Back to skill

Security audit

OpenClaw Browser WSL Attach

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-aligned for repairing OpenClaw browser automation, but it weakens browser isolation and persistently changes OpenClaw configuration in ways users should review first.

Install only if you specifically need this OpenClaw browser workaround. Prefer running Chromium as an unprivileged user with sandboxing enabled; if you use this skill, review the config changes first, keep the browser profile separate from sensitive sessions, and be aware it may kill existing Chromium processes on port 18800 and persistently modify ~/.openclaw/openclaw.json.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start-browser.sh:20
Finding

Chromium Runs as Root with Its Security Sandbox Disabled

Content
View full analysis
"$LOG_FILE" 2>&1 & ``` The insecure configuration is also explicitly recommended in `SKILL.md`, lines 41-48, and `references/troubleshooting.md`, lines 17-20. ### Technical Analysis The script launches Chromium with `--no-sandbox`. The project documentation specifically recommends this configuration when OpenClaw or Chromium runs as root. Chromium's sandbox is a defense-in-depth boundary intended to isolate browser renderer processes and web content from the operating-system account running the browser. Disabling it means that exploitation of a browser or renderer vulnerability may provide direct access to the privileges of the Chromium process rather than requiring a separate sandbox escape. The risk is especially significant in the documented root-run workflow. Browser automation is expected to visit and interact with external web pages, including potentially attacker-controlled content. The CDP endpoint also offers extensive browser-control capabilities, although the script's own health check accesses it through loopback. ### Attack Path 1. OpenClaw or an operator invokes `scripts/start-browser.sh` as root. 2. The script starts Chromium with `--no-sandbox`. 3. The automated browser visits an attacker-controlled or compromised web page. 4. The page exploits a Chromium renderer or browser-process vulnerability. 5. Because the sandbox is disabled, the exploit executes with the privileges of the Chromium process. 6. In the documented root-run scenario, the attacker may consequently execute commands, read or modify files, access browser data, or al ...[truncated 836 chars]
Remediation
View remediation
&2 exit 1 fi ``` 4. If an exceptional environment requires `--no-sandbox`, require an explicit opt-in variable and display a prominent security warning rather than enabling it automatically. 5. Place the browser inside an additional isolation boundary, such as a tightly configured container or sandbox with: - No unnecessary host mounts. - A read-only root filesystem where practical. - Dropped Linux capabilities. - Seccomp and mandatory access-control policies. - Restricted network access. 6. Use a separate browser profile with restrictive filesystem permissions and avoid storing privileged authentication material in that profile. 7. Update `SKILL.md` and `references/troubleshooting.md` so that root execution without a sandbox is described as a last-resort unsafe mode, not the preferred configuration. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/start-browser.sh:6
Finding

Predictable Shared Temporary Log Path Allows Symlink-Based File Clobbering

Content
View full analysis
"$LOG_FILE" 2>&1 & ``` ### Technical Analysis The default log file is a fixed name in the shared `/tmp` directory. Before Chromium is executed, the shell opens the destination using `>` and follows symbolic links. The redirection also truncates an existing destination. If a privileged operator runs this script and an attacker can prepare `/tmp/openclaw-browser.log` as a symbolic link, the redirection may open and truncate the link target with the operator's privileges. Browser output can subsequently be written into that target. The exploitability depends on local filesystem protections, ownership of an existing log file, mount options, and symbolic-link protection settings. It is most applicable on the first invocation, after the log has been removed, or in an environment where the attacker can otherwise control the path. The environment variable override does not remove the insecure default. It may also expose the same issue if an untrusted caller can influence `OPENCLAW_BROWSER_LOG`. ### Attack Path 1. A local attacker confirms that `/tmp/openclaw-browser.log` does not already exist or can otherwise be replaced. 2. The attacker creates a symbolic link at that path pointing to a file writable only by the privileged account, such as a service configuration or other root-owned file. 3. A privileged operator runs `scripts/start-browser.sh`. 4. The shell processes `>"$LOG_FILE"` before launching Chromium. 5. The ...[truncated 951 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly instructs the agent/operator to read and rewrite user configuration files and execute shell commands, but it does not declare an explicit tool scope or permissions boundary. That omission increases the chance of over-broad execution in environments that rely on metadata for least-privilege enforcement, making file and shell side effects less visible and less controllable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends noSandbox: true for Chromium when running as root, but does not provide a strong warning that disabling the browser sandbox removes a major containment boundary for malicious web content. In a browser automation context that may visit untrusted pages, this substantially raises the risk that a renderer or browser compromise could lead to host-level impact, especially when combined with root execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The repair workflow describes killing Chromium processes, rewriting ~/.openclaw/openclaw.json, and restarting services without clearly warning that active browser sessions may be terminated and user configuration may be overwritten. This can cause unintended denial of service, data loss in active sessions, or persistent configuration changes that the user did not knowingly approve.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script overwrites the user's persistent OpenClaw configuration without any interactive confirmation, dry-run mode, or explicit opt-in at execution time. Because it forces security-relevant browser settings such as noSandbox=true and attachOnly=true, an unsuspecting user or automated workflow could have their environment silently changed in a way that weakens browser isolation and affects future sessions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script launches Chromium with --no-sandbox, which disables a core browser isolation boundary. In this skill's context, the browser is explicitly intended for automation, login flows, clicking, typing, and page extraction, so it may process untrusted web content while OpenClaw runs as root or in headless sessions; if the browser is compromised, disabling the sandbox materially increases the chance of host-level code execution or full process compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.