Security audit
Prompt Hardening
Security checks for vulnerabilities and agentic risk
Overview
This is a prompt-hardening guide with a local audit helper, and its disclosed behavior is purpose-aligned with no evidence of credential access, network exfiltration, persistence, or destructive actions.
Install if you want an advisory checklist for hardening prompts. Run the audit helper only on prompt files you intentionally choose, review any rewritten prompt before applying it, and verify the publisher identity if the OpenClaw Team author claim matters to you.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
