An agent is more dangerous than a chatbot: it executes. Default security must be held to "production service" standards, not "toy demo" standards.
Principle of Least Privilege
- Skills are read-only by default
- Capabilities to write files / send messages / spend money are enabled per skill
- Keep production secrets isolated from everyday chat environments
Secrets and Configuration
- Environment variables or a secrets manager only — never commit them to the repo
- Rotate regularly; revoke immediately when someone leaves
- Redact sensitive values from logs (Authorization, cookies, private keys)
Network Egress
- Allowlist model and channel domains
- Forbid unapproved, arbitrary SSRF targets
- Set NO_PROXY explicitly behind corporate proxies
Auditing
- Record who triggered which tool, when, plus a result summary
- Retain a long enough replay window for incident post-mortems
- Require secondary confirmation for high-risk tools (human in the loop)
Incident Response (a 30-Minute Playbook)
- Stop the agent / revoke keys
- Freeze anomalous outbound channels
- Export the latest audit logs
- Rotate all related secrets
- Post-mortem: which missing policy allowed the privilege escalation
More: the site's Security page and OpenClaw security and cost.
Agent 比聊天机器人更危险:它会执行。默认安全必须按“生产服务”而不是“玩具 demo”。
最小权限原则
- 技能默认 只读
- 写文件 / 发消息 / 花钱 的能力 分技能开启
- 生产密钥与日常对话环境隔离
密钥与配置
- 仅环境变量或密钥管理器,禁止写进仓库
- 定期轮换;离职立即吊销
- 日志脱敏(Authorization、Cookie、私钥)
网络出站
- 白名单模型与通道域名
- 禁止未审批的任意 SSRF 目标
- 公司代理下明确 NO_PROXY
审计
- 记录:谁在何时触发了何工具、结果摘要
- 保留足够回放窗口用于事故复盘
- 对高风险工具二次确认(人在环)
事故响应(30 分钟手册)
- 停 Agent / 撤 Key
- 冻结异常外发通道
- 导出最近审计日志
- 轮换所有相关密钥
- 复盘:缺哪条策略导致越权
更多:站点 Security 页与 OpenClaw 安全与成本。
エージェントはチャットボットより危険です。実行するからです。デフォルトのセキュリティは「トイデモ」ではなく「本番サービス」の水準で整えるべきです。
最小権限の原則
- スキルはデフォルトで読み取り専用
- ファイル書き込み/メッセージ送信/課金の能力はスキル単位で有効化
- 本番シークレットと日常の対話環境を分離
シークレットと設定
- 環境変数またはシークレットマネージャーのみ。リポジトリへのコミットは禁止
- 定期的にローテーションし、退職時には即時に失効
- ログのマスキング(Authorization、Cookie、秘密鍵)
アウトバウンドネットワーク
- モデルとチャンネルのドメインをホワイトリスト化
- 承認されていない任意の SSRF 先を禁止
- コーポレートプロキシ配下では NO_PROXY を明示
監査
- 記録するのは、誰がいつどのツールを呼び出したかと結果の概要
- インシデント振り返りに足るリプレイ期間を保持
- 高リスクツールには二次確認(ヒューマンインザループ)
インシデント対応(30 分ハンドブック)
- エージェントを停止/キーを失効
- 異常な外向きチャンネルを凍結
- 直近の監査ログをエクスポート
- 関連するすべてのシークレットをローテーション
- 振り返り:どのポリシーの不足が権限越過を許したか
さらに詳しく:サイトの Security ページと OpenClaw のセキュリティとコスト。
Agent 比聊天機器人更危險:它會執行。預設安全必須按「正式環境服務」而不是「玩具 demo」的標準。
最小權限原則
- 技能預設 唯讀
- 寫檔案 / 傳訊息 / 花錢的能力 逐技能開啟
- 正式環境金鑰與日常對話環境隔離
金鑰與設定
- 僅使用環境變數或金鑰管理器,禁止寫進儲存庫
- 定期輪換;離職立即吊銷
- 日誌脫敏(Authorization、Cookie、私鑰)
對外網路連線
- 白名單模型與通道網域
- 禁止未審批的任意 SSRF 目標
- 公司代理下明確設定 NO_PROXY
稽核
- 記錄:誰在何時觸發了哪個工具、結果摘要
- 保留足夠的回溯期間用於事故檢討
- 對高風險工具二次確認(人在環)
事故應變(30 分鐘手冊)
- 停 Agent / 撤銷金鑰
- 凍結異常外發通道
- 匯出最近稽核日誌
- 輪換所有相關金鑰
- 檢討:缺哪條策略導致越權
更多:網站 Security 頁與 OpenClaw 安全與成本。
Ein Agent ist gefährlicher als ein Chatbot: Er führt aus. Die Standard-Sicherheit muss an den Maßstäben eines „Produktionsdienstes“ gemessen werden, nicht an denen einer „Spielzeug-Demo“.
Prinzip der geringsten Rechte
- Skills sind standardmäßig read-only
- Fähigkeiten zum Schreiben von Dateien / Senden von Nachrichten / Ausgeben von Geld werden pro Skill aktiviert
- Produktions-Secrets von alltäglichen Chat-Umgebungen getrennt halten
Secrets und Konfiguration
- Ausschließlich Umgebungsvariablen oder ein Secrets-Manager — niemals ins Repository committen
- Regelmäßig rotieren; beim Ausscheiden einer Person sofort widerrufen
- Sensible Werte in Logs schwärzen (Authorization, Cookies, private Schlüssel)
Ausgehender Netzwerkverkehr
- Modell- und Kanal-Domänen auf eine Allowlist setzen
- Nicht genehmigte, beliebige SSRF-Ziele verbieten
- Hinter Unternehmens-Proxys NO_PROXY explizit setzen
Auditing
- Festhalten, wer wann welches Tool ausgelöst hat, plus eine Ergebniszusammenfassung
- Ein ausreichend langes Replay-Fenster für Incident-Post-Mortems vorhalten
- Für Hochrisiko-Tools eine Zweitbestätigung verlangen (Human in the Loop)
Incident Response (ein 30-Minuten-Playbook)
- Agent stoppen / Keys widerrufen
- Anomale ausgehende Kanäle einfrieren
- Die neuesten Audit-Logs exportieren
- Alle zugehörigen Secrets rotieren
- Post-Mortem: Welche fehlende Policy hat die Rechteausweitung erlaubt
Mehr dazu: die Seite Security der Website und OpenClaw Sicherheit und Kosten.
Un agent est plus dangereux qu'un chatbot : il exécute. La sécurité par défaut doit être tenue aux standards d'un « service de production », pas à ceux d'une « démo jouet ».
Principe du moindre privilège
- Les Skills sont en lecture seule par défaut
- Les capacités à écrire des fichiers / envoyer des messages / dépenser de l'argent sont activées par Skill
- Maintenir les secrets de production isolés des environnements de conversation quotidiens
Secrets et configuration
- Uniquement des variables d'environnement ou un gestionnaire de secrets — jamais de commit dans le dépôt
- Rotation régulière ; révocation immédiate au départ d'une personne
- Masquer les valeurs sensibles dans les logs (Authorization, cookies, clés privées)
Sortie réseau
- Mettre les domaines des modèles et des canaux sur liste blanche
- Interdire les cibles SSRF arbitraires non approuvées
- Définir NO_PROXY explicitement derrière les proxys d'entreprise
Audit
- Consigner qui a déclenché quel outil, quand, plus un résumé du résultat
- Conserver une fenêtre de relecture assez longue pour les post-mortems d'incidents
- Exiger une double confirmation pour les outils à haut risque (humain dans la boucle)
Réponse aux incidents (un playbook de 30 minutes)
- Arrêter l'agent / révoquer les clés
- Figer les canaux sortants anormaux
- Exporter les derniers logs d'audit
- Retourner tous les secrets associés
- Post-mortem : quelle politique manquante a permis l'escalade de privilèges
Pour aller plus loin : la page Security du site et Sécurité et coûts d'OpenClaw.
Un agente es más peligroso que un chatbot: ejecuta. La seguridad por defecto debe cumplir los estándares de un «servicio de producción», no los de una «demo de juguete».
Principio de mínimo privilegio
- Las Skills son de solo lectura por defecto
- Las capacidades de escribir archivos / enviar mensajes / gastar dinero se activan por Skill
- Mantener los secretos de producción aislados de los entornos de chat cotidianos
Secretos y configuración
- Solo variables de entorno o un gestor de secretos — nunca subirlos al repositorio
- Rotar con regularidad; revocar de inmediato cuando alguien se marcha
- Ocultar los valores sensibles en los logs (Authorization, cookies, claves privadas)
Tráfico de red saliente
- Poner los dominios de modelos y canales en una lista de permitidos
- Prohibir destinos SSRF arbitrarios sin aprobar
- Configurar NO_PROXY explícitamente detrás de proxys corporativos
Auditoría
- Registrar quién activó qué herramienta y cuándo, más un resumen del resultado
- Conservar una ventana de reproducción bastante larga para los análisis post-incidente
- Exigir una confirmación secundaria para las herramientas de alto riesgo (humano en el bucle)
Respuesta a incidentes (un playbook de 30 minutos)
- Detener el agente / revocar las claves
- Congelar los canales salientes anómalos
- Exportar los últimos logs de auditoría
- Rotar todos los secretos relacionados
- Post-mortem: qué política faltante permitió la escalada de privilegios
Más información: la página Security del sitio y Seguridad y costes de OpenClaw.
Un agente es más peligroso que un chatbot: ejecuta. La seguridad por defecto debe cumplir los estándares de un «servicio de producción», no los de una «demo de juguete».
Principio de mínimo privilegio
- Las Skills son de solo lectura por defecto
- Las capacidades de escribir archivos / enviar mensajes / gastar dinero se activan por Skill
- Mantener los secretos de producción aislados de los entornos de chat cotidianos
Secretos y configuración
- Solo variables de entorno o un gestor de secretos — nunca subirlos al repositorio
- Rotar con regularidad; revocar de inmediato cuando alguien se marcha
- Ocultar los valores sensibles en los logs (Authorization, cookies, claves privadas)
Tráfico de red saliente
- Poner los dominios de modelos y canales en una lista de permitidos
- Prohibir destinos SSRF arbitrarios sin aprobar
- Configurar NO_PROXY explícitamente detrás de proxys corporativos
Auditoría
- Registrar quién activó qué herramienta y cuándo, más un resumen del resultado
- Conservar una ventana de reproducción bastante larga para los análisis post-incidente
- Exigir una confirmación secundaria para las herramientas de alto riesgo (humano en el bucle)
Respuesta a incidentes (un playbook de 30 minutos)
- Detener el agente / revocar las claves
- Congelar los canales salientes anómalos
- Exportar los últimos logs de auditoría
- Rotar todos los secretos relacionados
- Post-mortem: qué política faltante permitió la escalada de privilegios
Más información: la página Security del sitio y Seguridad y costes de OpenClaw.
Un agente è più pericoloso di un chatbot: esegue per davvero. La sicurezza predefinita deve rispettare gli standard di un «servizio di produzione», non quelli di una «demo giocattolo».
Principio del minimo privilegio
- Le Skill sono di sola lettura per impostazione predefinita
- Le capacità di scrivere file / inviare messaggi / spendere denaro vengono attivate per singola Skill
- Tenere i segreti di produzione isolati dagli ambienti di chat quotidiani
Segreti e configurazione
- Solo variabili d'ambiente o un gestore di segreti — mai committarli nel repository
- Rotazione regolare; revoca immediata quando qualcuno se ne va
- Oscurare i valori sensibili nei log (Authorization, cookie, chiavi private)
Traffico di rete in uscita
- Mettere in allowlist i domini dei modelli e dei canali
- Vietare destinazioni SSRF arbitrarie non approvate
- Impostare NO_PROXY esplicitamente dietro i proxy aziendali
Auditing
- Registrare chi ha attivato quale tool e quando, più un riepilogo del risultato
- Conservare una finestra di replay abbastanza lunga per i post-mortem degli incidenti
- Richiedere una conferma secondaria per i tool ad alto rischio (persona nel loop)
Risposta agli incidenti (un playbook di 30 minuti)
- Fermare l'agente / revocare le chiavi
- Congelare i canali in uscita anomali
- Esportare gli ultimi log di audit
- Ruotare tutti i segreti correlati
- Post-mortem: quale policy mancante ha permesso l'elevazione dei privilegi
Approfondimenti: la pagina Security del sito e Sicurezza e costi di OpenClaw.
에이전트는 챗봇보다 위험합니다. 직접 실행하기 때문입니다. 기본 보안은 "토이 데모" 기준이 아니라 "프로덕션 서비스" 기준으로 갖춰야 합니다.
최소 권한 원칙
- 스킬은 기본적으로 읽기 전용입니다
- 파일 쓰기 / 메시지 전송 / 결제 같은 권한은 스킬 단위로만 활성화합니다
- 프로덕션 시크릿은 일상 대화 환경과 분리합니다
시크릿과 설정
- 환경 변수 또는 시크릿 관리자만 사용하고 저장소에 커밋하지 않습니다
- 주기적으로 로테이션하고, 담당자가 떠나면 즉시 폐기합니다
- 로그의 민감한 값(Authorization, 쿠키, 개인 키)은 마스킹합니다
아웃바운드 네트워크
- 모델과 채널 도메인은 화이트리스트로 관리합니다
- 승인되지 않은 임의의 SSRF 대상은 금지합니다
- 사내 프록시 환경에서는 NO_PROXY를 명시적으로 설정합니다
감사
- 누가 언제 어떤 도구를 호출했는지와 결과 요약을 기록합니다
- 사고 분석에 쓸 수 있을 만큼 긴 재생 기간을 보존합니다
- 고위험 도구에는 2차 확인(휴먼 인 더 루프)을 요구합니다
사고 대응 (30분 플레이북)
- 에이전트 중지 / 키 폐기
- 비정상 아웃바운드 채널 동결
- 최신 감사 로그 내보내기
- 관련 시크릿 전부 로테이션
- 사후 분석: 어느 정책이 빠져서 권한 상승이 가능했는지
더 보기: 사이트의 Security 페이지와 OpenClaw 보안과 비용 문서.
الوكيل أخطر من روبوت الدردشة: فهو ينفّذ الأوامر فعليًا. يجب إمساك الأمان الافتراضي بمعايير «خدمة إنتاج» لا بمعايير «عرض تجريبي للعب».
مبدأ أقل الامتيازات
- المهارات (Skills) للقراءة فقط افتراضيًا
- قدرات كتابة الملفات / إرسال الرسائل / إنفاق المال تُفعَّل لكل مهارة على حدة
- عزل أسرار الإنتاج عن بيئات المحادثة اليومية
الأسرار والإعدادات
- متغيرات البيئة أو مدير أسرار فقط — ولا تُرفع إلى المستودع أبدًا
- تدوير منتظم؛ وإلغاء فوري عند مغادرة أي شخص
- إخفاء القيم الحساسة من السجلات (Authorization وملفات تعريف الارتباط والمفاتيح الخاصة)
حركة الشبكة الصادرة
- إدراج نطاقات النماذج والقنوات في قائمة السماح
- منع أهداف SSRF العشوائية غير المعتمدة
- تعيين NO_PROXY صراحةً خلف بروكسيات الشركات
التدقيق
- تسجيل من فعّل أي أداة ومتى، مع ملخص النتيجة
- الاحتفاظ بنافذة إعادة تشغيل طويلة بما يكفي لمراجعات ما بعد الحادث
- اشتراط تأكيد ثانٍ للأدوات عالية المخاطر (الإنسان في الحلقة)
الاستجابة للحوادث (دليل عملي من 30 دقيقة)
- إيقاف الوكيل / إبطال المفاتيح
- تجميد قنوات الاتصال الصادرة الشاذة
- تصدير أحدث سجلات التدقيق
- تدوير جميع الأسرار ذات الصلة
- مراجعة ما بعد الحادث: أي سياسة ناقصة سمحت بتصعيد الامتيازات
المزيد: صفحة Security على الموقع ومقالة أمان OpenClaw وتكلفته.