Back to skill

Security audit

OpenClaw Backup

Security checks for vulnerabilities and agentic risk

Overview

This is a plausible OpenClaw backup and restore skill, but its restore script can extract an arbitrary archive into the user's home directory and the backup contains sensitive data without strong protection guidance.

Review before installing. Only restore archives you created and trust, because a crafted backup could overwrite files in your home directory. Treat created backups as sensitive secrets: they may contain chat history, memory, identity data, configuration, and credential files, and should be stored on encrypted, access-controlled media rather than shared or untrusted cloud locations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/restore.sh:56
Finding

Unrestricted Backup Archive Extraction into the User Home Directory

Content
View full analysis
Remediation
View remediation
&2 exit 1 ;; esac done < <(tar -tzf "$BACKUP_FILE") tar -xzf "$BACKUP_FILE" -C "$STAGING_DIR" --no-same-owner --no-same-permissions ``` Additional link and special-file validation is still required before moving the staged data into place. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup.sh:24
Finding

Predictable Shared Temporary File Permits Manifest Manipulation

Content
View full analysis
/tmp/openclaw-backup-list.txt << 'EOF' .openclaw/workspace .openclaw/agents .openclaw/memory .openclaw/credentials .openclaw/cron .openclaw/identity .openclaw/extensions .openclaw/devices .openclaw/openclaw.json .openclaw/openclaw.json.bak .openclaw/openclaw.json.bak.1 .openclaw/openclaw.json.bak.2 .openclaw/openclaw.json.bak.3 .openclaw/exec-approvals.json .openclaw/feishu .openclaw/canvas .openclaw/media .openclaw/completions .openclaw/delivery-queue .openclaw/subagents .openclaw/update-check.json EOF # 如果设置 INCLUDE_SKILLS,则添加 skills 目录 if [ "${INCLUDE_SKILLS:-0}" = "1" ]; then echo ".openclaw/skills" >> /tmp/openclaw-backup-list.txt echo "📦 包含 skills 目录(完整备份模式)" fi ``` The same predictable path is later removed: ```bash rm -f /tmp/openclaw-backup-list.txt ``` ### Technical Analysis The script stores the archive manifest at the fixed path `/tmp/openclaw-backup-list.txt`. Shared temporary directories are writable by other local users, and the script does not use exclusive creation, verify ownership, reject symbolic links, or hold a securely opened file descriptor. Shell redirection follows symbolic links. A local attacker may therefore pre-create the predictable path as a symbolic link to a file writable by the victim. The initial `cat >` operation can truncate and overwrite that target. There is also a time-of-check/time-of-use window between manifest creation and the later `tar -T` operations. A local attacker who can replace or modify the temporary manifest may add unintended paths to the backup archive. Because `set -e` does not guarantee cleanup on every termination path, the predictable file may also remain after an interrupted run. ### Attack Path A symlink-based attack can proceed as follows: 1. A local attacker predicts `/tm ...[truncated 1240 chars]
Remediation
View remediation
"$LIST_FILE" <<'EOF' .openclaw/workspace .openclaw/agents .openclaw/memory .openclaw/credentials .openclaw/cron .openclaw/identity .openclaw/extensions .openclaw/devices .openclaw/openclaw.json .openclaw/openclaw.json.bak .openclaw/openclaw.json.bak.1 .openclaw/openclaw.json.bak.2 .openclaw/openclaw.json.bak.3 .openclaw/exec-approvals.json .openclaw/feishu .openclaw/canvas .openclaw/media .openclaw/completions .openclaw/delivery-queue .openclaw/subagents .openclaw/update-check.json EOF ``` Additional hardening should include: - Setting `umask 077` at script startup. - Keeping the manifest open through a securely created descriptor where practical. - Avoiding shared temporary storage entirely by using a private temporary directory. - Ensuring cleanup occurs for normal exit, errors, and signals. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup.sh:24
Finding

Sensitive OpenClaw Data Is Stored in an Unencrypted Backup Archive

Content
View full analysis
/tmp/openclaw-backup-list.txt << 'EOF' .openclaw/workspace .openclaw/agents .openclaw/memory .openclaw/credentials .openclaw/cron .openclaw/identity .openclaw/extensions .openclaw/devices .openclaw/openclaw.json .openclaw/openclaw.json.bak .openclaw/openclaw.json.bak.1 .openclaw/openclaw.json.bak.2 .openclaw/openclaw.json.bak.3 .openclaw/exec-approvals.json .openclaw/feishu .openclaw/canvas .openclaw/media .openclaw/completions .openclaw/delivery-queue .openclaw/subagents .openclaw/update-check.json EOF ``` The data is written to a gzip-compressed tar archive without archive-level encryption: ```bash tar -czf "$BACKUP_FILE" -T /tmp/openclaw-backup-list.txt ``` ### Technical Analysis The declared purpose requires reading OpenClaw data, but the generated archive contains broad categories of sensitive information, including conversation history, memory, identity data, configuration backups, and credential storage. The `tar -czf` operation provides compression only. Gzip does not provide encryption, authentication, or tamper detection. The script also does not set a restrictive `umask` before creating the output. Consequently, the resulting file permissions depend on the caller's environment and the behavior of the destination filesystem. If the destination file already exists, its prior permissions may also remain relevant. Although the documentation describes credentials as encrypted, the archive may still contain sensitive metadata, locally decryptable material, configuration secrets, or other private content. The archive as a whole remains readable to anyone who can access the output file. ### ...[truncated 1342 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The code clearly implements local backup of OpenClaw data and supports two backup modes: default exclusion of the skills directory and optional inclusion via INCLUDE_SKILLS=1, which aligns with the quick/full backup description. It writes the archive to the desktop by default or to a user-supplied path, also consistent with the description. However, there is no logic for scheduling, cron setup, timers, or automatic recurring execution in this code chunk. Since 'supports scheduled automatic backups' is part of the declared description but not represented in the supplied code, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill performs backups of OpenClaw data, including quick/full backup modes and scheduled automatic backups. The supplied code does not create backups at all. Its primary purpose is the opposite: restoring from an existing backup archive. It validates an input backup file, warns about missing OpenClaw installation, prompts before replacing existing ~/.openclaw data, moves current data to a timestamped backup directory, extracts the archive into the home directory, and optionally syncs skills. This is a material description-behavior mismatch because the code's core function is restore, not backup, and it also lacks any scheduling functionality described in the declaration.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/backup.sh (reported line 73)May include surrounding context.

sh
tar -czf "$BACKUP_FILE" -T /tmp/openclaw-backup-list.txt

# 清理临时文件
rm -f /tmp/openclaw-backup-list.txt

# 显示结果
ACTUAL_SIZE=$(du -h "$BACKUP_FILE" | cut -f1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly states that backups include highly sensitive material such as conversation history, memory data, configuration, and encrypted credentials, but the operational backup/restore instructions do not prominently warn users that they are creating and transferring a sensitive archive. In a backup/migration skill, this omission increases the chance users will store the archive on insecure media or share it through untrusted channels, leading to confidentiality loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The restore workflow describes automatic installation, extraction, and startup behavior without an explicit caution that running the restore script will modify the local system and may overwrite or replace existing OpenClaw data. Because this is presented as a simple one-click action, users may execute it without understanding the extent of system changes, increasing the risk of accidental overwrite, unwanted software installation, or restoration from an untrusted archive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that backups include sensitive material such as conversation history, memory, configuration, and encrypted credentials, but it does not prominently warn users that the resulting archive is security-sensitive. Users may store, transfer, or share the archive insecurely, leading to disclosure of private data or credential material if the archive is accessed by others.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a quick backup as 'without skills' and positions it as a smaller desktop backup, but the implemented file list still includes sensitive and broad OpenClaw state such as .openclaw/credentials, .openclaw/identity, and other operational data. This is more than a minimal lightweight cache-style backup and materially expands what the skill preserves beyond the manifest's simplified framing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The backup list explicitly includes .openclaw/credentials, causing secrets to be written into a tar.gz archive without any warning, access control guidance, or optional exclusion. In a desktop-backup workflow, users may move or store the archive insecurely, increasing the risk of credential disclosure if the file is copied, synced, or accessed by another user.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is described as a backup utility, but it also includes full restore behavior that overwrites user state under ~/.openclaw and extracts an arbitrary archive into the user's home directory. This mismatch increases the chance that users invoke destructive functionality without expecting it, and the restore flow lacks archive-content validation, making it risky if a malicious or tampered backup file is supplied.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · README.md (reported line 178)May include surrounding context.

md
### Ease of Use / 易用性

**English:**
- **No technical knowledge required** - Double-click scripts handle everything
- **Automatic detection** - Detects existing data and preserves it
- **Smart installation** - Installs OpenClaw automatically if missing
- **Cross-platform** - Same backup works on macOS, Linux, and Windows

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

All user-facing comments and echo output are in Chinese, with no option to select another language and no documentation that the skill is intentionally limited to a Chinese-speaking audience. This is a natural-language policy concern because it imposes a locale/language choice without opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

Beyond handling backup archives, the script checks for an OpenClaw installation and advises global npm installation, then later runs clawhub sync after restore. Those operational capabilities relate to environment setup and remote/local skill synchronization rather than the manifest's narrowly stated backup purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.