This dashboard is not clearly malicious, but it exposes sensitive agent data and operational controls with defaults and documentation that do not fully match its authority.
Treat this as an admin console, not a passive dashboard. Install only if you are comfortable with it reading session transcripts and workspace metadata, deriving operator identities, writing local dashboard/topic state, and controlling OpenClaw jobs. Run it only on a trusted machine, explicitly bind or firewall it to localhost, enable strong authentication before any LAN/VPN/public/tunnel exposure, and review optional setup, dependency, tunnel, and Linear sync scripts before using them.