High-risk tools in OpenClaw
35 of the 129 tools in OpenClaw are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
abortExecuteAbort active run
-
acpExecuteRun and manage ACP-backed coding agents
-
actionExecutestatus, start, pause, resume, complete, block, clear
-
agentExecuteRun one agent turn via the Gateway
-
authExecuteRun provider auth/login flow
-
bashExecuteRun a host command (if enabled).
-
browserExecuteManage OpenClaw
-
capabilityExecuteRun provider capability commands (fallback alias: infer)
-
chatExecuteOpen a local terminal UI (alias for tui --local)
-
commandExecuteShell command
-
completionExecuteGenerate shell completion script
-
crestodianExecuteOpen the interactive setup and repair assistant
-
cronExecuteSchedule and inspect Gateway background jobs
-
daemonExecuteManage the Gateway service (legacy alias)
-
doctorExecuteDiagnose and repair config, Gateway, plugin, and channel problems
-
elevatedExecuteToggle elevated mode (on|off).
-
events_waitExecuteWait for the next queued OpenClaw conversation event.
-
gatewayExecuteRun, inspect, and query the OpenClaw Gateway
-
inferExecuteRun provider-backed model, media, search, and embedding commands
-
newExecuteReset the session (/reset).
-
nodeExecuteRun and manage the headless node host service
-
nodesExecutePair nodes and run node-host commands through the Gateway
-
permissions_respondExecuteAllow or deny one pending OpenClaw exec or plugin approval request.
-
phoneExecuteArm/disarm high-risk phone node commands (camera/screen/writes).
-
pluginsExecuteInstall, enable, disable, and inspect plugins
-
proxyExecuteRun the OpenClaw debug proxy and inspect captured traffic
-
qaExecuteRun QA scenarios and launch the private QA debugger UI
-
restartExecuteRestart the gateway (if enabled).
-
sandboxExecuteManage sandbox containers for agent isolation
-
securityExecuteSecurity tools and local config audits
-
sessionExecuteSwitch session (or open picker)
-
stopExecuteStop the current run.
-
targetExecuteRun id, index, or session key
-
terminalExecuteOpen a local terminal UI (alias for tui --local)
-
tuiExecuteOpen a terminal UI connected to the Gateway
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.