Back to skill

Security audit

OpenClaw Security Hardening Toolkit

Security checks for vulnerabilities and agentic risk

Overview

The available artifacts are coherent developer workflow skills with disclosed command use and user-directed guardrails, though some workflows can perform high-impact maintainer actions.

Install only if you want ClawHub/Convex maintainer and developer workflow assistance. Review proposed commands before allowing writes, especially moderation actions, GitHub publishing, Convex deployment commands, package installs, and the autoreview helper's default full-access nested Codex review mode.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.