Skip to content

Auditing Your OpenClaw Security

I’ve spent way too much time worrying if my configuration is actually safe. It is that nagging feeling that a small oversight in a config file might lead to a data leak or a security breach. We often focus so much on getting things to work that we forget to check if they are secure.

I found that having an automated way to check for these issues saves a lot of manual auditing time. Instead of guessing if my setup is safe, I use the built-in security tools to verify my configuration and fix common mistakes.

  • An active OpenClaw installation.
  • A configured session or gateway setup.

I recommend running these steps to ensure your environment is locked down. It takes less than five minutes to identify the most common vulnerabilities.

  1. Run a basic audit: This checks your current configuration for immediate risks.

    Terminal window
    openclaw security audit
  2. Run a deep audit: If you want a more thorough inspection, use the deep flag.

    Terminal window
    openclaw security audit --deep
  3. Review the output: Look for warnings regarding session sharing or model sandboxing.

  4. Apply automatic fixes: If the audit finds issues it can resolve, you can let the tool handle it.

    Terminal window
    openclaw security audit --fix

I have run into a few specific warnings while using these tools. Here is how to handle them based on the official recommendations:

  • Shared DM Sessions: If the audit warns that multiple DM senders share the main session, I recommend switching to secure DM mode. You can set session.dmScope="per-channel-peer". For those using multi-account channels, use session.dmScope="per-account-channel-peer" instead.
  • Small Model Risks: The audit flags models smaller than or equal to 300B if you have web or browser tools enabled without sandboxing. To fix this, you should enable sandboxing for these specific models to prevent unauthorized access.

If you need specific help with your configuration, check out the AI Setup Assistant.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.