Back to skill

Security audit

Openclaw Error Fix

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent OpenClaw troubleshooting guide, but it recommends several high-impact commands without enough safeguards for ordinary users.

Review this skill before installing or using it. Prefer safer alternatives: download and verify remote setup scripts before running them, avoid sudo -E unless necessary, back up ~/.openclaw/config.yaml before resetting it, avoid persistent npm registry/proxy changes unless you trust them, and try graceful process termination before kill -9.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:29
Finding

Unverified Remote Script Executed with Root Privileges

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:53
Finding

Unpinned Global Package Installation Through a Third-Party Registry

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (12)

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The chained pattern 'curl ... | sudo -E bash -' combines network retrieval, shell interpretation, and privileged execution in one step, removing opportunities for inspection or validation. This greatly increases the chance of arbitrary code execution if the remote content is tampered with or the source is spoofed.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
brew install node@20

# Ubuntu
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs

# 验证

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The direct 'rm ~/.openclaw/config.yaml' command is destructive and offers no confirmation, backup, or validation. Even though the path is specific, users may lose credentials and custom settings, and copy-paste execution normalizes unsafe deletion practices.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

解决:

bash
# 重置配置
rm ~/.openclaw/config.yaml
openclaw config init

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description says the skill is suitable for "遇到错误的用户" (users who encounter errors), which is a very broad trigger condition with no constraints on product scope, error type, or invocation context. This could overlap with many ordinary troubleshooting situations and cause unintended activation because it does not clearly define when the skill should or should not be used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The line "遇到错误不用慌,这里有你需要的解决方案" implies applicability whenever a user encounters an error, without specifying OpenClaw-only scope or boundaries. Because the activation framing is generic and lacks negative examples, it increases the risk of accidental invocation for unrelated issues.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
98% confidence
Finding

The explicit use of 'sudo -E' preserves user environment variables while running a remote-fetched script as root, which can unintentionally pass sensitive or dangerous environment state into privileged execution. Combined with curl-to-bash, this materially raises the risk of privilege abuse or unintended code execution.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
brew install node@20

# Ubuntu
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs

# 验证

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
98% confidence
Finding

The explicit use of 'sudo -E' preserves user environment variables while running a remote-fetched script as root, which can unintentionally pass sensitive or dangerous environment state into privileged execution. Combined with curl-to-bash, this materially raises the risk of privilege abuse or unintended code execution.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
brew install node@20

# Ubuntu
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs

# 验证

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
# Ubuntu
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs

# 验证
node --version  # 应该显示 v20.x.x

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

解决:

bash
# 不要用 sudo!修复 npm 权限
mkdir ~/.npm-global
npm config set prefix '~/.npm-global'
echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.zshrc
source ~/.zshrc

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

解决:

bash
# 不要用 sudo!修复 npm 权限
mkdir ~/.npm-global
npm config set prefix '~/.npm-global'
echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.zshrc
source ~/.zshrc

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

bash
# 验证 DeepSeek API Key
curl https://api.deepseek.com/v1/models \
  -H "Authorization: Bearer $API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The config reset instructions delete a user configuration file without warning, backup guidance, or validation that the path is correct. This can cause loss of settings, credentials, and service configuration, especially if copied blindly by inexperienced users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Using 'kill -9 ' without warning encourages force-terminating processes and can kill the wrong process or interrupt active work. SIGKILL prevents graceful shutdown and may corrupt state or lose unsaved data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.