Openclaw Installer

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward OpenClaw installation guide with normal cautions around global npm installs and running local services.

Install only if you intend to add OpenClaw globally. Review the npm packages and official documentation, consider pinning a version if reproducibility matters, keep any gateway or dashboard private or properly protected, and set API spending limits when using paid model providers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal