Back to skill

Security audit

Subagent Setup Wizard

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only guide for configuring OpenClaw subagents, with some state-changing commands users should run deliberately.

Install this only if you want OpenClaw subagent setup guidance. Review any config reset, config set, restart, or kill command before running it, because those can change your active agent environment and affect resource use or API cost.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger conditions include broad everyday terms like “并发” and “多 agent”, which can cause the skill to activate in unrelated conversations. This increases the chance that users are shown operational guidance or configuration steps they did not intend to request, creating confusion and potentially leading to unsafe system changes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The troubleshooting guidance includes commands that reset or modify live Subagent configuration without clearly warning that they can alter the existing environment. If surfaced or followed casually, these commands could disable working settings, interrupt operations, or change concurrency behavior in ways that affect stability and cost.

Static analysis

No suspicious patterns detected.