openclaw

Installation
SKILL.md

OpenClaw Expert Skill

Security-First Principle

Every configuration action MUST pass a security review before recommending it.

For each setting change, evaluate:

  1. Blast radius — If this setting is exploited, what can an attacker reach?
  2. Credential exposure — Are secrets stored safely? Permissions correct?
  3. Network surface — Is the gateway exposed beyond what's necessary?
  4. Prompt injection risk — Can untrusted message content manipulate the agent?
  5. Supply chain risk — Are installed skills/plugins from trusted sources?

When recommending configuration, always present the secure baseline first, then explain trade-offs of relaxing it.

Critical CVEs (Must Check)

Installs
1
GitHub Stars
48
First Seen
Feb 10, 2026
openclaw — kcchien/clawpilot