openclaw-setup

Fail

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEPERSISTENCECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The installation guide instructs users to pipe remote shell and PowerShell scripts directly into interpreters (curl | bash and iwr | iex) from https://openclaw.ai.- [CREDENTIALS_UNSAFE]: The troubleshooting and configuration documentation includes commands to print sensitive environment variables such as ANTHROPIC_API_KEY and OPENAI_API_KEY, as well as commands to retrieve authentication tokens from the openclaw.json config file.- [PERSISTENCE]: The skill automates the creation of background services using launchd on macOS and systemd on Linux to ensure the application remains active across system restarts.- [COMMAND_EXECUTION]: The instructions involve broad process termination capabilities using killall and pkill, and the execution of arbitrary Node.js code via node -e for environment diagnosis.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user messages and workspace files (AGENTS.md, SOUL.md) to drive agent logic without defined sanitization or boundary markers.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 28, 2026, 08:33 AM
Security Audit — agent-trust-hub — openclaw-setup