Back to skill

Security audit

Agent Tab Title

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly scoped local patch for OpenClaw tab titles, with some operational risks around modifying and restoring the installed UI file.

Install only if you are comfortable with a local patch that edits OpenClaw's installed Control UI file. Avoid running it with elevated privileges unless necessary, confirm the target path, keep in mind that updates may require reapplying the patch, and reinstall OpenClaw if rollback leaves the UI broken.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/apply.sh:105
Finding

Inline Patch Removal Can Truncate the Control UI HTML

Content
View full analysis
/ { buf=$0; in_script=1; next } in_script { buf=buf"\n"$0 if (index($0, marker)) { has_marker=1 } if ($0 ~ /<\/script>/) { if (!has_marker) print buf buf=""; in_script=0; has_marker=0 } next } { print } ' "$INDEX_FILE" > "${INDEX_FILE}.tmp" && mv "${INDEX_FILE}.tmp" "$INDEX_FILE" ``` ### Technical Analysis The fallback uninstall implementation attempts to parse HTML scripts with line-oriented AWK rules. When a line contains both ``, the opening-tag rule stores the line and immediately executes `next`: ```awk /`, the buffered content is discarded at end-of-file. The generated output is not validated for completeness before: ```bash mv "${INDEX_FILE}.tmp" "$INDEX_FILE" ``` This behavior is particularly relevant to bundled or minified HTML, where complete script elements commonly appear on one line. It can replace the original Control UI file with a truncated document. ### Attack Path 1. The target Control UI `index.html` contains the patch marker. 2. The corresponding `.bak` file is absent, causing uninstall to use the AWK fallback. 3. The HTML contains a one-line script element with both opening and closing tags. 4. The user executes: ```bash bash scripts/apply.sh --uninstall ``` 5. AWK sees `
Remediation
View remediation
``` 2. Remove only the content between those exact markers rather than attempting to parse arbitrary HTML script elements with AWK. 3. Create temporary files with `mktemp` in the destination directory instead of using a predictable `${INDEX_FILE}.tmp` path. 4. Before replacement, validate that: - Both expected patch delimiters were found. - The output still contains required document structure such as `` and ``. - The output is nonempty and does not unexpectedly shrink beyond the known patch size. - The patch marker is absent after removal. 5. Preserve the original file until all validation succeeds, then perform a same-filesystem atomic rename. 6. If validation fails, leave the target untouched and return a nonzero exit status. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/apply.sh:135
Finding

Stale Backup Restoration Can Downgrade or Break an Updated Control UI

Content
View full analysis
$BAK_FILE" else echo "Backup already exists at $BAK_FILE (kept as the pristine rollback point)." fi ``` Uninstall later restores that backup unconditionally: ```bash if [[ -f "$BAK_FILE" ]]; then cp "$BAK_FILE" "$INDEX_FILE" echo "Restored $INDEX_FILE from $BAK_FILE" echo "(.bak kept; remove manually if you want.)" ``` ### Technical Analysis The backup has no associated package version, timestamp policy, or content hash. Once created, it is treated as the permanent rollback source even when the installed OpenClaw package has subsequently changed. If an OpenClaw update replaces `index.html` but leaves the adjacent `.bak` file intact, reapplying the patch retains the old backup. A later uninstall copies the old document over the newer package file. This can produce a version mismatch between `index.html` and the current JavaScript, CSS, or backend components. The behavior also conflicts with the assumption that the backup is always a pristine rollback point. It may be pristine only for an earlier package release. ### Attack Path 1. A user applies the patch, creating `index.html.bak`. 2. OpenClaw is upgraded, replacing the current distribution files while the backup remains. 3. The user reapplies the patch. 4. The script detects the old backup and deliberately keeps it. 5. The user later runs: ```bash bash scripts/apply.sh --uninstall ``` 6. The script unconditionally copies the old backup over the current `index.html`. 7. The restored HTML references or expects assets and behavior from the earli ...[truncated 751 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file instructs the user to run a script that edits openclaw/dist/control-ui/index.html in place and manages an index.html.bak rollback file. Although the mechanics are described, there is no clear user-facing caution that this alters installed package contents and may be overwritten by updates, which is the kind of system-affecting behavior SQP-2 asks markdown files to warn about.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.