跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

Persistence (AML.TA0006)

OpenClaw persistence threats (AML.TA0006): T-PERSIST-001, T-PERSIST-002, T-PERSIST-003

Threats in the persistence tactic (AML.TA0006) of the MITRE ATLAS framework. Each entry lists the ATLAS technique, attack vector, affected components, current mitigations, residual risk, and recommendations.

The trust boundaries and data flows these threats cross are defined in the threat model index, which also holds the risk matrix, the recommendations summary, and the ATLAS technique mapping.

T-PERSIST-001: Malicious skill installation

AttributeValue
ATLAS IDAML.T0010.001 - Supply Chain Compromise: AI Software
DescriptionAttacker publishes a malicious skill to ClawHub
Attack vectorCreate account, publish skill with hidden malicious code
Affected componentsClawHub, skill loading, agent execution
Current mitigationsGitHub account age verification, static pattern/AST-adjacent scanning, LLM-based agentic risk review, VirusTotal scanning
Residual riskHigh - detection layers exist but skills still run with agent privileges and no execution sandboxing
RecommendationsSkill execution sandboxing, expanded community review

T-PERSIST-002: Skill update poisoning

AttributeValue
ATLAS IDAML.T0010.001 - Supply Chain Compromise: AI Software
DescriptionAttacker compromises a popular skill and pushes a malicious update
Attack vectorAccount compromise, social engineering of skill owner
Affected componentsClawHub versioning, auto-update flows
Current mitigationsVersion fingerprinting, moderation/scanning re-run on new versions
Residual riskHigh - auto-updates may pull malicious versions before review completes
RecommendationsUpdate signing, rollback capability, version pinning

T-PERSIST-003: Agent configuration tampering

AttributeValue
ATLAS IDAML.T0010.002 - Supply Chain Compromise: Data
DescriptionAttacker modifies agent configuration to persist access
Attack vectorConfig file modification, settings injection
Affected componentsAgent config, tool policies
Current mitigationsFile permissions
Residual riskMedium - requires local access
RecommendationsConfig integrity verification, audit logging for config changes