Back to skill

Security audit

OpenClaw Backup

Security checks for vulnerabilities and agentic risk

Overview

This backup skill is mostly aligned with disaster recovery, but it needs review because it can move broad local data to GitHub, handle credentials, create scheduled jobs, delete backups, and run code from restored archives.

Install only if you are comfortable with a shell-based backup tool that can read most of your OpenClaw workspace, optionally handle credentials, create recurring OpenClaw cron jobs, delete old backup sets, replace ~/.openclaw during restore, and upload archives to GitHub. Before using it, review archive contents, avoid pushing secrets unless you explicitly intend to, treat operational archives as potentially private rather than automatically cloud-safe, and restore only from backup sets you trust.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/push-to-github.sh:90
Finding

Encrypted Credential Archives Are Uploaded Without Explicit Per-Upload Consent

Content
View full analysis
/dev/null git push origin HEAD >/dev/null info "Pushed backup to $REMOTE" fi ) ``` ### Technical Analysis When `--secrets` is omitted, the script reads the manifest, locates the associated encrypted secrets archive, and assigns it to `SECRETS_PATH` automatically. It then copies that archive into the repository and pushes it to GitHub. This exceeds the minimum privilege and data-transfer scope required to push an operational archive. It also conflicts with the documented model that secrets archives are intended for local recovery by default and shoul ...[truncated 1643 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/backup.sh:204
Finding

Plaintext Secrets Archive Persists When Encryption Fails

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/restore.sh:184
Finding

Restore of an Untrusted Backup Executes Code Supplied by the Archive

Content
View full analysis
/dev/null 2>&1 || die "age is required for secrets restore. Install with: brew install age (macOS) or apt install age (Linux)" [ -f "$SECRETS_PATH" ] || die "Secrets archive not found: $SECRETS_PATH" DECRYPTED_SECRETS="$TMP_DIR/secrets.tar.gz" if [ -n "$AGE_IDENTITY_FILE" ]; then age --decrypt -i "$AGE_IDENTITY_FILE" -o "$DECRYPTED_SECRETS" "$SECRETS_PATH" elif [ -n "$AGE_PASSPHRASE_FILE" ]; then AGE_PASSPHRASE="$(cat "$AGE_PASSPHRASE_FILE")" age --decrypt -o "$DECRYPTED_SECRETS" "$SECRETS_PATH" <<< "$AGE_PASSPHRASE" else die "Secrets archive provided, but no decryption material was supplied. Use --age-identity or --age-passphrase-file." fi mkdir -p "$TMP_DIR/secrets" tar -xzf "$DECRYPTED_SECRETS" -C "$TMP_DIR/secrets" [ -d "$TMP_DIR/secrets/openclaw" ] || die "Secrets archive does not contain top-level openclaw/ directory" cp -R "$TMP_DIR/secrets/openclaw/." "$STAGING_DIR/" fi ``` ```bash HEALTHCHECK_SCRIPT="$OPENCLAW_DIR/workspace/scripts/pre-restart-check.sh" if [ -f "$HEALTHCHECK_SCRIPT" ]; then if ! bash "$HEALTHCHECK_SCRIPT"; then rollback die "Health check failed after restore; rolled back." fi else info "Health check script not found; skipped: $HEALTHCHECK_SCRIPT" fi ``` The corresponding verification trusts a checksum stored in the supplied manifest: ```python manifest = json.loads(Path(manifest_ ...[truncated 2954 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backup.sh:181
Finding

Operational Archive Marked Cloud-Safe Recursively Includes Unreviewed Workspace Data

Content
View full analysis
/dev/null git push origin HEAD >/dev/null info "Pushed backup to $REMOTE" fi ) ``` ### Technical Analysis The operational backup recursively copies the entire workspace without content filtering. Only `openclaw.json` is passed through the key-name-based redaction function. Files elsewhere in the workspace are copied verbatim. The documented workspace scope includes memory, prompts, notes, local scripts, custom skills, active artifacts, nested repositories, and daily logs. Any of those locations may also contain API tokens, private keys, `.env` files, cookies, credentials, sensitive conversations, proprietary source code, or personal information. Calling the resulting archive “cloud-safe” creates an unsafe trust assumption. The GitHub push script does not inspect or scan the operat ...[truncated 1180 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description focuses on backup and restore, but the skill also indicates scheduling and drill workflows that may create, modify, or delete persistent cron jobs through OpenClaw tooling. This mismatch can hide persistence-establishing behavior from users and policy systems, increasing the chance that a caller authorizes backup actions without realizing the skill can also alter recurring job state.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/backup.sh (reported line 193)May include surrounding context.

sh
copy_file "$OPENCLAW_DIR/cron/jobs.json" "$OP_STAGE/openclaw/cron/jobs.json" "cron/jobs.json"

if [ "$INCLUDE_SECRETS" -eq 1 ]; then
  copy_file "$OPENCLAW_DIR/.env" "$SEC_STAGE/openclaw/.env" ".env"
  copy_dir "$OPENCLAW_DIR/agents" "$SEC_STAGE/openclaw/agents" "agents/"
fi

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/backup.sh (reported line 205)May include surrounding context.

sh
copy_file "$OPENCLAW_DIR/cron/jobs.json" "$OP_STAGE/openclaw/cron/jobs.json" "cron/jobs.json"

if [ "$INCLUDE_SECRETS" -eq 1 ]; then
  copy_file "$OPENCLAW_DIR/.env" "$SEC_STAGE/openclaw/.env" ".env"
  copy_dir "$OPENCLAW_DIR/agents" "$SEC_STAGE/openclaw/agents" "agents/"
fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/pre-change-snapshot.sh (reported line 19)May include surrounding context.

sh
TMP_OUTPUT="$(mktemp "${TMPDIR:-/tmp}/openclaw-snapshot.XXXXXX")"
STAGE_ROOT="$(mktemp -d "${TMPDIR:-/tmp}/openclaw-snapshot-stage.XXXXXX")"
trap 'rm -f "$TMP_OUTPUT"; rm -rf "$STAGE_ROOT"' EXIT

bash "$BACKUP_SCRIPT" --no-secrets --output-dir "$STAGE_ROOT" >"$TMP_OUTPUT"

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/pre-change-snapshot.sh (reported line 19)May include surrounding context.

sh
TMP_OUTPUT="$(mktemp "${TMPDIR:-/tmp}/openclaw-snapshot.XXXXXX")"
STAGE_ROOT="$(mktemp -d "${TMPDIR:-/tmp}/openclaw-snapshot-stage.XXXXXX")"
trap 'rm -f "$TMP_OUTPUT"; rm -rf "$STAGE_ROOT"' EXIT

bash "$BACKUP_SCRIPT" --no-secrets --output-dir "$STAGE_ROOT" >"$TMP_OUTPUT"

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The restore flow executes a script taken directly from the restored backup at "$OPENCLAW_DIR/workspace/scripts/pre-restart-check.sh" after the archive has been unpacked and moved into place. An attacker who can influence the backup contents can place arbitrary shell commands in that path, causing code execution during restore with the privileges of the operator, which is especially dangerous because restore is a trusted administrative action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file documents a workflow to push the operational archive to GitHub, which is a network transmission of backup data to a third-party service. Although it notes the archive is 'cloud-safe,' it does not explicitly warn users that backup contents will leave the local system and be stored remotely, which is a relevant user-facing disclosure for privacy and system-data handling.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes shell scripts for backup, verification, restore, and GitHub push, but it declares no explicit tool scope or permissions. That makes the skill's operational authority ambiguous and can lead to over-broad execution in environments that rely on metadata to constrain file and shell access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically prunes older snapshot directories by recursively deleting every matching run directory beyond the five newest, without any notice, confirmation, or dry-run mode. In a backup/restore skill, silent retention cleanup is security-relevant because it can destroy recovery points unexpectedly, weakening resilience and incident response if a needed historical snapshot is removed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This script copies backup archives into a local clone and pushes them to GitHub, but it does not present a clear interactive warning or confirmation immediately before transmitting the data. In a backup skill, users may assume the tool is only handling local files; pushing operational backups and manifests to a remote service can expose sensitive configuration or metadata if the user misunderstands what is being uploaded or the repository visibility changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This shell script creates a cron job that will later execute backup.sh, and the system-event text also references backing up encrypted secrets. Although the script logs cron creation and replacement, it does not disclose to the user in this file that scheduling the job will cause recurring backup execution or that secrets backup may occur if explicitly requested.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This script is presented as a weekly verification workflow, but it also performs retention pruning and orphan cleanup, including recursive deletion of backup run directories. Combining verification with destructive maintenance increases the chance of accidental data loss because a user or scheduler may invoke it expecting a read-only integrity check. In a backup/disaster-recovery context, silent deletion is especially risky because backups are the last recovery path.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script deletes whole backup directories with rm -rf and removes secret archives and manifests during a workflow named weekly-verify. That makes the operation non-obvious and potentially destructive when run from automation, especially if backup metadata is malformed or incomplete, causing files needed for recovery to be removed. For backup tooling, destructive behavior inside verification materially increases operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prune loop removes directories listed in PRUNE_LIST using rm -rf with no confirmation, preview, or prominent warning in output. Because this is backup retention logic, mistakes in timestamp parsing, metadata generation, or path selection could irreversibly destroy recoverable backups without operator awareness. Lack of disclosure is particularly dangerous in unattended cron-style execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script silently deletes manifests lacking archives and deletes secret archive files whenever a manifest is absent. If a transient failure, partial copy, race, or manual recovery workflow temporarily creates this state, the cleanup can remove evidence and recovery material that operators may still need. In backup software, automatically deleting 'orphans' without notice can worsen recovery failures and hide underlying integrity problems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.