Back to skill

Security audit

quark-backup

Security checks for vulnerabilities and agentic risk

Overview

This backup skill is coherent, but it handles broad private OpenClaw data and a full Quark session cookie with weak scoping and unsafe setup details.

Review carefully before installing. Use only if you are comfortable uploading the full OpenClaw state to Quark Drive, and avoid enabling cron until the kuake binary source is pinned and verified, the cookie is stored with strict permissions or a secret manager, and the backup archive is narrowed or encrypted.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup-openclaw.sh:9
Finding

Unencrypted Sensitive Backup Written to a Predictable Temporary Path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup-openclaw.sh:24
Finding

Credential Configuration File Is Executed as Shell Code

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/kuake-setup.md:5
Finding

Unpinned and Unverifiable External Upload Component

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
78% confidence
Finding

The skill instructs users to extract a full Quark session cookie from the browser and place it into a local environment file for automated use. Even though the archive exclusion mentions tools/kuake/.env, the skill still normalizes storing long-lived authentication material in plaintext on disk and using it for unattended cloud access, which creates credential theft and account compromise risk if the host, logs, backups, or file permissions are weak.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

├── bin/kuake # kuake CLI 二进制 ├── use-kuake.sh # 包装脚本(设置 Cookie 环境变量) ├── backup-openclaw-full.sh # 主备份脚本 └── .env # 不存在则跳过(Cookie 由上一步提供)

text

### 打包排除项

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/backup-openclaw.sh (reported line 51)May include surrounding context.

sh
--exclude='.openclaw/agents/*/workspace/.openclaw/cdp-profile' \
  --exclude='.openclaw/agents/*/workspace/.openclaw/cdp-profile/*' \
  --exclude='.openclaw/agents/*/workspace/.openclaw/cdp-profile-*' \
  --exclude='workspace/tools/kuake/.env' \
  -czf "$ARCHIVE" \
  -C "$(dirname "$OPENCLAW_HOME")" "$(basename "$OPENCLAW_HOME")"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly automates packaging and remote upload of the entire .openclaw directory, including workspace, memory, sessions, and configuration, but does not present a clear user-facing warning about the privacy and security consequences of exporting this data to a third-party cloud service. Because these paths can contain conversation history, session artifacts, tokens, and other sensitive material, users may trigger or schedule exfiltration-like behavior without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script conditionally sources a local secret file and exports its contents into the environment, which is access to sensitive credentials. Although the variable check on L28 enforces presence of the cookie, there is no user-facing warning at the point of credential loading beyond Chinese error text for missing configuration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The activation description enumerates only Chinese trigger phrases such as "备份" and "上传夸克". This creates a language-specific activation policy without stating that the skill is China-region-specific or offering alternative language handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script emits operational and error messages in Chinese, and the same pattern continues throughout the file. This enforces a specific language for user interaction without opt-in or an explicit justification that the skill is intended only for a Chinese-speaking environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.