Back to skill

Security audit

Security Dashboard

Security checks for vulnerabilities and agentic risk

Overview

This is a real local security dashboard, but its installer grants broader passwordless sudo access than the documentation makes clear and the web server has file disclosure and dashboard injection risks.

Review and harden scripts/install.sh before installing. Prefer the dedicated user over root, replace wildcard sudoers entries with a narrow root-owned metrics helper, keep the dashboard bound to 127.0.0.1, and fix the static file traversal and innerHTML rendering issues before exposing it to administrators.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/install.sh:26
Finding

Overbroad Passwordless Sudo Authorization for the Dashboard Account

Content
View full analysis
"$SUDOERS_FILE" << 'SUDOEOF' # Allow openclaw-dashboard to check security status without password Cmnd_Alias DASHBOARD_CMDS = /usr/bin/systemctl is-active *, \ /usr/bin/systemctl status *, \ /usr/bin/fail2ban-client status *, \ /usr/sbin/ufw status, \ /usr/bin/firewall-cmd --state, \ /usr/bin/journalctl *, \ /usr/bin/ss *, \ /usr/bin/tailscale status * openclaw-dashboard ALL=(ALL) NOPASSWD: DASHBOARD_CMDS SUDOEOF chmod 440 "$SUDOERS_FILE" ``` ### Technical Analysis The installer creates a passwordless sudo policy for the `openclaw-dashboard` account. Several permitted commands accept unrestricted wildcard arguments, including: - `/usr/bin/journalctl *` - `/usr/bin/systemctl status *` - `/usr/bin/fail2ban-client status *` - `/usr/bin/ss *` The rule also permits execution as any target account through `ALL=(ALL)`, even though the dashboard only needs narrowly scoped, read-only checks as root. An attacker who obtains command execution as this account could supply arguments that were not anticipated by the application. In particular, unrestricted privileged journal access can expose logs from arbitrary services. Such logs may contain environment details, usernames, internal addresses, command lines, request data, tokens accidentally logged by other applications, or other operationally sensitive information. Several grants are broader than the commands actually invoked with `sudo` in `server.js`. The implementation uses sudo for specific `ss`, `ufw`, `firewall-cmd`, ` ...[truncated 1788 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
server.js:421
Finding

Static File Path Traversal Can Expose Files Outside the Public Directory

Content
View full analysis
{ if (error) { if (error.code === 'ENOENT') { res.writeHead(404); res.end('404 Not Found'); } else { res.writeHead(500); res.end('500 Internal Server Error'); } } else { res.writeHead(200, { 'Content-Type': contentType }); res.end(content); } }); ``` ### Technical Analysis The server directly combines the attacker-controlled `req.url` value with `PUBLIC_DIR` and reads the resulting path. It does not: - Parse and isolate the URL pathname. - Reject `..` path components. - Canonicalize the final path and verify that it remains inside `PUBLIC_DIR`. - Restrict static content to an allowlist. - Reject query strings, encoded separators, or malformed paths before filesystem access. Normalization of traversal components can produce a path outside the intended `public/` directory. If the resulting file is readable by the service account, `fs.readFile` returns it to the requester. The localhost-only listener reduces remote exposure, but it does not eliminate the vulnerability. The service is intentionally accessed through SSH forwarding, and other local processes can reach it. The documented root installation option significantly increases impact because the server would then be able to read files using root privileges. ### Attack Path 1. The attacker obtains access to the local dashboard endpoint, either from the host, through an authorized or compromis ...[truncated 1046 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
public/index.html:284
Finding

Unescaped Security Metrics Permit Dashboard Cross-Site Scripting

Content
View full analysis
= 32 ? 'good' : 'critical')} ${metric('Auth Mode', openclaw.authMode, openclaw.authMode === 'token' ? 'good' : 'warning')} ${metric('Main Sessions', openclaw.sessionCount)} ${metric('Subagents', openclaw.subagentCount)} ${metric('Skills Enabled', openclaw.skillsCount)} ${metric('Current Version', openclaw.currentVersion)} ${metric('Updates', openclaw.updateStatus, openclaw.updateAvailable ? 'warning' : 'good')} `; } ``` Additional affected rendering includes alerts: ```javascript function renderAlerts(alerts) { const container = document.getElementById('alerts'); if (!alerts || alerts.length === 0) { container.innerHTML = ''; return; } container.innerHTML = alerts.map(alert => `
${alert.title}
${alert.message}
`).join(''); } ``` The common rendering function inserts values directly into markup: ```javascript function metric(label, value, status) { const statusClass = status ? `value-${status}` : ''; const icon = status === 'good' ? '✓' : status === 'critical' ? '✗' : status === 'warning' ? '⚠' : ''; return `
...[truncated 2269 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill provides real-time security monitoring of Linux/OpenClaw infrastructure. However, the supplied code chunk does not implement monitoring, dashboarding, alerting, or security checks. It is strictly a publishing script used to upload/package the skill to ClawdHub with metadata. That is a materially different primary purpose from the declared functionality, so this code chunk does not accurately represent the described behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
Edit `server.js` line 445:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
Edit `server.js` line 445:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

md
Edit `server.js` line 445:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

md
- `public/index.html` - Dashboard UI

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 314)May include surrounding context.

bash
sudo systemctl stop security-dashboard
sudo systemctl disable security-dashboard
sudo rm /etc/systemd/system/security-dashboard.service
sudo systemctl daemon-reload

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 320)May include surrounding context.

Then remove skill directory:

bash
rm -rf /root/clawd/skills/security-dashboard

Publishing

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 320)May include surrounding context.

Then remove skill directory:

bash
rm -rf /root/clawd/skills/security-dashboard

Publishing

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · public/index.html (reported line 168)May include surrounding context.

html
<div id="alerts"></div>

    <div class="dashboard">
        <!-- OpenClaw Security -->
        <div class="section">
            <div class="section-header">
                <div class="section-title">

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · server.js (reported line 351)May include surrounding context.

js
alerts.push({
      level: 'warning',
      title: `${system.updates} System Updates Available`,
      message: 'Run: sudo apt update && sudo apt upgrade'
    });
  }

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 50)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 51)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 273)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 312)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 313)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 314)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 315)May include surrounding context.

bash
# Service management
sudo systemctl status security-dashboard
sudo systemctl restart security-dashboard

# View logs

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documentation describes installation, service management, and shell-based operational steps, but it does not declare any explicit tool scope such as allowed-tools or permissions. In an agent ecosystem, missing tool constraints can let the skill invoke shell/environment capabilities more broadly than users expect, increasing the risk of command execution outside the stated monitoring purpose.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
server.js:16