openclaw-client-bootstrap
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The bootstrap and installation scripts fetch and execute installation scripts from official sources including NodeSource, Tailscale, and the primary vendor domain (openclaw.ai). These are standard procedures for installing the required runtime and security components.\n- [COMMAND_EXECUTION]: The toolkit utilizes system-level commands via
sudoandsystemctlto manage firewall rules, SSH security settings, and background services for the agent environment.\n- [EXTERNAL_DOWNLOADS]: Fetches software assets, GPG keys, and configuration templates from official repositories for Node.js, Docker, and Tailscale during the initialization of the client environment.\n- [DATA_EXFILTRATION]: Facilitates the secure transfer of API keys for integrated AI providers to the remote host using SSH-based management scripts as part of the intended administrative functionality.
Audit Metadata