openclaw-tools
Warn
Audited by Socket on Mar 3, 2026
1 alert found:
AnomalyAnomalyreferences/en/tools/elevated.md
LOWAnomalyLOW
references/en/tools/elevated.md
No malicious code is present in this text fragment — it is documentation describing a privileged feature. However, the feature it describes (running exec on gateway host and an auto-approve "full" mode) is high-risk if implemented or configured incorrectly. Reviewers should ensure strict feature gating, accurate allowlist configuration (avoid accidental fallbacks), robust auditing/logging, and conservative defaults (feature off by default, require explicit per-agent allowlists) before enabling. Treat this as a security-sensitive capability, not malware.
Confidence: 90%Severity: 60%
Audit Metadata