T09 · Insecure Skill Coding Practices
- Location
test-restore.ps1:38- Finding
Decrypted OpenClaw Credentials Persist in Local Restore Directories
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent OpenClaw backup/restore skill, but its restore scripts handle sensitive decrypted data and live OpenClaw replacement in ways users should review carefully before installing.
Install only if you are comfortable backing up OpenClaw credentials and auth profiles to your own Cloudflare R2 bucket, protected by your restic password. Use a strong password, keep .env and .restic-pass private and separate, run the test restore first, manually delete decrypted restore-test/OpenClaw-restore folders after inspection, and avoid non-interactive restore unless you have a separate verified backup of the current .openclaw directory.
test-restore.ps1:38Decrypted OpenClaw Credentials Persist in Local Restore Directories
portable/restore-portable.ps1:82Destructive Restore Can Continue After Failed or Partial Native Commands
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#
# Coloque nesta mesma pasta:
# restic\restic.exe (binario do restic)
# .env (credenciais R2 + RESTIC_REPOSITORY)
# .restic-pass (senha do repositorio)
#
# O script: baixa o backup mais recente do R2, extrai e
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#
# Coloque nesta mesma pasta:
# restic\restic.exe (binario do restic)
# .env (credenciais R2 + RESTIC_REPOSITORY)
# .restic-pass (senha do repositorio)
#
# O script: baixa o backup mais recente do R2, extrai e
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#
# Coloque nesta mesma pasta:
# restic\restic.exe (binario do restic)
# .env (credenciais R2 + RESTIC_REPOSITORY)
# .restic-pass (senha do repositorio)
#
# O script: baixa o backup mais recente do R2, extrai e
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#
# Coloque nesta mesma pasta:
# restic\restic.exe (binario do restic)
# .env (credenciais R2 + RESTIC_REPOSITORY)
# .restic-pass (senha do repositorio)
#
# O script: baixa o backup mais recente do R2, extrai e
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
#
# Coloque nesta mesma pasta:
# restic\restic.exe (binario do restic)
# .env (credenciais R2 + RESTIC_REPOSITORY)
# .restic-pass (senha do repositorio)
#
# O script: baixa o backup mais recente do R2, extrai e
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
$Root = Split-Path -Parent $MyInvocation.MyCommand.Path
$ResticExe = Join-Path $Root 'restic\restic.exe'
$EnvFile = Join-Path $Root '.env'
$PassFile = Join-Path $Root '.restic-pass'
if (!(Test-Path $ResticExe)) { throw "Missing: $ResticExe" }
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
$Root = Split-Path -Parent $MyInvocation.MyCommand.Path
$ResticExe = Join-Path $Root 'restic\restic.exe'
$EnvFile = Join-Path $Root '.env'
$PassFile = Join-Path $Root '.restic-pass'
if (!(Test-Path $ResticExe)) { throw "Missing: $ResticExe" }
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
$Root = Split-Path -Parent $MyInvocation.MyCommand.Path
$ResticExe = Join-Path $Root 'restic\restic.exe'
$EnvFile = Join-Path $Root '.env'
$PassFile = Join-Path $Root '.restic-pass'
if (!(Test-Path $ResticExe)) { throw "Missing: $ResticExe" }
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
> ⚠️ **This OVERWRITES your live `.openclaw`.** The restore replaces `%USERPROFILE%\.openclaw` with the latest backup from R2. **Anything created after the last backup — new agents, credentials, config changes — is lost.** The script asks you to type `RESTAURAR` to confirm, and moves your current folder to `.openclaw.backup-<date>` first. But that local backup can fail if files are locked (e.g. the gateway is running), in which case it overwrites in place. **Run `test-restore.ps1` first** to inspect the backup non-destructively, and only run the real restore when you're sure you want to replace the active install.
>
> Non-interactive automation can skip the prompt by setting `$env:OPENCLAW_RESTORE_YES = 1` — do this only when you fully understand it overwrites without asking.
---
Comments and operational/status strings throughout the script are written in Portuguese, including error messages and runtime logs. This imposes a specific language on users without opt-in or any indication that the skill is intentionally limited to Portuguese-speaking contexts.
No suspicious patterns detected.