases the chance of unintended privileged actions.
The skill instructions and example notification content are presented only in Chinese, with no indication that the user can choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.
No suspicious patterns detected.