openclaw-new-agent
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use standard shell commands such as
cpfor configuration backups,mkdirfor workspace creation, andgrepfor parsing log files to identify user IDs. It also invokes theopenclawCLI for system verification and service restarts. These actions are necessary for managing the OpenClaw environment.\n- [CREDENTIALS_UNSAFE]: The skill requires the processing of sensitive Feishu App IDs and App Secrets. These credentials are provided by the user and written to the localopenclaw.jsonfile. The analysis found no evidence of these credentials being transmitted to external servers or stored insecurely outside of the application's required configuration.\n- [EXTERNAL_DOWNLOADS]: The documentation references installation vianpx clawhub@latestandgit clonefrom the author's GitHub repository. These are standard distribution methods for the OpenClaw ecosystem and target the official repository of the skill author.
Audit Metadata