Back to skill

Security audit

Upgrade Guard

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent OpenClaw upgrade helper, but it uses high-impact upgrade commands with some under-scoped safety controls.

Review before installing if this would run on a machine with production OpenClaw config or credentials. Prefer pinning an exact OpenClaw version, confirming package provenance, adding owner-only permissions for backups, and replacing the rm -rf pruning pipeline with safer path-validated cleanup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:67
Finding

Unpinned Global Package Installation from a Mutable Release Tag

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:49
Finding

Sensitive Configuration Backups Are Created Without Explicit Permission Hardening

Content
View full analysis
/dev/null | tr ' ' '_') mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" cp ~/.openclaw/openclaw.json "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}/" ln -sfn "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" "$HOME/.openclaw/upgrade-guard/latest" ``` Equivalent backup instructions are repeated at `SKILL.md:154-160` and `references/zh.md:37-44`. ### Technical Analysis The workflow copies `~/.openclaw/openclaw.json` into a persistent backup hierarchy without first setting a restrictive `umask` and without explicitly enforcing directory and file permissions. OpenClaw configuration may contain authentication material, provider credentials, gateway settings, or other sensitive operational data. The effective permissions depend on the existing source permissions, current process umask, and preexisting destination directories. If those settings are permissive, another local account or process may be able to read the backup. Retaining up to ten copies also extends the period during which old or revoked credentials may remain recoverable. This is a local confidentiality weakness rather than evidence that the Skill intentionally transmits data. Exploitation requires local access capable of reading the resulting backup path. ### Attack Path 1. A user has permissive configuration permissions, a permissive umask, or a preexisting backup directory with insufficient access controls. 2. The user follows the documented backup workflow. 3. `openclaw.json` is copied into `~/.openclaw/upgrade-guard/` without explicit permission validation or hardening. 4. Another local user or process enumerates the readable backup directory. 5. The attacker reads one or more retained configuration backups. ...[truncated 603 chars]
Remediation
View remediation
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Chaining Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The cleanup command chains directory changes, globbing, sorting, and xargs rm -rf into a destructive pipeline without robust safeguards. If backup names are malformed, contain unexpected characters, or if the command runs in an unintended directory/state, it can delete unintended paths; the use of a symlinked 'latest' pointer in the same area increases the need for careful path handling.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Keep max 10 backups:

bash
# Prune old backups (keep newest 10)
cd ~/.openclaw/upgrade-guard && ls -1d pre-* 2>/dev/null | sort | head -n -10 | xargs rm -rf 2>/dev/null; cd -

Upgrade: Cautious Mode

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
## Upgrade: Manual Mode

Just backup and pre-check. Print instructions, user handles the rest.

## Rollback

Chaining Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The cleanup pipeline cd ~/.openclaw/upgrade-guard && ls -1d pre-* 2>/dev/null | sort | head -n -10 | xargs rm -rf is dangerous because it uses shell expansion and xargs rm -rf on filenames without robust delimiter handling or -- protection. If a crafted directory name contains whitespace, newlines, or begins with -, the command can misparse inputs and delete unintended paths; the risk is elevated because it performs recursive forced deletion.

Content

Scanner excerpt · references/zh.md (reported line 46)May include surrounding context.

保留最近 10 个,自动清理旧的:

bash
cd ~/.openclaw/upgrade-guard && ls -1d pre-* 2>/dev/null | sort | head -n -10 | xargs rm -rf 2>/dev/null

Cautious 模式(推荐)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says the skill triggers on phrases like "gateway won't start", "config broke", and "config migration" without constraining them to OpenClaw upgrade scenarios. These phrases are broad enough to collide with ordinary support requests, which could cause unintended invocation of this upgrade skill.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Always backup config before upgrading:

bash
# Create timestamped backup
mkdir -p ~/.openclaw/upgrade-guard
ts=$(date +%Y%m%d-%H%M%S)
ver=$(openclaw --version 2>/dev/null | tr ' ' '_')

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

升级前必须备份配置文件:

bash
mkdir -p ~/.openclaw/upgrade-guard
ts=$(date +%Y%m%d-%H%M%S)
ver=$(openclaw --version 2>/dev/null | tr ' ' '_')
mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/zh.md (reported line 34)May include surrounding context.

升级前必须备份配置文件:

bash
mkdir -p ~/.openclaw/upgrade-guard
ts=$(date +%Y%m%d-%H%M%S)
ver=$(openclaw --version 2>/dev/null | tr ' ' '_')
mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

mkdir -p ~/.openclaw/upgrade-guard ts=$(date +%Y%m%d-%H%M%S) ver=$(openclaw --version 2>/dev/null | tr ' ' '_') mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" cp ~/.openclaw/openclaw.json "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}/" ln -sfn "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" "$HOME/.openclaw/upgrade-guard/latest"

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

mkdir -p ~/.openclaw/upgrade-guard ts=$(date +%Y%m%d-%H%M%S) ver=$(openclaw --version 2>/dev/null | tr ' ' '_') mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" cp ~/.openclaw/openclaw.json "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}/" ln -sfn "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" "$HOME/.openclaw/upgrade-guard/latest"

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/zh.md (reported line 37)May include surrounding context.

mkdir -p ~/.openclaw/upgrade-guard ts=$(date +%Y%m%d-%H%M%S) ver=$(openclaw --version 2>/dev/null | tr ' ' '_') mkdir -p "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" cp ~/.openclaw/openclaw.json "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}/" ln -sfn "$HOME/.openclaw/upgrade-guard/pre-${ts}-${ver}" "$HOME/.openclaw/upgrade-guard/latest"

text

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

该 markdown 文件以“中文说明”明确限定内容语言,且全文仅提供中文说明,没有提供用户可选择其他语言的选项,也没有解释这是区域或合规要求导致的限制。按规则,强制特定语言而无用户选择属于自然语言层面的语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.