Back to skill

Security audit

Coordinator Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about coordinating OpenClaw agents, but it should be installed only with carefully scoped workspace and messaging access.

Install only if you want a coordinator that can read the agent workspaces you list and send summaries to Telegram or other configured messaging platforms. Use a dedicated scoped auth profile, avoid copying broad credentials, exclude workspaces containing secrets or private data, and leave self-healing disabled unless rerunning missed cron jobs is safe.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.