openclaw-multibot-audit
Installation
SKILL.md
OpenClaw Multi-Bot Security Audit
Audit any OpenClaw Telegram bot for multi-tenant security issues. Based on real production incidents from deploying CanArt Bot and TreeArt Bot.
When to Use
- Before launching a public OpenClaw Telegram bot
- After adding multi-user support to an existing bot
- During security review of any OpenClaw gateway serving multiple users
- When you suspect cross-user data leakage
Critical Context: OpenClaw's Security Model
From official docs (https://docs.openclaw.ai/gateway/security):
"OpenClaw is NOT a hostile multi-tenant security boundary for multiple adversarial users sharing one agent/gateway."
"If you need mixed-trust or adversarial-user operation, split trust boundaries (separate gateway + credentials, ideally separate OS users/hosts)."