Back to skill

Security audit

NxtSecure-openclaw

Security checks for vulnerabilities and agentic risk

Overview

This is a real host-security audit skill, but it can automatically make privileged and persistent system changes that could lock users out or create unsafe execution paths.

Review before installing. Use audit-only configuration first, avoid running as root until the config file and scripts are trusted, pin and verify any npm CLI version, confirm SSH key login from a second session before allowing SSH changes, and inspect the cron entry and log path before enabling nightly runs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Error
Location
SKILL.md:16
Finding

Unpinned and Unverified Global npm Package Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/openclaw_security_audit.sh:8
Finding

Arbitrary Shell Execution Through Sourced Configuration Files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install_cron.sh:7
Finding

Cron Command and Entry Injection Through OPENCLAW_AUDIT_LOG

Content
View full analysis
> ${LOG_PATH} 2>&1" ``` ```bash CURRENT_CRONTAB="$(mktemp)" UPDATED_CRONTAB="$(mktemp)" trap 'rm -f "${CURRENT_CRONTAB}" "${UPDATED_CRONTAB}"' EXIT crontab -l 2>/dev/null > "${CURRENT_CRONTAB}" || true awk -v start="${START_MARKER}" -v end="${END_MARKER}" ' $0 == start { skip = 1; next } $0 == end { skip = 0; next } skip != 1 { print } ' "${CURRENT_CRONTAB}" > "${UPDATED_CRONTAB}" { cat "${UPDATED_CRONTAB}" printf '%s\n' "${START_MARKER}" printf '%s\n' "${CRON_LINE}" printf '%s\n' "${END_MARKER}" } | crontab - ``` ### Technical Analysis `OPENCLAW_AUDIT_LOG` is copied directly into a crontab command. The value is not quoted for shell interpretation and is not checked for newline characters, carriage returns, `%`, whitespace, or shell metacharacters. This creates two related injection surfaces: 1. A newline in `OPENCLAW_AUDIT_LOG` can terminate the intended cron line and add another cron entry. 2. Shell metacharacters can alter the command executed by the intended entry because the log path is inserted as shell syntax rather than as a safely quoted argument. Cron also treats `%` specially in command fields, giving an attacker another way to change command behavior. The installed task persists after the installer exits and runs as the account whose crontab was modified. The nightly cron mechanism itself matches the declared functionality. The vulnerability is the construction of persistent executable content from unvalidated environment input. ### Attack Path 1. An attacker influences the environment of the user or automation invoking `install_cron.sh`. 2. The attacker assigns a ma ...[truncated 931 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/openclaw_security_audit.sh:21
Finding

Automatic SSH Password Disablement Without Verifying Working Key Access

Content
View full analysis
"${tmp_file}" <<'EOF' PasswordAuthentication no KbdInteractiveAuthentication no ChallengeResponseAuthentication no EOF if run_privileged mkdir -p /etc/ssh/sshd_config.d \ && run_privileged install -m 0644 "${tmp_file}" "${drop_in}" \ && run_privileged sshd -t \ && (run_privileged systemctl reload sshd >/dev/null 2>&1 || run_privileged systemctl reload ssh >/dev/null 2>&1); then rm -f "${tmp_file}" action "Disabled SSH password authentication with ${drop_in}." return 0 fi rm -f "${tmp_file}" return 1 } ``` ```bash ssh_key_auth_enabled() { local key_auth key_auth="$(ssh_effective_value pubkeyauthentication)" [[ -z "${key_auth}" || "${key_auth}" == "yes" ]] } ``` ```bash if [[ "${SSH_REQUIRE_KEYS_ONLY}" -eq 1 ]]; then if [[ "${password_auth}" != "no" ]]; then if [[ "${AUTO_REMEDIATE}" -eq 1 ]] && remediate_ssh_password_auth; then password_auth="$(ssh_effective_value passwordauthentication)" fi fi if [[ "${password_auth}" != "no" ]]; then issue "SSH password authentication is still enabled." elif ! ssh_key_auth_enabled; then issue "SSH public key authentication is not enabled." else log "SSH is configured for key-based authentication only." fi ``` ### Technical Analysis Both `SSH_REQUIRE_KEYS_ONLY` and `AUTO_REMEDIATE` default to enabled. When password authentication is available, the script immediately writes an SSH drop-in disabling password, keyboar ...[truncated 2140 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation does not actually perform the advertised security checks and instead mainly prepares VirusTotal browser workflows, the skill creates a false sense of security. Users may believe a host has been audited and hardened when critical controls like firewall, SSH, failed-log review, updates, and cron scheduling were never verified.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the implementation does not actually perform the advertised security checks and instead mainly prepares VirusTotal browser workflows, the skill creates a false sense of security. Users may believe a host has been audited and hardened when critical controls like firewall, SSH, failed-log review, updates, and cron scheduling were never verified.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
`ssh-keygen -t ed25519 -C "openclaw-admin"`
4. Help the user install the public key on the server:
   `ssh-copy-id -p <new-port> <user>@<host>`
   or append the public key to `~/.ssh/authorized_keys` with correct permissions.
5. Update SSH to use the chosen non-default port and disable password authentication.
6. Make sure the firewall allows the new SSH port before reloading SSH.
7. Tell the user to open a second terminal and verify:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script sources a configuration file with Bash source, which executes arbitrary shell code from whichever candidate file is selected. Because this audit script may run as root or via passwordless sudo, a modified config file can become a privilege-escalation or arbitrary-code-execution path rather than simple data input.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/openclaw_security_audit.sh (reported line 79)May include surrounding context.

sh
run_privileged() {
  if is_root; then
    "$@"
  elif command_exists sudo && sudo -n true >/dev/null 2>&1; then
    sudo "$@"
  else
    return 126

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill directs the agent to run privileged shell commands (npm install -g, audit/remediation commands, cron installation) but does not declare any explicit tool scope or allowed-tools boundary. In a security-sensitive skill that modifies host configuration, missing tool restrictions increases the chance of overbroad command execution or unintended privileged actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install_cron.sh (reported line 22)May include surrounding context.

sh
trap 'rm -f "${CURRENT_CRONTAB}" "${UPDATED_CRONTAB}"' EXIT

crontab -l 2>/dev/null > "${CURRENT_CRONTAB}" || true
awk -v start="${START_MARKER}" -v end="${END_MARKER}" '
  $0 == start { skip = 1; next }
  $0 == end { skip = 0; next }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script reads the current crontab, rewrites it, and installs a new scheduled job, which changes persistent system scheduling state. Although it prints a message after installation, there is no prior confirmation prompt or inline warning comment/docstring disclosing that the script will alter the user's crontab before doing so.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script enables automatic remediation by default and can make persistent system changes such as enabling services, changing SSH settings, stopping containers, cleaning disk space, and altering firewall rules without an explicit confirmation step. In a security-audit skill, this creates meaningful operational risk because an operator may expect inspection but instead trigger disruptive remediation immediately.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/openclaw_security_audit.sh (reported line 79)May include surrounding context.

sh
run_privileged() {
  if is_root; then
    "$@"
  elif command_exists sudo && sudo -n true >/dev/null 2>&1; then
    sudo "$@"
  else
    return 126

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/openclaw_security_audit.sh (reported line 80)May include surrounding context.

sh
run_privileged() {
  if is_root; then
    "$@"
  elif command_exists sudo && sudo -n true >/dev/null 2>&1; then
    sudo "$@"
  else
    return 126

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/openclaw_security_audit.sh (reported line 109)May include surrounding context.

sh
safe_systemctl_enable_now() {
  local service="$1"
  if run_privileged systemctl enable --now "${service}" >/dev/null 2>&1; then
    action "Enabled ${service}."
    return 0
  fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/openclaw_security_audit.sh (reported line 525)May include surrounding context.

sh
safe_systemctl_enable_now() {
  local service="$1"
  if run_privileged systemctl enable --now "${service}" >/dev/null 2>&1; then
    action "Enabled ${service}."
    return 0
  fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/openclaw_security_audit.sh (reported line 563)May include surrounding context.

sh
safe_systemctl_enable_now() {
  local service="$1"
  if run_privileged systemctl enable --now "${service}" >/dev/null 2>&1; then
    action "Enabled ${service}."
    return 0
  fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/openclaw_security_audit.sh (reported line 544)May include surrounding context.

sh
run_privileged dnf -y install dnf-automatic >/dev/null 2>&1 || return 1

  if command_exists systemctl; then
    if systemctl list-unit-files 2>/dev/null | grep -q '^dnf-automatic-install.timer'; then
      timer_service="dnf-automatic-install.timer"
    elif systemctl list-unit-files 2>/dev/null | grep -q '^dnf-automatic.timer'; then
      timer_service="dnf-automatic.timer"

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/openclaw_security_audit.sh (reported line 592)May include surrounding context.

sh
if command_exists dnf; then
    if command_exists systemctl \
      && (systemctl is-enabled --quiet dnf-automatic-install.timer 2>/dev/null || systemctl is-enabled --quiet dnf-automatic.timer 2>/dev/null) \
      && grep -Eq '^\s*upgrade_type\s*=\s*security' /etc/dnf/automatic.conf 2>/dev/null; then
      log "Automatic security updates are enabled via dnf-automatic."
      return 0

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The hardcoded string "audit de sécurité réussi" imposes a specific language with no opt-in or locale handling. This is a natural-language policy issue because the file otherwise uses English messaging and gives users no language choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.