Back to skill

Security audit

OpenClaw Pilot

Security checks for vulnerabilities and agentic risk

Overview

This is a low-risk planning skill that formats project ideas into reviewable OpenClaw execution packets without installing code or accessing private data.

Reasonable to install as a planning and prompt-formatting helper. Users should still read any generated OpenClaw execution packet before handing it to an executor, because the skill shapes instructions but does not independently prove that the packet is safe for a specific project.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.