Back to skill

Security audit

Openclaw Deploy

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with OpenClaw deployment, but it can package private configuration and tokens and run an unverified remote installer, so it needs careful review before use.

Install only if you are comfortable auditing shell scripts first. Prefer the clean package for sharing or deployment, avoid distributing the full package unless you intentionally want to move secrets and conversation history, and protect any full archive as sensitive data. Do not run install-node.sh as root, and replace the curl-to-bash installer with a verified Node.js installation method where possible. Set OUTPUT_DIR carefully because the build script deletes it recursively.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
templates/install-node.sh:14
Finding

Unverified Remote Installer Is Piped Directly into Bash

Content
View full analysis
/dev/null 2>&1; then echo "📦 安装 NVM..." curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.0/install.sh | bash export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" fi ``` The installer is propagated into generated deployment packages by `scripts/build-portable.sh`, line 107: ```bash cp "$TEMPLATE_DIR/install-node.sh" "$OUTPUT_DIR/" 2>/dev/null || echo " ⚠️ install-node.sh 模板不存在" ``` ### Technical Analysis The script downloads content from an external URL and immediately pipes it into Bash. Although the URL refers to the recognized `nvm-sh/nvm` GitHub repository and specifies the `v0.40.0` tag, the retrieved bytes are not authenticated through a checksum or cryptographic signature. The effective code executed by the Skill is therefore not fully contained in the audited package. Compromise of the upstream repository, release reference, hosting infrastructure, TLS trust environment, or network path could cause different code to execute after the Skill has already been reviewed. The script also omits defensive download options such as `--fail`, so it does not explicitly require a successful HTTP status before passing the response body to Bash. The documented deployment workflow directs users to run this installer, making the vulnerable operation part of the expected usage path. Direct remote execution is not required for the declared portable deployment functionality. Node.js can be installed through a trusted system package manager, or an installer can be downloaded and verified before execution. ### Attack Path 1. A user builds or receives an OpenClaw portable deployment package. 2. The package includes the copied `install-node.sh` template. 3. The user follows the deployment instructions and ru ...[truncated 911 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/build-portable.sh:93
Finding

Full Portable Package Exports Tokens and Private Configuration Without Protection

Content
View full analysis
/dev/null || true echo " ✅ 复制完整配置" else echo " ⚠️ 配置目录不存在,跳过" fi ``` Plaintext archive creation in `scripts/export-portable.sh`: ```bash if [ -d "$PORTABLE_DIR/full" ]; then tar -czf "$OUTPUT_DIR/openclaw-full-portable.tar.gz" -C "$PORTABLE_DIR" full/ echo "✅ Full: openclaw-full-portable.tar.gz ($(du -h $OUTPUT_DIR/openclaw-full-portable.tar.gz | cut -f1))" else echo "⚠️ Full version not found, skipping" fi ``` The project documentation explicitly states that the full version contains current configuration, conversation records, Feishu settings, and gateway tokens. ### Technical Analysis The full-package workflow recursively copies the contents matched by `"$OPENCLAW_CONFIG_DIR"/*` into the portable output. It does not apply an allowlist, redact credential fields, identify sensitive files, or obtain separate confirmation before collecting the configuration. The resulting directory is compressed into an ordinary `.tar.gz` archive. Compression provides no confidentiality. The scripts do not establish a restrictive `umask`, explicitly set archive permissions, encrypt the archive, or verify that the destination is private. Backup and migration are declared features, so copying configuration is intentional. However, including authentication tokens and private history by default exceeds the minimum data needed to package the application itself and creates a credential-disclosure risk. The `2>/dev/null || true` construct also suppresses copy failures. This can leave an incomplete pack ...[truncated 1464 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/build-portable.sh:60
Finding

Unrestricted Configurable Output Path Is Recursively Deleted

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (17)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Using curl ... | bash removes any opportunity to validate the downloaded content before execution and is a classic unsafe command-chaining pattern. In this skill context, the script is specifically intended to be run by users on their machines, so successful exploitation would directly yield arbitrary shell command execution in the user's environment.

Content

Scanner excerpt · templates/install-node.sh (reported line 17)May include surrounding context.

sh
# 安装 NVM
if ! command -v nvm >/dev/null 2>&1; then
    echo "📦 安装 NVM..."
    curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.0/install.sh | bash
    export NVM_DIR="$HOME/.nvm"
    [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh"
fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The export and remote transfer instructions encourage packaging and copying deployment artifacts to another server without warning that the exported bundle may include the 'full' image and therefore embedded tokens, configuration, and historical conversations. This increases the chance of accidental exfiltration during export, SCP transfer, storage on intermediate systems, or deployment to less-trusted hosts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly recommends a 'full' image that contains DreamMoon configuration, Feishu settings, gateway tokens, and conversation history, but does not warn that these are sensitive secrets and private data. In a deployment/backup context, this can lead operators to distribute or run an image with embedded credentials and user data, enabling credential compromise, unauthorized service access, and privacy leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file documents safety-relevant behavior including deploying to remote servers and backing up/restoring configurations, which can modify remote systems or affect user data. There is no accompanying warning about these effects, prerequisites, or the need to verify target paths and data handling before use.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
## Features

- 🐳 Build Docker images (clean/full versions)
- 📦 Create portable packages for deployment
- 🚀 Deploy to remote servers with one command
- 💾 Backup and restore configurations

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script copies the entire user's OpenClaw configuration directory into the generated portable package with no filtering, sanitization, or explicit warning. Configuration directories commonly contain tokens, API keys, server endpoints, chat history, or other private data, so packaging and sharing the output can unintentionally exfiltrate sensitive information.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

At L43 the comment says 'Create deployment script', implying the following block will generate a usable deploy.sh file. However, the redirection at L44 targets README.md for the here-document content, and the body from L45 onward is clearly Markdown documentation rather than a shell script. This is an active mismatch between the inline intent and the implemented behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script automatically deletes any existing container with the target name via docker stop and docker rm. Although it prints a status message, it does not warn the user in advance or request confirmation before carrying out an irreversible container removal.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly instructs users to execute local shell scripts for environment checking, Node.js installation, and service startup without explaining what those scripts do or warning that they may modify the host system. In a software distribution context, encouraging blind execution of scripts increases supply-chain and social-engineering risk, especially when one script installs software and others start services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script uses Chinese-only user-facing strings such as the title, status messages, and completion notice. For a general install script, forcing a specific language without user opt-in can violate language/locale policy because users are not given an alternative or explanation for the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Comments and error messages in this script are written in Chinese, including the only actionable installation guidance shown to users on failure. This imposes a specific language on all users without opt-in or justification, which is a natural-language locale policy concern under the stated rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code creates output files and overwrites generated artifacts such as tarballs and README/deploy files in the export directory. While the script prints progress messages, it does not explicitly warn the user that existing files in the target export path may be replaced, which is a safety-relevant file write operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The natural-language content of the skill documentation is exclusively Chinese, which may impose a language constraint on users without any opt-in or justification. Under the policy rule, forcing a specific language without user choice can be a locale-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This shell script uses Chinese-only natural-language strings for comments and user-facing output throughout the file. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which it is not here.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The script downloads an external installer from the internet and immediately executes it, creating a supply-chain risk. If the remote content, hosting account, network path, or TLS trust chain is compromised, arbitrary code will run with the user's privileges during installation.

Content

Scanner excerpt · templates/install-node.sh (reported line 17)May include surrounding context.

sh
# 安装 NVM
if ! command -v nvm >/dev/null 2>&1; then
    echo "📦 安装 NVM..."
    curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.0/install.sh | bash
    export NVM_DIR="$HOME/.nvm"
    [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh"
fi

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This shell script ultimately executes a Node.js application via exec, replacing the current process. While the script prints startup status, it does not disclose what gateway start will do or warn the user about the launched operation's behavior, and there is no inline comment or prompt near the execution point explaining potential effects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.