Openclaw Security

Perform a thorough security audit before installing any skill, script, plugin, or code from an external source — including GitHub repositories, URLs, .skill files, shell scripts, npm packages, pip packages, and zip archives. Trigger this skill whenever the user mentions: installing a skill from outside, downloading scripts, "install from GitHub", "run this script", importing an external plugin, or any time untrusted code is about to be executed or installed. ALWAYS use this skill proactively — security checks should happen before installation, not after. Even if the user just pastes a URL or file and says "install this", run the security check first. This is the openclaw external source security verification skill.

fanthus c3dfaa5 3 files · 11.4 KB Updated

File contents

fanthus/agent-skills/tree/main/openclaw-security commit c3dfaa57df

Frequently asked questions

npx skillmds@latest add fanthus/openclaw-security