openclaw-client-bootstrap

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The bootstrap and installation scripts fetch and execute installation scripts from official sources including NodeSource, Tailscale, and the primary vendor domain (openclaw.ai). These are standard procedures for installing the required runtime and security components.\n- [COMMAND_EXECUTION]: The toolkit utilizes system-level commands via sudo and systemctl to manage firewall rules, SSH security settings, and background services for the agent environment.\n- [EXTERNAL_DOWNLOADS]: Fetches software assets, GPG keys, and configuration templates from official repositories for Node.js, Docker, and Tailscale during the initialization of the client environment.\n- [DATA_EXFILTRATION]: Facilitates the secure transfer of API keys for integrated AI providers to the remote host using SSH-based management scripts as part of the intended administrative functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 08:49 AM