Back to skill

Security audit

Governed Delegation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow delegation-policy helper that reads task details and prints a governed spawn request without hidden credential, network, persistence, or destructive behavior.

This appears safe for its stated role as a delegation guardrail. Before installing, confirm your OpenClaw environment provides the expected local policy module, and avoid placing secrets or private data in prompts that may be handed to delegated agents or external model providers.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.