Security audit
OpenClaw Release Validation
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed release-validation workflow with clear safeguards around local gateway changes and public GitHub posting.
Before installing, understand that this skill is meant for OpenClaw release testers: it can modify a real selected gateway if you choose in-place mode, and it can post to GitHub only after review and explicit approval. Use the isolated OCM copy path unless you are comfortable testing against your actual gateway state.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
