openclaw-upgrade
Warn
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill frequently employs
sudoin both its documentation and theupgrade.shscript to perform global NPM package installations and modify system-wide directories. - [CREDENTIALS_UNSAFE]: The skill intentionally accesses and backs up sensitive directories containing user credentials and session data, specifically
~/.openclaw/credentialsand~/.openclaw/sessions. - [COMMAND_EXECUTION]: The skill utilizes several powerful shell commands to manage the environment, including:
- Forceful process termination via
pkill -9 -f openclaw-gateway. - Management of systemd services using
systemctlto stop, start, and restart the gateway. - macOS application lifecycle management using
osascriptto quit the app andcp -Rto overwrite files in the/Applicationsfolder. - SSH connections to the host
exe.devas part of the VM upgrade workflow. - [EXTERNAL_DOWNLOADS]: The skill triggers external downloads from two primary sources:
- Cloning the project source code from
https://github.com/openclaw/openclaw.git. - Fetching and installing updates from the NPM registry via
npm i -g openclaw. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection due to its handling of external data:
- Ingestion points: The
upgrade.shscript reads and acts upon outputs fromnpm view,openclaw doctor, and local configuration files such as~/.openclaw/config.json. - Boundary markers: No specific boundary markers or instructions to ignore embedded commands are present when processing tool outputs or configuration data.
- Capability inventory: The skill possesses high-impact capabilities including
sudoexecution, directory deletion (rm -rf), and service manipulation. - Sanitization: There is no evidence of sanitization or validation of strings returned by external tools or read from local configuration before they are used in script logic.
Audit Metadata