Security audit
OpenClaw Smart Backup
Security checks for vulnerabilities and agentic risk
Overview
The backup tool is purpose-aligned, but its visible exclusion logic appears flawed and could include sensitive key files or symlinked files that users would expect it to skip.
Before installing or running, use the documented dry-run mode, review which files would be archived, avoid workspaces containing symlinks to sensitive locations, store backup archives securely, and consider fixing the wildcard and symlink exclusion logic.
Static analysis
No suspicious patterns detected.
