T08 · Insecure Dependencies
- Location
SKILL.md:67- Finding
Unpinned Global Package Installation from a Mutable Release Tag
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent OpenClaw upgrade helper, but it uses high-impact upgrade commands with some under-scoped safety controls.
Review before installing if this would run on a machine with production OpenClaw config or credentials. Prefer pinning an exact OpenClaw version, confirming package provenance, adding owner-only permissions for backups, and replacing the rm -rf pruning pipeline with safer path-validated cleanup.
SKILL.md:67Unpinned Global Package Installation from a Mutable Release Tag
SKILL.md:49Sensitive Configuration Backups Are Created Without Explicit Permission Hardening
The cleanup command chains directory changes, globbing, sorting, and xargs rm -rf into a destructive pipeline without robust safeguards. If backup names are malformed, contain unexpected characters, or if the command runs in an unintended directory/state, it can delete unintended paths; the use of a symlinked 'latest' pointer in the same area increases the need for careful path handling.
Keep max 10 backups:
# Prune old backups (keep newest 10)
cd ~/.openclaw/upgrade-guard && ls -1d pre-* 2>/dev/null | sort | head -n -10 | xargs rm -rf 2>/dev/null; cd -
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
## Upgrade: Manual Mode
Just backup and pre-check. Print instructions, user handles the rest.
## Rollback
The cleanup pipeline cd ~/.openclaw/upgrade-guard && ls -1d pre-* 2>/dev/null | sort | head -n -10 | xargs rm -rf is dangerous because it uses shell expansion and xargs rm -rf on filenames without robust delimiter handling or -- protection. If a crafted directory name contains whitespace, newlines, or begins with -, the command can misparse inputs and delete unintended paths; the risk is elevated because it performs recursive forced deletion.
保留最近 10 个,自动清理旧的:
cd ~/.openclaw/upgrade-guard && ls -1d pre-* 2>/dev/null | sort | head -n -10 | xargs rm -rf 2>/dev/null
The manifest says the skill triggers on phrases like "gateway won't start", "config broke", and "config migration" without constraining them to OpenClaw upgrade scenarios. These phrases are broad enough to collide with ordinary support requests, which could cause unintended invocation of this upgrade skill.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Always backup config before upgrading:
# Create timestamped backup
mkdir -p ~/.openclaw/upgrade-guard
ts=$(date +%Y%m%d-%H%M%S)
ver=$(openclaw --version 2>/dev/null | tr ' ' '_')
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
升级前必须备份配置文件:
mkdir -p ~/.openclaw/upgrade-guard
ts=$(date +%Y%m%d-%H%M%S)
ver=$(openclaw --version 2>/dev/null | tr ' ' '_')
mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
升级前必须备份配置文件:
mkdir -p ~/.openclaw/upgrade-guard
ts=$(date +%Y%m%d-%H%M%S)
ver=$(openclaw --version 2>/dev/null | tr ' ' '_')
mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.openclaw/upgrade-guard ts=$(date +%Y%m%d-%H%M%S) ver=$(openclaw --version 2>/dev/null | tr ' ' '_') mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" cp ~/.openclaw/openclaw.json "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}/" ln -sfn "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" "$HOME/.openclaw/upgrade-guard/latest"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.openclaw/upgrade-guard ts=$(date +%Y%m%d-%H%M%S) ver=$(openclaw --version 2>/dev/null | tr ' ' '_') mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" cp ~/.openclaw/openclaw.json "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}/" ln -sfn "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" "$HOME/.openclaw/upgrade-guard/latest"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.openclaw/upgrade-guard ts=$(date +%Y%m%d-%H%M%S) ver=$(openclaw --version 2>/dev/null | tr ' ' '_') mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" cp ~/.openclaw/openclaw.json "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}/" ln -sfn "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" "$HOME/.openclaw/upgrade-guard/latest"
该 markdown 文件以“中文说明”明确限定内容语言,且全文仅提供中文说明,没有提供用户可选择其他语言的选项,也没有解释这是区域或合规要求导致的限制。按规则,强制特定语言而无用户选择属于自然语言层面的语言/locale 策略问题。
No suspicious patterns detected.