Security Audit

Use OpenClaw built-in security audit tool. Run regularly.

$ openclaw security audit
$ openclaw security audit --deep
$ openclaw security audit --fix

What the Audit Checks

🚪

Inbound Access

DM policies, group policies, allowlists.

💥

Tool Blast Radius

Elevated tools + open rooms.

🌐

Network Exposure

Gateway bind/auth, Tailscale.

🌐

Browser Control

Remote nodes, CDP endpoints.

📁

Local Disk

Permissions, symlinks.

🔌

Plugins

Extensions without allowlist.

Priority Order

  1. Anything "open" + tools enabled
  2. Public network exposure
  3. Browser control exposure
  4. Permissions
  5. Plugins

Credential Storage

ChannelLocation
WhatsApp~/.openclaw/credentials/whatsapp/*/creds.json
TelegramConfig/env or channels.telegram.tokenFile
Model Auth~/.openclaw/agents/*/agent/auth-profiles.json
Sessions~/.openclaw/agents/*/sessions/*.jsonl