Back to skill

Security audit

Config Safe Edit

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent, instruction-only workflow for making safer configuration edits, with high-impact credential and startup-file handling disclosed and bounded by user-controlled steps.

Reasonable to install if you want a checklist for safer config changes. Before using it on credentials, API keys, or OpenClaw startup settings, confirm the exact file and values, review diffs carefully, and protect or remove backup files that may contain secrets.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.