Agent Create Config

PassAudited by VirusTotal on Mar 21, 2026.

Findings (1)

The skill automates the creation and configuration of OpenClaw agents, which requires high-risk capabilities including shell command execution (e.g., `mkdir`, `cat`, `openclaw gateway restart`) and direct modification of configuration files and workspaces in the user's home directory (`~/.openclaw/`). It also handles sensitive credentials such as Feishu/Lark bot tokens and app secrets. While these behaviors are aligned with the stated purpose of agent setup, the broad filesystem access and instructions for agents to act autonomously without seeking permission ("不要问许可,直接做" in `references/MERGED_PROCESS.md`) present a significant security risk and attack surface.