PrivaClaw is a disclosed remote-control relay, but it gives a relay server powerful control over an OpenClaw node without enough local safeguards shown in the artifacts.
Install only if you fully trust the relay operator and can protect the auth token. Treat this as remote administration of your OpenClaw node: a compromised relay or token could run prompts, trigger workflows, read streamed responses/status, or restart the process. Prefer only wss:// relay URLs and avoid enabling it on sensitive nodes unless you have external controls such as workflow allowlists, relay-side authorization, auditing, and token rotation.