OpenClaw浏览器自动化配置

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate browser automation setup, but its examples can expose powerful remote browser control without enough security guidance.

Review before installing. Use only trusted remote browser providers, protect Browserless tokens as secrets, avoid sensitive logins in shared or cloud browsers, bind local CDP to localhost or place it behind SSH/VPN/firewall controls, and consider pinning the Docker image version or digest.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation instructs users to connect OpenClaw to remote CDP endpoints, including a third-party browserless service, without warning that browser automation traffic may expose page contents, session cookies, credentials, screenshots, and browsing context to the remote endpoint provider or any intermediary. CDP provides powerful browser control, so using remote or cloud endpoints without clear trust, transport security, and secret-handling guidance can lead to privacy leakage and account compromise.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal