Install-Then-Update Trap Detector for Openclaw

Detects malicious updates in AI agent skills that pass initial security audits but introduce backdoors through subsequent automatic updates.

andyxinweiminicloud
v1.1.0
Feb 25, 2026
0
1.3k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install install-then-update-trap-detector

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install install-then-update-trap-detector using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Install-Then-Update Trap Detector?

This skill addresses the critical security gap known as the install-then-update attack pattern. In many agent marketplaces, initial skill publications undergo rigorous scrutiny, but subsequent updates often bypass re-audit. This allows a skill to appear safe at version 1.0 while silently introducing malicious behavior, such as credential harvesting or network exfiltration, in later versions. By monitoring the evolution of a skill, this tool ensures continuous security beyond the initial installation phase.

Built for developers and security-conscious users of Openclaw Skills, this detector analyzes the risk surface across multiple dimensions, including behavioral changes, permission creep, and cryptographic chain-of-custody. It provides a structured risk verdict, helping operators decide whether to trust, monitor, or block specific updates based on empirical evidence rather than just the publisher's changelog.

Install-Then-Update Trap Detector Use Cases

  • Identifying undeclared behavioral changes after a skill update
  • Auditing an agent's list of installed skills for combined update-window risk
  • Detecting permission scope expansion that occurs across version boundaries
  • Verifying the cryptographic chain-of-custody for skill update sequences
  • Flagging suspicious update timing patterns that coincide with low-attention windows

How Install-Then-Update Trap Detector Works

  1. The user provides a skill identifier, specific versions to compare, or a list of installed skills from the agent environment.
  2. The tool fetches historical data and metadata for the specified versions from the registry.
  3. It performs a behavioral delta assessment, comparing declared changelogs against observed execution patterns.
  4. It evaluates the update policy transparency and checks for permission scope creep (e.g., new file or network access).
  5. It verifies the cryptographic signatures and hash chains to ensure the integrity of the update sequence.
  6. A comprehensive trap detection report is generated, providing a risk verdict (SAFE, MONITOR, ELEVATED, or TRAP-PATTERN-DETECTED) and recommended remediation steps.

Install-Then-Update Trap Detector Setup

To use this tool within your environment, ensure you have the necessary dependencies installed. This skill requires curl and python3 for execution.

# Verify dependencies
curl --version
python3 --version

# The skill can be invoked via the Openclaw CLI to assess a specific version transition
# Example: compare v1.0 to v1.2 of a target skill

Install-Then-Update Trap Detector Data Schema & Taxonomy

The detector organizes its findings into a structured report using the following taxonomy:

Attribute Description
Update Transparency Evaluation of whether update policies are clearly declared and maintained.
Behavioral Delta Comparison of observed code behavior vs. the published changelog.
Permission Scope Tracking of resource access changes across different versions.
Timing Anomalies Flags for updates published during off-hours or holiday periods.
Chain-of-Custody Cryptographic verification of hash-chained update sequences (v1.1+).
Risk Verdict Final assessment: SAFE, MONITOR, ELEVATED, or TRAP-PATTERN-DETECTED.

Install-Then-Update Trap Detector Advanced Features

  • Cryptographic chain-of-custody verification to prevent unauthorized version injections
  • Automated risk scoring based on historical behavioral deltas
  • Multi-version regression analysis to identify long-term permission creep
  • Integration with Openclaw Skills transparency logs for independent audit verification
  • Actionable remediation advice including rollback feasibility ratings and update policy enforcement

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*