Scan Report
5 /100
openclaw
Comprehensive guide for installing, configuring, operating, and troubleshooting OpenClaw — a self-hosted, multi-channel AI agent gateway
OpenClaw Maintenance Skill is a documentation-only knowledge base (54 markdown files, 11,366 lines) for installing, configuring, and operating the OpenClaw AI agent gateway. No executable code, scripts, or dependencies are present. All flagged IOCs are legitimate documentation examples or clearly marked placeholders.
Safe to install
This skill is safe to use as-is. The `curl|bash` pattern is a documented installation method (not self-executed), and hardcoded credentials are example placeholders. No action required.
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | READ | READ | ✓ Aligned | Skill contains markdown files read by the AI to answer queries |
| Network | READ | READ | ✓ Aligned | SKILL.md references URLs (openclaw.ai, github.com, docs.openclaw.ai) for install… |
| Shell | NONE | NONE | — | No shell scripts present; curl|bash is documented as an install method, not self… |
| Environment | NONE | NONE | — | No environment access code; documentation references env vars as configuration o… |
| Skill Invoke | NONE | NONE | — | No skill invocation code; documents ClawHub registry as a feature |
| Clipboard | NONE | NONE | — | No clipboard access |
| Browser | NONE | NONE | — | No browser automation; browser.md is documentation about the browser tool featur… |
| Database | NONE | NONE | — | No database access |
1 Critical 3 High 101 findings
Critical Dangerous Command 危险 Shell 命令
curl -fsSL https://openclaw.ai/install.sh | bash SKILL.md:279 High API Key 疑似硬编码凭证
password: "example-password" references/channel_routing.md:113 High IP Address 硬编码 IP 地址
172.21.0.1 references/sandboxing.md:143 High API Key 疑似硬编码凭证
apiKey: "elevenlabs_api_key" references/voice.md:42 Medium External URL 外部 URL
https://docs.openclaw.ai/ README.md:121 Medium External URL 外部 URL
https://docs.openclaw.ai/install README.md:123 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/architecture README.md:124 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/agent README.md:125 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/agent-loop README.md:126 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/configuration README.md:127 Medium External URL 外部 URL
https://docs.openclaw.ai/channels README.md:128 Medium External URL 外部 URL
https://docs.openclaw.ai/providers README.md:129 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/model-failover README.md:130 Medium External URL 外部 URL
https://docs.openclaw.ai/tools README.md:131 Medium External URL 外部 URL
https://docs.openclaw.ai/tools/thinking README.md:132 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/queue README.md:133 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/streaming README.md:134 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/memory README.md:135 Medium External URL 外部 URL
https://docs.openclaw.ai/tools/clawhub README.md:136 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/multi-agent README.md:137 Medium External URL 外部 URL
https://docs.openclaw.ai/nodes/talk README.md:138 Medium External URL 外部 URL
https://docs.openclaw.ai/automation/poll README.md:139 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/presence README.md:140 Medium External URL 外部 URL
https://docs.openclaw.ai/pi README.md:141 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/security README.md:142 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/troubleshooting README.md:143 Medium External URL 外部 URL
https://docs.openclaw.ai/cli README.md:144 Medium External URL 外部 URL
http://127.0.0.1:18789/ SKILL.md:125 Medium External URL 外部 URL
https://openclaw.ai/install.sh SKILL.md:279 Medium External URL 外部 URL
https://docs.openclaw.ai/cli/acp references/acp_agents.md:245 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/agent-workspace references/agent_runtime.md:6 Medium External URL 外部 URL
http://127.0.0.1:18789/hooks/wake references/automation.md:155 Medium External URL 外部 URL
http://127.0.0.1:18789/hooks/agent references/automation.md:164 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/bonjour references/bonjour.md:3 Medium External URL 外部 URL
http://127.0.0.1:18792 references/browser.md:38 Medium External URL 外部 URL
http://10.0.0.42:9222 references/browser.md:64 Medium External URL 外部 URL
https://provider.example?token= references/browser.md:110 Medium External URL 外部 URL
https://user:[email protected] references/browser.md:111 Medium External URL 外部 URL
https://production-sfo.browserless.io?token= references/browser.md:132 Medium External URL 外部 URL
https://docs.openclaw.ai/tools/chrome-extension references/browser.md:142 Medium External URL 外部 URL
https://docs.openclaw.ai/tools/browser-login references/browser.md:199 Medium External URL 外部 URL
https://docs.openclaw.ai/tools/browser-linux-troubleshooting references/browser.md:234 Medium External URL 外部 URL
https://docs.openclaw.ai/channels/channel-routing references/channel_routing.md:3 Medium External URL 外部 URL
https://docs.openclaw.ai/channels/mattermost references/channel_routing.md:68 Medium External URL 外部 URL
https://chat.example.com references/channel_routing.md:81 Medium External URL 外部 URL
https://docs.openclaw.ai/channels/bluebubbles references/channel_routing.md:98 Medium External URL 外部 URL
https://bluebubbles.app references/channel_routing.md:101 Medium External URL 外部 URL
http://192.168.1.100:1234 references/channel_routing.md:112 Medium External URL 外部 URL
https://your-gateway-host:3000/bluebubbles-webhook?password= references/channel_routing.md:120 Medium External URL 外部 URL
https://t.me/BotFather references/channels.md:100 Medium External URL 外部 URL
https://discord.com/developers/applications references/channels.md:123 Medium External URL 外部 URL
https://api.example.com/v1 references/config_reference.md:431 Medium External URL 外部 URL
https://firecrawl.dev references/diffs_firecrawl.md:103 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/network-model references/gateway_internals.md:7 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/gateway-lock references/gateway_internals.md:23 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/health references/gateway_internals.md:48 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/doctor references/gateway_internals.md:74 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/logging references/gateway_internals.md:111 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/background-process references/gateway_internals.md:136 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/heartbeat references/heartbeat.md:3 Medium External URL 外部 URL
https://openclaw.ai/install.ps1 references/install.md:29 Medium External URL 外部 URL
https://docs.openclaw.ai/install/docker references/install.md:85 Medium External URL 外部 URL
https://x.com/plattenschieber/status/2014508656335770033 references/lobster.md:275 Medium External URL 外部 URL
https://docs.openclaw.ai/nodes/camera references/media.md:3 Medium External URL 外部 URL
https://docs.openclaw.ai/providers/openai references/memory.md:261 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/session-pruning references/memory.md:271 Medium External URL 外部 URL
https://docs.openclaw.ai/concepts/oauth references/model_failover.md:5 Medium External URL 外部 URL
https://p.prose.md/ references/openprose.md:97 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/pairing references/pairing.md:3 Medium External URL 外部 URL
https://docs.openclaw.ai/platforms/macos references/platforms.md:34 Medium External URL 外部 URL
https://docs.openclaw.ai/platforms/ios references/platforms.md:47 Medium External URL 外部 URL
https://docs.openclaw.ai/platforms/android references/platforms.md:58 Medium External URL 外部 URL
https://docs.openclaw.ai/platforms/windows references/platforms.md:66 Medium External URL 外部 URL
https://docs.openclaw.ai/platforms/linux references/platforms.md:74 Medium External URL 外部 URL
https://docs.openclaw.ai/vps references/platforms.md:85 Medium External URL 外部 URL
https://docs.openclaw.ai/plugins/voice-call references/plugins.md:19 Medium External URL 外部 URL
https://docs.openclaw.ai/plugins/zalouser references/plugins.md:20 Medium External URL 外部 URL
https://docs.openclaw.ai/channels/matrix references/plugins.md:21 Medium External URL 外部 URL
https://docs.openclaw.ai/channels/nostr references/plugins.md:22 Medium External URL 外部 URL
https://docs.openclaw.ai/channels/zalo references/plugins.md:23 Medium External URL 外部 URL
https://docs.openclaw.ai/channels/msteams references/plugins.md:24 Medium External URL 外部 URL
https://docs.openclaw.ai/gateway/discovery references/presence_discovery.md:5 Medium External URL 外部 URL
https://docs.openclaw.ai/providers/ references/providers.md:244 Medium External URL 外部 URL
http://127.0.0.1:18789 references/remote_access.md:35 Medium External URL 外部 URL
https://127.0.0.1:18789 references/remote_access.md:89 Medium External URL 外部 URL
https://docs.openclaw.ai/reference/session-management-compaction references/sessions.md:229 Medium External URL 外部 URL
https://clawhub.com references/skills.md:27 Medium External URL 外部 URL
https://example.invalid references/skills.md:69 Medium External URL 外部 URL
https://docs.openclaw.ai/tools/skills-config references/skills.md:140 Medium External URL 外部 URL
https://docs.openclaw.ai/web/tui references/tui.md:3 Medium External URL 外部 URL
https://docs.openclaw.ai/nodes/voicewake references/voice.md:5 Medium External URL 外部 URL
https://brave.com/search/api/ references/web_tools.md:38 Medium External URL 外部 URL
https://openrouter.ai/ references/web_tools.md:67 Medium External URL 外部 URL
https://aistudio.google.com/ references/web_tools.md:93 Info Email 邮箱地址
[email protected] references/browser.md:111 Info Email 邮箱地址
[email protected] references/channel_routing.md:60 Info Email 邮箱地址
[email protected] references/channel_troubleshooting.md:339 Info Email 邮箱地址
[email protected] references/model_failover.md:21 Info Email 邮箱地址
[email protected] references/multi_agent.md:118 Info Email 邮箱地址
[email protected] references/polls.md:27 Info Email 邮箱地址
[email protected] references/polls.md:38 File Tree
54 files · 343.1 KB · 11366 lines Markdown 54f · 11366L
├─
▾
references
│ ├─
acp_agents.md
Markdown
│ ├─
agent_runtime.md
Markdown
│ ├─
architecture.md
Markdown
│ ├─
automation.md
Markdown
│ ├─
bonjour.md
Markdown
│ ├─
browser.md
Markdown
│ ├─
channel_routing.md
Markdown
│ ├─
channel_troubleshooting.md
Markdown
│ ├─
channels.md
Markdown
│ ├─
clawhub.md
Markdown
│ ├─
config_reference.md
Markdown
│ ├─
diffs_firecrawl.md
Markdown
│ ├─
elevated.md
Markdown
│ ├─
exec_approvals.md
Markdown
│ ├─
exec.md
Markdown
│ ├─
gateway_internals.md
Markdown
│ ├─
gateway_ops.md
Markdown
│ ├─
heartbeat.md
Markdown
│ ├─
hooks.md
Markdown
│ ├─
install.md
Markdown
│ ├─
llm_task.md
Markdown
│ ├─
lobster.md
Markdown
│ ├─
media.md
Markdown
│ ├─
memory.md
Markdown
│ ├─
model_failover.md
Markdown
│ ├─
multi_agent.md
Markdown
│ ├─
nodes.md
Markdown
│ ├─
openprose.md
Markdown
│ ├─
pairing.md
Markdown
│ ├─
pdf_tool.md
Markdown
│ ├─
platforms.md
Markdown
│ ├─
plugins.md
Markdown
│ ├─
polls.md
Markdown
│ ├─
presence_discovery.md
Markdown
│ ├─
providers.md
Markdown
│ ├─
queue.md
Markdown
│ ├─
remote_access.md
Markdown
│ ├─
sandboxing.md
Markdown
│ ├─
secrets.md
⚠
Markdown
│ ├─
security.md
Markdown
│ ├─
sessions.md
Markdown
│ ├─
skills.md
Markdown
│ ├─
slash_commands.md
Markdown
│ ├─
streaming.md
Markdown
│ ├─
subagents.md
Markdown
│ ├─
thinking.md
Markdown
│ ├─
tools.md
Markdown
│ ├─
tui.md
Markdown
│ ├─
voice.md
Markdown
│ ├─
web_tools.md
Markdown
│ └─
web_ui.md
Markdown
├─
README_CN.md
Markdown
├─
README.md
Markdown
└─
SKILL.md
Markdown
Security Positives
✓ Documentation-only skill with no executable code or scripts
✓ No dependencies or package files that could introduce supply chain risks
✓ No credential harvesting, data exfiltration, or obfuscation patterns
✓ All hardcoded values (IP 172.21.0.1, passwords) are clearly marked as example/placeholder documentation
✓ The curl|bash pattern is a documented third-party install method for OpenClaw software, not self-execution
✓ Comprehensive security documentation covers sandboxing, elevated mode controls, tool policies, and secrets management
✓ Skill accurately reflects declared capabilities with no shadow functionality