This is a broad local OpenClaw security audit skill whose sensitive reads and limited writes are mostly disclosed and aligned with its purpose.
Install only if you want a comprehensive local security audit and are comfortable with it reading OpenClaw files, agent logs/session metadata, installed skill text, host security posture signals, credential-store path existence, and ClawHub token-store presence/permissions. Treat generated reports as private because they can map sensitive local security metadata, and use `--no-history`, `--no-host`, `--no-native`, `--no-sockets`, or `--no-deptree` when you want narrower scope.