T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned and Unverified Global npm Package Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real host-security audit skill, but it can automatically make privileged and persistent system changes that could lock users out or create unsafe execution paths.
Review before installing. Use audit-only configuration first, avoid running as root until the config file and scripts are trusted, pin and verify any npm CLI version, confirm SSH key login from a second session before allowing SSH changes, and inspect the cron entry and log path before enabling nightly runs.
SKILL.md:16Unpinned and Unverified Global npm Package Installation
scripts/openclaw_security_audit.sh:8Arbitrary Shell Execution Through Sourced Configuration Files
scripts/install_cron.sh:7Cron Command and Entry Injection Through OPENCLAW_AUDIT_LOG
scripts/openclaw_security_audit.sh:21Automatic SSH Password Disablement Without Verifying Working Key Access
If the implementation does not actually perform the advertised security checks and instead mainly prepares VirusTotal browser workflows, the skill creates a false sense of security. Users may believe a host has been audited and hardened when critical controls like firewall, SSH, failed-log review, updates, and cron scheduling were never verified.
If the implementation does not actually perform the advertised security checks and instead mainly prepares VirusTotal browser workflows, the skill creates a false sense of security. Users may believe a host has been audited and hardened when critical controls like firewall, SSH, failed-log review, updates, and cron scheduling were never verified.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
`ssh-keygen -t ed25519 -C "openclaw-admin"`
4. Help the user install the public key on the server:
`ssh-copy-id -p <new-port> <user>@<host>`
or append the public key to `~/.ssh/authorized_keys` with correct permissions.
5. Update SSH to use the chosen non-default port and disable password authentication.
6. Make sure the firewall allows the new SSH port before reloading SSH.
7. Tell the user to open a second terminal and verify:
The script sources a configuration file with Bash source, which executes arbitrary shell code from whichever candidate file is selected. Because this audit script may run as root or via passwordless sudo, a modified config file can become a privilege-escalation or arbitrary-code-execution path rather than simple data input.
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
run_privileged() {
if is_root; then
"$@"
elif command_exists sudo && sudo -n true >/dev/null 2>&1; then
sudo "$@"
else
return 126
The skill directs the agent to run privileged shell commands (npm install -g, audit/remediation commands, cron installation) but does not declare any explicit tool scope or allowed-tools boundary. In a security-sensitive skill that modifies host configuration, missing tool restrictions increases the chance of overbroad command execution or unintended privileged actions.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
trap 'rm -f "${CURRENT_CRONTAB}" "${UPDATED_CRONTAB}"' EXIT
crontab -l 2>/dev/null > "${CURRENT_CRONTAB}" || true
awk -v start="${START_MARKER}" -v end="${END_MARKER}" '
$0 == start { skip = 1; next }
$0 == end { skip = 0; next }
This shell script reads the current crontab, rewrites it, and installs a new scheduled job, which changes persistent system scheduling state. Although it prints a message after installation, there is no prior confirmation prompt or inline warning comment/docstring disclosing that the script will alter the user's crontab before doing so.
The script enables automatic remediation by default and can make persistent system changes such as enabling services, changing SSH settings, stopping containers, cleaning disk space, and altering firewall rules without an explicit confirmation step. In a security-audit skill, this creates meaningful operational risk because an operator may expect inspection but instead trigger disruptive remediation immediately.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
run_privileged() {
if is_root; then
"$@"
elif command_exists sudo && sudo -n true >/dev/null 2>&1; then
sudo "$@"
else
return 126
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
run_privileged() {
if is_root; then
"$@"
elif command_exists sudo && sudo -n true >/dev/null 2>&1; then
sudo "$@"
else
return 126
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
safe_systemctl_enable_now() {
local service="$1"
if run_privileged systemctl enable --now "${service}" >/dev/null 2>&1; then
action "Enabled ${service}."
return 0
fi
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
safe_systemctl_enable_now() {
local service="$1"
if run_privileged systemctl enable --now "${service}" >/dev/null 2>&1; then
action "Enabled ${service}."
return 0
fi
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
safe_systemctl_enable_now() {
local service="$1"
if run_privileged systemctl enable --now "${service}" >/dev/null 2>&1; then
action "Enabled ${service}."
return 0
fi
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
run_privileged dnf -y install dnf-automatic >/dev/null 2>&1 || return 1
if command_exists systemctl; then
if systemctl list-unit-files 2>/dev/null | grep -q '^dnf-automatic-install.timer'; then
timer_service="dnf-automatic-install.timer"
elif systemctl list-unit-files 2>/dev/null | grep -q '^dnf-automatic.timer'; then
timer_service="dnf-automatic.timer"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
if command_exists dnf; then
if command_exists systemctl \
&& (systemctl is-enabled --quiet dnf-automatic-install.timer 2>/dev/null || systemctl is-enabled --quiet dnf-automatic.timer 2>/dev/null) \
&& grep -Eq '^\s*upgrade_type\s*=\s*security' /etc/dnf/automatic.conf 2>/dev/null; then
log "Automatic security updates are enabled via dnf-automatic."
return 0
The hardcoded string "audit de sécurité réussi" imposes a specific language with no opt-in or locale handling. This is a natural-language policy issue because the file otherwise uses English messaging and gives users no language choice.
No suspicious patterns detected.