Back to skill

Security audit

openclaw-cleaner

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local cleanup skill with user-triggered file archiving/deletion, but users should review its config before enabling force or cron.

Run it in dry-run first and inspect the listed files before using --force or cron. Keep archive_dir inside ~/.openclaw/workspace unless you intentionally want another location, review delete patterns carefully, and do not rely on the whitelist until you have tested that it protects the files you expect.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.