safe-exec
Enables secure command execution for OpenClaw Agents with risk assessment and user approval, ensuring safe automation of shell commands.
Install this skill
Security score
The safe-exec skill was audited on Jun 4, 2026 and we found 15 security issues across 4 threat categories, including 1 critical. Review the findings below before installing.
Categories Tested
Security Issues
Piping content to bash shell
| 136 | **HIGH**: User data deletion or significant system changes (chmod 777, curl | bash) |
Webhook reference - potential data exfiltration
| 266 | - ❌ No integration with external notification services (Feishu, webhooks, etc.) |
Access to hidden dotfiles in home directory
| 9 | "writes": ["~/.openclaw/safe-exec/", "~/.openclaw/safe-exec-audit.log"], |
Access to hidden dotfiles in home directory
| 76 | git clone https://github.com/OTTTTTO/safe-exec.git ~/.openclaw/skills/safe-exec |
Access to hidden dotfiles in home directory
| 79 | chmod +x ~/.openclaw/skills/safe-exec/safe-exec*.sh |
Access to hidden dotfiles in home directory
| 82 | ln -s ~/.openclaw/skills/safe-exec/safe-exec.sh ~/.local/bin/safe-exec |
Access to hidden dotfiles in home directory
| 83 | ln -s ~/.openclaw/skills/safe-exec/safe-exec-*.sh ~/.local/bin/ |
Access to hidden dotfiles in home directory
| 100 | - Requests stored in: `~/.openclaw/safe-exec/pending/` |
Access to hidden dotfiles in home directory
| 101 | - Audit log: `~/.openclaw/safe-exec-audit.log` |
Access to hidden dotfiles in home directory
| 102 | - Rules config: `~/.openclaw/safe-exec-rules.json` |
Access to hidden dotfiles in home directory
| 209 | cat ~/.openclaw/safe-exec-audit.log |
Access to hidden dotfiles in home directory
| 232 | - SafeExec version (run: `grep "VERSION" ~/.openclaw/skills/safe-exec/safe-exec.sh`) |
Access to hidden dotfiles in home directory
| 236 | - Relevant logs from `~/.openclaw/safe-exec-audit.log` |
Access to hidden dotfiles in home directory
| 249 | Log location: `~/.openclaw/safe-exec-audit.log` |
External URL reference
| 281 | - **ClawdHub:** https://www.clawhub.ai/skills/safe-exec |