openclaw-new-agent

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard shell commands such as cp for configuration backups, mkdir for workspace creation, and grep for parsing log files to identify user IDs. It also invokes the openclaw CLI for system verification and service restarts. These actions are necessary for managing the OpenClaw environment.\n- [CREDENTIALS_UNSAFE]: The skill requires the processing of sensitive Feishu App IDs and App Secrets. These credentials are provided by the user and written to the local openclaw.json file. The analysis found no evidence of these credentials being transmitted to external servers or stored insecurely outside of the application's required configuration.\n- [EXTERNAL_DOWNLOADS]: The documentation references installation via npx clawhub@latest and git clone from the author's GitHub repository. These are standard distribution methods for the OpenClaw ecosystem and target the official repository of the skill author.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 06:40 AM
Security Audit — agent-trust-hub — openclaw-new-agent