This is a real GitHub backup skill, but it can upload highly sensitive OpenClaw memory and configuration files with weak guardrails and a risky cron default.
Install only if you intentionally want OpenClaw identity, memory, tool configuration, skills, and related workspace files backed up to GitHub. Use a private repository that you own, set GITHUB_REPO explicitly, remove or change the davinwang/openclaw-memory cron default, use a fine-grained token limited to that one repo, avoid placing the token in ~/.bashrc or inline cron entries, review the exact files before pushing, and keep a local backup before any restore.