Back to skill

Security audit

gateway-watchdog

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed hidden Windows watchdog, but it needs review because its admin installer can kill unrelated processes and its background watchdog can run automatic repair commands.

Install only if you intentionally want a persistent hidden Windows watchdog for OpenClaw Gateway on this machine. Before installing, review the scripts, understand that the admin installer changes scheduled tasks, may kill every running `node.exe` and `wscript.exe` process, and that the watchdog can run `openclaw doctor --fix` automatically. Prefer a version that targets only OpenClaw-owned processes and clearly documents disable/uninstall steps.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install_watchdog_admin.bat:27
Finding

Elevated Installer Terminates Unrelated Node.js and Windows Script Host Processes

Content
View full analysis

Vulnerability Details

File Location: scripts/install_watchdog_admin.bat, lines 27–28
Vulnerability Type: Unscoped elevated process termination
Risk Level: Medium

Vulnerable Code

bat
taskkill /f /im wscript.exe >nul 2>&1
taskkill /f /im node.exe >nul 2>&1

Technical Analysis

The documented installation procedure instructs the user to run this batch file as Administrator. The script then uses taskkill /f /im to forcibly terminate every accessible process whose image name is wscript.exe or node.exe.

The operation is not restricted to the OpenClaw Gateway process, its scheduled task, its command line, or a previously recorded process ID. Consequently, authorization to restart the Gateway is expanded into authority to terminate unrelated Node.js and Windows Script Host processes, including processes in other user sessions when permitted by the installer’s elevated token.

This is a reachable coding defect rather than evidence of malicious intent. The scheduled-task changes and hidden launchers are disclosed as part of the Skill’s watchdog functionality.

Attack Path

  1. An administrator follows the documented deployment instructions and runs install_watchdog_admin.bat with elevated privileges.
  2. An unrelated user or application has an active process named node.exe or wscript.exe.
  3. The installer reaches lines 27–28 while restarting the Gateway.
  4. taskkill /f /im matches processes solely by executable image name.
  5. Windows forcibly terminates all matching processes accessible to the elevated installer, not only the OpenClaw Gateway.

No attacker-controlled command injection is required. The affected processes only need to use one of the broadly targeted executable names when the installer runs.

Impact Assessment

The defect can cause cross-user or system-wide denial of service against unrelated Node.js applications and Windows Script Host workloads. It may interrupt development servers, automation, servic ...[truncated 297 chars]

Remediation
View remediation

Remediation Suggestions

  • Stop only the intended scheduled task, for example:
bat
schtasks /End /TN "OpenClaw Gateway"
  • Restart the Gateway through its named scheduled task rather than killing processes by image name.
  • If direct termination is unavoidable, record the Gateway PID when it starts and verify the PID’s executable path and command line before terminating it.
  • Do not use /IM node.exe or /IM wscript.exe from an elevated installer because those executable names are shared by unrelated applications.
  • Handle stop and restart failures explicitly and abort rather than falling back to system-wide process termination.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · scripts/watchdog.ps1 (reported line 264)May include surrounding context.

text
$cycle++

        # --- MAINTENANCE GATE ---
        # If a repair (ours or external) holds a fresh lock, do NOT judge
        # the gateway health or attempt a restart. Just wait.
        if (Test-MaintenanceLock) {
            if ($lastStatus -ne "maintenance") {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README instructs users to run an administrator-level installer and deploy hidden launcher scripts with no visible warning about privilege use, persistence, or the operational impact of a watchdog that can automatically restart software. In a security review context, hidden execution plus elevated installation reduces user awareness and can normalize behaviors commonly associated with stealthy persistence, increasing the chance of unsafe deployment or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script launches gateway.cmd as a hidden subprocess with no user-facing disclosure, which reduces transparency and can conceal persistent background execution from the user. In this skill’s context, the behavior is expected for a watchdog/tray utility, but hiding execution still creates abuse potential by making unauthorized or unexpected process launches harder to notice and investigate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installer forcefully terminates all wscript.exe and node.exe processes system-wide, not just the specific OpenClaw Gateway instance it manages. On a Windows system, those executables are commonly used by unrelated applications and administrative scripts, so this can disrupt other services, cause data loss, or terminate security tooling unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script performs forced process termination without warning the user that unrelated wscript.exe and node.exe workloads may be killed. In an admin-run installer, this creates avoidable operational risk because users are not given a chance to save work, stop dependent services gracefully, or opt out of the disruptive action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script launches gateway.cmd with a fully hidden window using shell.Run(..., 0, True), which suppresses visible indication that a subprocess is being executed. Although comments describe the behavior for a developer, there is no user-facing prompt, log, or visible disclosure warning the user that a hidden command process will run.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a watchdog maintenance lock used to prevent repair operations from racing the watchdog, and the file header frames this script as wrapping a repair command such as doctor --fix. However, the implementation accepts any remaining arguments and executes the first token as an arbitrary executable with arbitrary arguments, which gives the script a general command-launching capability not justified by the stated watchdog purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The watchdog goes beyond passive monitoring and restart behavior by automatically invoking openclaw doctor --fix, which performs repair actions that can change system state. In a long-running hidden background process, this increases risk of unintended modifications, repeated self-healing loops, or execution of a powerful maintenance command without explicit operator approval.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

$SELF_REFRESH_HOURS is set to 24, while the runtime log/comment in the self-refresh block says it is relaunching before a '72h limit'. This is an active contradiction between inline intent/documentation and actual behavior, not just an omitted detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.