Back to skill

Security audit

Openclaw Issue

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward helper for drafting OpenClaw/ClawHub GitHub issues, with normal public-posting and account-use caveats.

Before installing or using it, review the generated issue title and body carefully. Do not include secrets, credentials, private URLs, personal data, or unverified security claims. Prefer the pre-filled URL method if you want a final browser review before posting to GitHub.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.