Back to skill

Security audit

OpenClaw Security Audit

Security checks for vulnerabilities and agentic risk

Overview

This security skill is mostly purpose-aligned, but its hardening mode handles live credentials in risky ways and under-declares some file changes.

Review harden.py carefully before use. Prefer running audit.py only, or use harden.py first in dry-run mode; if you proceed, restrict permissions on ~/.openclaw/.env and security-backups, inspect generated set_env.sh or set_env.ps1 before running it, and avoid using a custom --path from an untrusted source.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
harden.py:31
Finding

Sensitive credential files are created without restrictive permissions

Content
View full analysis

Vulnerability Details

File Location: harden.py:31-52 and harden.py:97-119
Vulnerability Type: Insecure plaintext credential storage
Risk Level: Medium

Vulnerable Code

python
def backup_config(self) -> Optional[Path]:
    """Create backup of current configuration"""
    if not self.config_file.exists():
        print("[ERROR] openclaw.json not found")
        return None

    if self.dry_run:
        print(f"[DRY-RUN] Would create backup in: {self.backup_dir}")
        return None

    self.backup_dir.mkdir(exist_ok=True)
    timestamp = datetime.now().strftime('%Y%m%d_%H%M%S')
    backup_path = self.backup_dir / f"openclaw.json.backup.{timestamp}"

    try:
        with open(self.config_file, 'r', encoding='utf-8') as f:
            config = f.read()

        with open(backup_path, 'w', encoding='utf-8') as f:
            f.write(config)

        print(f"[BACKUP] Configuration backed up to: {backup_path}")
        return backup_path
python
env_file = self.openclaw_path / ".env"
env_example = self.openclaw_path / ".env.example"

if self.dry_run:
    print(f"[DRY-RUN] Would create: {env_file}")
    print(f"[DRY-RUN] Would create: {env_example}")
    return None

# Generate .env file (actual credentials)
lines = [
    "# OpenClaw Environment Variables",
    f"# Generated: {datetime.now().isoformat()}",
    "# WARNING: Keep this file secure! Never commit to version control.",
    "",
]

for key, value in credentials.items():
    lines.append(f"{key}={value}")

try:
    with open(env_file, 'w', encoding='utf-8') as f:
        f.write('\n'.join(lines))
    print(f"[ENV] Created: {env_file}")

Technical Analysis

The hardening process creates two additional plaintext copies of credentials:

  1. A complete backup of the original openclaw.json, including all credentials it contained.
  2. A .env file containing extracted Feishu cr ...[truncated 2010 chars]
Remediation
View remediation

Remediation Suggestions

  • Create sensitive files atomically with owner-only permissions. On POSIX systems, use os.open with O_CREAT | O_EXCL | O_WRONLY and mode 0o600.
  • Create security-backups with mode 0o700 and verify the effective mode after creation.
  • If .env or backup files already exist, verify ownership and permissions before overwriting them.
  • Apply platform-appropriate access control lists on Windows so only the current user can read the files.
  • Avoid retaining plaintext backups by default. Require explicit consent or encrypt backups using a user-managed key.
  • Implement a documented retention policy and provide a safe mechanism for deleting obsolete plaintext backups.
  • Write files to a protected temporary file, flush and synchronize the content, then atomically rename the file into place.
  • Update the documentation and permission metadata to disclose all credential-bearing files created by hardening.

T09 · Insecure Skill Coding Practices

Error
Location
harden.py:204
Finding

User-controlled paths are embedded unsafely into generated executable scripts

Content
View full analysis

Vulnerability Details

File Location: harden.py:204-250 and harden.py:372-394
Vulnerability Type: Generated shell-script command injection
Risk Level: High

Vulnerable Code

python
def _generate_windows_script(self) -> Optional[Path]:
    """Generate Windows PowerShell setup script"""
    script_path = self.openclaw_path / "set_env.ps1"
    env_file = self.openclaw_path / ".env"

    if self.dry_run:
        print(f"[DRY-RUN] Would create: {script_path}")
        return None

    script_content = f'''# OpenClaw Environment Variables Setup Script
# Run: .\\set_env.ps1

$envFile = "{env_file}"

if (Test-Path $envFile) {{
    Get-Content $envFile | ForEach-Object {{
        if ($_ -match '^([^#][^=]*)=(.*)$') {{
            $name = $matches[1]
            $value = $matches[2]
            [Environment]::SetEnvironmentVariable($name, $value, 'User')
            Write-Host "Set $name = *** (hidden)"
        }}
    }}
    Write-Host "Environment variables set successfully!"
    Write-Host "Note: Restart your terminal for changes to take effect."
}} else {{
    Write-Error ".env file not found at $envFile"
}}
'''
python
def _generate_unix_script(self) -> Optional[Path]:
    """Generate Unix (macOS/Linux) shell setup script"""
    script_path = self.openclaw_path / "set_env.sh"
    env_file = self.openclaw_path / ".env"

    if self.dry_run:
        print(f"[DRY-RUN] Would create: {script_path}")
        return None

    script_content = f'''#!/bin/bash
# OpenClaw Environment Variables Setup Script
# Run: source set_env.sh

ENV_FILE="{env_file}"

if [ -f "$ENV_FILE" ]; then
    while IFS='=' read -r name value; do
        # Skip comments and empty lines
        [[ "$name" =~ ^#.*$ ]] && continue
        [[ -z "$name" ]] && continue
        export "$name=$value"
        echo "Exported $name"
    done < "$ENV_FILE"
    echo "Environmen
...[truncated 2890 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not embed user-controlled paths directly into generated source code.
  • Prefer a static setup script that accepts the .env path as a runtime argument and validates it before use.
  • For POSIX shell generation, encode values with a robust shell-quoting function such as shlex.quote; do not rely on surrounding a value with double quotes.
  • For PowerShell, implement a proper single-quoted literal encoder that doubles embedded single quotes, or pass the path as a parameter rather than generating it into the script.
  • Reject paths containing control characters, carriage returns, or newlines.
  • Resolve and validate the requested path before use, and optionally restrict hardening to the expected ~/.openclaw directory unless an explicit advanced option is enabled.
  • Add automated tests for paths containing spaces, quotes, $(), backticks, semicolons, PowerShell subexpressions, and newline characters.
  • Consider avoiding generated scripts entirely. The tool can instead print platform-specific, safely quoted instructions or directly launch a subprocess with an argument array where appropriate.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (34)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAWHUB_PUBLISH.md (reported line 26)May include surrounding context.

md
### 为什么需要这个 Skill?

你的 OpenClaw 配置文件中可能存储着:
- API Keys 和 Access Tokens
- 飞书/微信/Discord 等渠道凭证
- Gateway 认证令牌
- 数据库密码或其他敏感信息

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAWHUB_PUBLISH.md (reported line 60)May include surrounding context.

md
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAWHUB_PUBLISH.md (reported line 65)May include surrounding context.

md
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAWHUB_PUBLISH.md (reported line 146)May include surrounding context.

md
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 25)May include surrounding context.

md
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · harden.py (reported line 127)May include surrounding context.

python
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · harden.py (reported line 227)May include surrounding context.

python
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · harden.py (reported line 266)May include surrounding context.

python
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · harden.py (reported line 353)May include surrounding context.

python
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · harden.py (reported line 360)May include surrounding context.

python
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · harden.py (reported line 362)May include surrounding context.

python
### Harden (`harden.py`)
- Backs up your configuration
- Extracts credentials to .env file
- Sanitizes openclaw.json
- Generates platform-specific setup scripts

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill claims a narrowly scoped security-audit purpose, but the documented behavior includes modifying configuration, creating .env files, generating scripts, and writing reports without corresponding declared permissions. This mismatch is dangerous because users may trust the description while the skill performs broader state-changing actions that affect credential storage and system configuration.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill explicitly handles live credentials by extracting them from configuration and writing them into a .env file. Even for a legitimate security-hardening purpose, credential access and relocation are sensitive operations that can expose secrets if file permissions, backups, generated scripts, or placeholder replacement are mishandled.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
This will:
1. Backup your current configuration
2. Extract credentials from openclaw.json
3. Create .env file with credentials
4. Sanitize openclaw.json (replace with placeholders)
5. Generate setup scripts for Windows/macOS/Linux

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
4. Sanitize openclaw.json (replace with placeholders)
5. Generate setup scripts for Windows/macOS/Linux

**IMPORTANT**: After running harden.py, you must set environment variables before OpenClaw can access credentials.

### Custom Configuration

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
- ✅ Respects file permissions

This tool does NOT:
- ❌ Send data to external servers
- ❌ Modify system files outside ~/.openclaw
- ❌ Store or log actual credential values
- ❌ Require elevated permissions

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · audit.py (reported line 257)May include surrounding context.

python
return 'CRITICAL'
        elif any(x in name for x in ['token', 'auth']):
            return 'HIGH'
        elif any(x in name for x in ['.env', '.key', '.pem']):
            return 'MEDIUM'
        else:
            return 'LOW'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAWHUB_PUBLISH.md (reported line 203)May include surrounding context.

md
"secret-input.js"
  ],
  "sensitive_extensions": [
    ".env",
    ".key",
    ".pem",
    ".p12",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
"secret-input.js"
  ],
  "sensitive_extensions": [
    ".env",
    ".key",
    ".pem",
    ".p12",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · audit.py (reported line 77)May include surrounding context.

python
"secret-input.js"
  ],
  "sensitive_extensions": [
    ".env",
    ".key",
    ".pem",
    ".p12",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.json (reported line 17)May include surrounding context.

json
"secret-input.js"
  ],
  "sensitive_extensions": [
    ".env",
    ".key",
    ".pem",
    ".p12",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · harden.py (reported line 97)May include surrounding context.

python
"secret-input.js"
  ],
  "sensitive_extensions": [
    ".env",
    ".key",
    ".pem",
    ".p12",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · harden.py (reported line 204)May include surrounding context.

python
"secret-input.js"
  ],
  "sensitive_extensions": [
    ".env",
    ".key",
    ".pem",
    ".p12",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · harden.py (reported line 243)May include surrounding context.

python
"secret-input.js"
  ],
  "sensitive_extensions": [
    ".env",
    ".key",
    ".pem",
    ".p12",

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This section generates a real .env file containing extracted credentials in plaintext. Even though the stated goal is hardening, writing secrets to a plaintext file materially increases the chance of disclosure through local compromise, backups, logs, accidental sharing, or source-control commits.

Content

Scanner excerpt · harden.py (reported line 105)May include surrounding context.

python
print(f"[DRY-RUN] Would create: {env_example}")
            return None
        
        # Generate .env file (actual credentials)
        lines = [
            "# OpenClaw Environment Variables",
            f"# Generated: {datetime.now().isoformat()}",

Static analysis

No suspicious patterns detected.