Security audit
Assistant Configurator
Security checks for vulnerabilities and agentic risk
Overview
This is an instruction-only configuration guide for OpenClaw, with powerful settings examples that are visible and aligned with its purpose.
Install this only if you want help changing OpenClaw settings. Before applying suggested config patches, review the exact change, back up current configuration, change one setting at a time, and avoid placing real API keys or bot tokens in chat or logs.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
