Back to skill

Security audit

OpenClaw Lifecycle Manager

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only lifecycle planning skill whose high-impact OpenClaw actions are disclosed and guarded, with no evidence of hidden execution or data theft.

Install only if you want an agent to help plan and possibly write OpenClaw lifecycle changes. Review any generated publish, install, deploy, deprecate, retire, or artifact-write action before allowing it, and verify the referenced local SSOT manuals are trusted.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.