Back to skill

Security audit

Bud Sudo Tool

Security checks for vulnerabilities and agentic risk

Overview

This skill openly aims to save a sudo password and reuse it for arbitrary root commands, but its scope and credential handling are too risky for automatic trust.

Install only if you intentionally want a reusable local sudo-password vault and arbitrary root-command wrapper. Prefer interactive sudo or tightly scoped sudoers rules for specific commands; if already used, remove the stored .password.enc and .salt files and consider rotating the account password.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
sudo-tool.sh:59
Finding

Sudo Credential Encryption Key Stored Beside Ciphertext

Content
View full analysis
"$SALT_FILE" # Encrypt and store if ! echo "$PASSWORD" | openssl aes-256-cbc -salt -pbkdf2 -out "$PW_FILE" -pass pass:"$SALT" 2>&1; then echo "❌ Failed to encrypt password" exit 1 fi chmod 600 "$PW_FILE" chmod 600 "$SALT_FILE" echo "" echo "✅ Password configured successfully!" } get_password() { if ! is_configured; then echo "❌ Password not configured. Run: sudo-tool setup" exit 1 fi SALT=$(cat "$SALT_FILE") local PW if ! PW=$(openssl aes-256-cbc -d -pbkdf2 -in "$PW_FILE" -pass pass:"$SALT" 2>/dev/null); then echo "❌ Failed to decrypt password" exit 1 fi ``` ### Technical Analysis The random value named `SALT` is not merely a public cryptographic salt. It is supplied through `-pass pass:"$SALT"` and therefore acts as the secret from which OpenSSL derives the encryption key. The same value is written to `.salt` next to `.password.enc`. Consequently, possession of both files is sufficient to decrypt the stored sudo password. The design does not use a user-supplied master secret, hardware-backed key, operating-system credential vault, or system-bound key. File permissions reduce exposure to other local accounts but do not protect against malicious processes running as the user, compromised backups, accidental archival, or later compromise of that account. This also conflicts with the documentation's assertion that the credential is “not recoverable without your system.” The credential is recoverable using the ciphertext, the adjacent `.salt` file, and OpenSSL. ### Attack Path 1. An attacker obtains execution under the affected user account or gains rea ...[truncated 1206 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
sudo-tool.sh:90
Finding

Root Command Injection Through Shell String Construction

Content
View full analysis
"$TMPFILE" # Run sudo with password from temp file, then delete sudo -S bash -c "$CMD" < "$TMPFILE" rm -f "$TMPFILE" } ``` The function is reached through the following argument forwarding logic at `sudo-tool.sh:151-153`: ```bash shift run_sudo "$CMD" "$@" ``` ### Technical Analysis `local CMD="$*"` concatenates all command arguments into a single string, discarding their original boundaries. The resulting string is then supplied to `bash -c` under `sudo`. Shell metacharacters in any argument—including command separators, redirections, substitutions, pipelines, and expansions—are interpreted as shell syntax rather than literal argument data. A caller may believe it is forwarding a structured argument array safely, but this implementation re-parses that data as a root shell program. The tool intentionally supports arbitrary privileged commands, so a user directly entering a malicious command already has substantial control. The injection vulnerability is especially relevant when another skill, automation layer, or script invokes `sudo-tool` with partially untrusted data. In that scenario, control of a single argument can become control of an entire root shell command. ### Attack Path 1. A legitimate automat ...[truncated 1268 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
sudo-tool.sh:108
Finding

Plaintext Sudo Password Temporary File Is Not Reliably Removed

Content
View full analysis
"$TMPFILE" # Run sudo with password from temp file, then delete sudo -S bash -c "$CMD" < "$TMPFILE" rm -f "$TMPFILE" ``` The script enables immediate exit behavior at `sudo-tool.sh:5`: ```bash set -e ``` ### Technical Analysis The decrypted sudo password is written in plaintext to a filesystem-backed temporary file. Cleanup occurs only through the final `rm -f` statement and is not registered in an `EXIT`, `HUP`, `INT`, or `TERM` trap. Because the script uses `set -e`, a nonzero result from the `sudo` command can terminate the script before `rm -f` runs. Forced termination, signals, system interruption, or a process crash can produce the same outcome. The documentation and inline comment claiming that temporary files are deleted immediately are therefore not reliable. `mktemp` ordinarily creates a uniquely named file with restrictive permissions, and the script additionally applies mode `600`. These controls reduce cross-user exposure but do not eliminate plaintext persistence. The file remains readable by the affected user and by any process executing under that identity. It may also be captured by diagnostics, snapshots, backups, or forensic acquisition. ### Attack Path 1. The tool decrypts the stored sudo password into `PW`. 2. It creates a temporary file and writes the plaintext password into it. 3. The attacker causes the privileged command to fail, terminates the wrapper, or waits for an unrelated interruption. 4. Due to `set -e` or process termination, execution does not reach `rm -f "$TMPFILE"`. 5. The attacker, operating as the same user or through a process with access to that ...[truncated 858 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (30)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

100k iterations)

  • No plaintext passwords stored anywhere
  • Temp files deleted immediately after use

Required By

  • vpn-mesh — needs sudo to auto-install WireGuard

Files

text
~/.openclaw/sudo-tool/
├── .password.enc   # Encrypted password
├── .salt           # Random salt for encryption
└── sudo-tool.sh     # The tool itself

Add to PATH with:

bash
echo 'export PATH="$HOME/bin:$PATH"' >> ~/.bashrc
ln -s ~/.openclaw/sudo-tool/sudo-tool.sh ~/bin/sudo-tool

Chaining Abuse

High
Category
Tool Misuse
Confidence
86% confidence
Finding

The pattern echo "$PASSWORD" | sudo -S ... demonstrates an automation-friendly privilege-escalation primitive that can be reused or adapted by other components. In a skill ecosystem, this materially increases chaining risk because once a password is available, root execution can occur non-interactively and with minimal friction.

Content

Scanner excerpt · sudo-tool.sh (reported line 51)May include surrounding context.

sh
fi
    
    # Test password first
    if ! echo "$PASSWORD" | sudo -S echo "   ✅ Password verified" 2>/dev/null; then
        echo "❌ Incorrect password"
        exit 1
    fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: sudo-tool
description: "Store and use sudo password for automated root commands. Essential companion for skills that need sudo access (like vpn-mesh)."
metadata:
  {
    "version": "1.0.0",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
---
name: sudo-tool
description: "Store and use sudo password for automated root commands. Essential companion for skills that need sudo access (like vpn-mesh)."
metadata:
  {
    "version": "1.0.0",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
---
name: sudo-tool
description: "Store and use sudo password for automated root commands. Essential companion for skills that need sudo access (like vpn-mesh)."
metadata:
  {
    "version": "1.0.0",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
50% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: sudo-tool
description: "Store and use sudo password for automated root commands. Essential companion for skills that need sudo access (like vpn-mesh)."
metadata:
  {
    "version": "1.0.0",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
}
---

# Sudo Tool 🔐

**Securely store your sudo password for automated root commands.** No more re-entering passwords for every sudo call.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Setup (One-time)

bash
# Configure your sudo password (one-time only)
sudo-tool setup

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill states it stores the user's sudo password on disk for later automated use. Even if encrypted, persistent storage of a reusable local privilege credential materially increases attack surface: compromise of the account, key material, decryption routine, or the skill itself can enable privilege escalation to root.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

sudo-tool setup

text

You'll be prompted to enter your sudo password. It's encrypted with OpenSSL and stored in `~/.openclaw/sudo-tool/` — never in plaintext.

---

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The skill explicitly advertises running arbitrary commands with sudo, which turns it into a generic privilege-escalation wrapper. In the context of an agent skill with exec access, this is dangerous because any downstream prompt injection, compromised companion skill, or user mistake can result in unrestricted root command execution on the host.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
# Check if configured
sudo-tool status

# Run any command with sudo
sudo-tool apt update
sudo-tool apt install wireguard-tools
sudo-tool systemctl restart nginx

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

The documented ability to run any command with sudo gives the skill effectively unrestricted root execution. In an agent environment this is especially dangerous because a single prompt-manipulated or compromised invocation could install persistence, alter network settings, exfiltrate secrets, or damage the host.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
# Check if configured
sudo-tool status

# Run any command with sudo
sudo-tool apt update
sudo-tool apt install wireguard-tools
sudo-tool systemctl restart nginx

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
97% confidence
Finding

Using sudo -S with a recovered stored password automates privileged execution by feeding credentials through stdin. While it may avoid process-list leakage, it still centralizes and operationalizes the user's sudo secret, making credential theft or misuse by the agent ecosystem far easier.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
## How It Works

1. **Setup** — encrypts your password with OpenSSL (AES-256-CBC) using a random salt, stores in `~/.openclaw/sudo-tool/.password.enc`
2. **Use** — decrypts password and pipes to `sudo -S` (reads from stdin)
3. **Secure** — password never appears in process list, temp files are deleted immediately

---

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
97% confidence
Finding

Using sudo -S with a recovered stored password automates privileged execution by feeding credentials through stdin. While it may avoid process-list leakage, it still centralizes and operationalizes the user's sudo secret, making credential theft or misuse by the agent ecosystem far easier.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
## How It Works

1. **Setup** — encrypts your password with OpenSSL (AES-256-CBC) using a random salt, stores in `~/.openclaw/sudo-tool/.password.enc`
2. **Use** — decrypts password and pipes to `sudo -S` (reads from stdin)
3. **Secure** — password never appears in process list, temp files are deleted immediately

---

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
87% confidence
Finding

The file is explicitly designed to provide superuser execution capability. Root-execution functionality is inherently high risk in this skill context because it is a generic privilege-escalation helper rather than a narrowly scoped admin task, so misuse or chaining by other skills can result in complete host compromise.

Content

Scanner excerpt · sudo-tool.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash
# Sudo Tool - Execute commands with superuser privileges
# Uses OpenSSL for password encryption (more reliable than GPG)

set -e

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
83% confidence
Finding

The usage text advertises the tool as a general mechanism to run commands with elevated privileges. In context, that broad positioning makes the skill more dangerous because it encourages arbitrary root command execution and use as a reusable escalation primitive by other automation.

Content

Scanner excerpt · sudo-tool.sh (reported line 12)May include surrounding context.

sh
SALT_FILE="$TOOL_DIR/.salt"

usage() {
    echo "Sudo Tool - Run commands with elevated privileges"
    echo ""
    echo "Usage:"
    echo "  sudo-tool setup              Configure password (one-time)"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · sudo-tool.sh (reported line 27)May include surrounding context.

sh
ensure_tool_dir() {
    mkdir -p "$TOOL_DIR"
    chmod 700 "$TOOL_DIR"
}

is_configured() {

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

The setup flow is dedicated to capturing the user's sudo password for later automated reuse. In this context, collecting a root-capable credential is itself dangerous because compromise of the stored secret directly enables privileged command execution on the host.

Content

Scanner excerpt · sudo-tool.sh (reported line 37)May include surrounding context.

sh
setup_password() {
    ensure_tool_dir
    
    echo "🔐 Setting up sudo password (one-time)..."
    echo ""
    echo "⚠️  Your password will be stored encrypted in:"
    echo "   $PW_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

This skill collects and persistently stores the user's sudo password, which is an extremely sensitive credential, but only presents a minimal notice that it will be stored 'encrypted'. Because the script also stores the decryption material locally, the warning understates the real risk: local compromise of the account or tool directory can expose root credentials and enable full privilege escalation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
98% confidence
Finding

The script prompts directly for the user's sudo password, a credential that can unlock full system control. Within an agent skill ecosystem, requesting such a secret is especially risky because users may normalize handing over privileged credentials to automation that can later be reused without oversight.

Content

Scanner excerpt · sudo-tool.sh (reported line 42)May include surrounding context.

sh
echo "⚠️  Your password will be stored encrypted in:"
    echo "   $PW_FILE"
    echo ""
    read -s -p "Enter your sudo password: " PASSWORD
    echo ""
    
    if [ -z "$PASSWORD" ]; then

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

Using sudo -S explicitly enables non-interactive password submission to sudo, which is risky because it bypasses the normal interactive trust boundary and requires handling the raw root-capable secret in script logic. This pattern is often abused to automate privilege escalation once credentials are obtained.

Content

Scanner excerpt · sudo-tool.sh (reported line 51)May include surrounding context.

sh
fi
    
    # Test password first
    if ! echo "$PASSWORD" | sudo -S echo "   ✅ Password verified" 2>/dev/null; then
        echo "❌ Incorrect password"
        exit 1
    fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

Using sudo -S explicitly enables non-interactive password submission to sudo, which is risky because it bypasses the normal interactive trust boundary and requires handling the raw root-capable secret in script logic. This pattern is often abused to automate privilege escalation once credentials are obtained.

Content

Scanner excerpt · sudo-tool.sh (reported line 51)May include surrounding context.

sh
fi
    
    # Test password first
    if ! echo "$PASSWORD" | sudo -S echo "   ✅ Password verified" 2>/dev/null; then
        echo "❌ Incorrect password"
        exit 1
    fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · sudo-tool.sh (reported line 66)May include surrounding context.

sh
exit 1
    fi
    
    chmod 600 "$PW_FILE"
    chmod 600 "$SALT_FILE"
    echo ""
    echo "✅ Password configured successfully!"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · sudo-tool.sh (reported line 67)May include surrounding context.

sh
exit 1
    fi
    
    chmod 600 "$PW_FILE"
    chmod 600 "$SALT_FILE"
    echo ""
    echo "✅ Password configured successfully!"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
94% confidence
Finding

Writing the recovered sudo password to a temporary file, even briefly, creates another at-rest copy of a root-capable credential. If the script crashes before cleanup, the file persists; additionally, temporary-file handling increases the risk of accidental disclosure through backups, forensic recovery, or host compromise.

Content

Scanner excerpt · sudo-tool.sh (reported line 108)May include surrounding context.

sh
# Write password to secure temp file (deleted immediately after)
    local TMPFILE=$(mktemp)
    chmod 600 "$TMPFILE"
    echo "$PW" > "$TMPFILE"
    
    # Run sudo with password from temp file, then delete

Static analysis

No suspicious patterns detected.