Back to skill

Security audit

Auto Updater.Local

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly says it will run daily auto-updates, but it creates persistent unattended authority to modify Clawdbot and every installed skill without per-update review.

Install only if you are comfortable allowing Clawdbot to modify itself and every installed skill automatically on a schedule. Prefer a check-only or dry-run schedule, pinned or allowlisted updates, and manual approval for core or skill changes; confirm you know how to remove the cron job before enabling it.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:32
Finding

Persistent Daily Auto-Update Task

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:53
Finding

Unpinned Unattended Installation of Remote Updates

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/agent-guide.md:52
Finding

Suppressed Update and Migration Failures

Content
View full analysis
&1 | tee -a "$LOG_FILE" || true # Capture new version CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown") # Update skills log "Updating skills via ClawdHub..." SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true ``` ### Technical Analysis Both the migration command and the skill update command append `|| true`, forcing their shell status to success even when the underlying operation fails. The script consequently proceeds to log completion and generate a summary without retaining a dependable overall failure status. This can conceal failed migrations, partial updates, registry failures, or inconsistent state. Capturing standard error in a variable or log does not replace explicit status handling, particularly when an automated agent is expected to determine whether the operation succeeded. ### Attack Path 1. A core migration or skill update fails because of a network error, permission problem, malformed package, or hostile upstream behavior. 2. `|| true` replaces the nonzero exit status with success. 3. The script continues rather than entering a failure or rollback path. 4. The routine emits its normal completion markers and summary data. 5. Monitoring or the agent may interpret the run as complete while the installation remains partially updated or inconsistent. 6. A later run may execute against that inconsistent state, increasing operational and security risk. ### Impact Assessment This issue does not directly grant new privileges. Its primary impact is loss of integrity and observability. Failed migrations may leave the core runtime and configuration at incompatible versions. Partial skill updates may leave executable components inconsistent, while suppressed status ...[truncated 105 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Self-Modification

High
Category
Rogue Agent
Confidence
97% confidence
Finding

The skill explicitly performs self-modification by running clawdhub update --all, which updates all installed skills automatically. In this context, that is dangerous because the agent's capabilities and code can change without human review, expanding the blast radius of any compromised repository, malicious skill update, or accidental breaking release.

Content

Scanner excerpt · references/agent-guide.md (reported line 61)May include surrounding context.

md
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")

# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill schedules unattended updates that will modify the Clawdbot installation and all installed skills, but the description does not prominently warn users that software changes will occur automatically on a recurring basis. This is dangerous because users may enable the skill without understanding that it grants a persistent mechanism for automatic code changes, increasing supply-chain and operational risk if an update is malicious, incompatible, or disruptive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs users to enable unattended updates that modify the bot and its installed skills on a schedule, but it does not require explicit trust controls, pinning, staging, approval, or rollback safeguards. This creates a real supply-chain and operational risk because remote package or skill changes can be pulled and applied automatically, potentially introducing malicious code or breaking behavior without user review.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/agent-guide.md (reported line 21)May include surrounding context.

bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"

text

## Step 2: Create the Update Script (Optional)

For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup confirmation example states that daily updates will run at 4:00 AM in America/Los_Angeles. This prescribes a specific locale/time zone in user-facing language without offering a choice or explaining why that locale is required, which conflicts with the policy against forcing a locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.