openclaw-security-practice-guide
Installation
SKILL.md
OpenClaw Security Practice Guide
Skill by ara.so — Hermes Skills collection.
A battle-tested security framework for high-privilege autonomous AI agents running with terminal/root access. This guide shifts from traditional static host defense to Agentic Zero-Trust Architecture, mitigating risks like destructive operations, prompt injection, supply chain poisoning, and unauthorized business logic execution.
Core Principle: Security measures designed to be interpreted and deployed by the AI agent itself, minimizing manual configuration while maintaining explicit human-in-the-loop controls for high-risk operations.
What This Guide Provides
3-Tier Defense Matrix
- Pre-action Defense
- Behavior blacklists (red/yellow line commands)
- Strict Skill/MCP installation audit protocols
- Supply chain poisoning prevention