openclaw-upgrade

Warn

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill frequently employs sudo in both its documentation and the upgrade.sh script to perform global NPM package installations and modify system-wide directories.
  • [CREDENTIALS_UNSAFE]: The skill intentionally accesses and backs up sensitive directories containing user credentials and session data, specifically ~/.openclaw/credentials and ~/.openclaw/sessions.
  • [COMMAND_EXECUTION]: The skill utilizes several powerful shell commands to manage the environment, including:
  • Forceful process termination via pkill -9 -f openclaw-gateway.
  • Management of systemd services using systemctl to stop, start, and restart the gateway.
  • macOS application lifecycle management using osascript to quit the app and cp -R to overwrite files in the /Applications folder.
  • SSH connections to the host exe.dev as part of the VM upgrade workflow.
  • [EXTERNAL_DOWNLOADS]: The skill triggers external downloads from two primary sources:
  • Cloning the project source code from https://github.com/openclaw/openclaw.git.
  • Fetching and installing updates from the NPM registry via npm i -g openclaw.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection due to its handling of external data:
  • Ingestion points: The upgrade.sh script reads and acts upon outputs from npm view, openclaw doctor, and local configuration files such as ~/.openclaw/config.json.
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands are present when processing tool outputs or configuration data.
  • Capability inventory: The skill possesses high-impact capabilities including sudo execution, directory deletion (rm -rf), and service manipulation.
  • Sanitization: There is no evidence of sanitization or validation of strings returned by external tools or read from local configuration before they are used in script logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — openclaw-upgrade