New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

OpenClaw

Verified
NPMopenclaw
FRisk gradecritical blast radius
Last checked 91 days ago·Live handshake·Watched hourly for changes
Auth postureNot probedno remote endpoint probed yet
Tools1293 Destructive · 35 Execute · 41 Write · 37 Read · 13 Other
Worst categoryDestructivegrade tracks the peak, not the average
Capability mix
Destructive 3Execute 35Write 41Read 37Other 13
What it can reach
Ingests untrusted inputTouches secretsReaches networkRuns codeTouches filesChanges permissionsSends external commsPersistsDeletes dataMoves money
Exfiltration pathReads content an attacker can plant and can send data outward — a prompt-injection-to-exfiltration route.
Tools 129
dropDestructiveHighresetDestructiveHighuninstallDestructiveHighabortExecuteHighacpExecuteHigh
View all 129 tools
actionExecuteHighagentExecuteHighauthExecuteMediumbashExecuteCriticalbrowserExecuteHighcapabilityExecuteHighchatExecuteHighcommandExecuteCriticalcompletionExecuteMediumcrestodianExecuteMediumcronExecuteHighdaemonExecuteHighdoctorExecuteHighelevatedExecuteHighevents_waitExecuteMediumgatewayExecuteHighinferExecuteHighnewExecuteHighnodeExecuteHighnodesExecuteHighpermissions_respondExecuteHighphoneExecuteCriticalpluginsExecuteHighproxyExecuteHighqaExecuteMediumrestartExecuteHighsandboxExecuteHighsecurityExecuteHighsessionExecuteMediumstopExecuteMediumtargetExecuteHighterminalExecuteCriticaltuiExecuteHighactivationWriteMediumactive-memoryWriteMediumagentsWriteHighapprovalsWriteHighbackupWriteMediumcardWriteMediumchannelsWriteMediumcommitmentsWriteMediumcompactWriteLowconfigWriteHighconfigureWriteHighdebugWriteMediumdevicesWriteMediumdreamingWriteMediumfastWriteLowhooksWriteMediummatrixWriteHighmcpWriteHighmessageWriteMediummessages_sendWriteMediummigrateWriteHighnoteWriteLowonboardWriteMediumpairWriteMediumpairingWriteHighpathWriteHighqueueWriteMediumreasoningWriteLowsendWriteMediumsettingsWriteMediumsetupWriteMediumskillsWriteMediumtextWriteLowthinkWriteLowtraceWriteMediumupdateWriteHighusageWriteLowverboseWriteLowwebhooksWriteMediumwikiWriteMediumworkboardWriteMediumaskReadLowattachments_fetchReadLowcanvasReadMediumcommandsReadLowcontextReadLowconversation_getReadLowconversations_listReadLowdashboardReadLowdirectoryReadLowdnsReadLowdocsReadLowechoReadLowevents_pollReadLowexec-policyReadMediumgateway-statusReadLowgwstatusReadLowhealthReadLowhelpReadLowidReadLowinstructionsReadLowlogsReadLowmemoryReadLowmessages_readReadLowmodelReadLowmodelsReadLownameReadLowpermissions_list_openReadLowpingReadLowpolicyReadLowsecretsReadHighsessionsReadLowstatusReadLowsubagentsReadLowsystemReadLowtasksReadLowtranscriptsReadLowwhoamiReadLowcapOtherLowchannelOtherLowclawbotOtherLowdebounceOtherLowelevOtherLowexitOtherLowhostOtherLowinputOtherLowlevelOtherLowmodeOtherLowqrOtherLowquitOtherLowvalueOtherLow
Change history
No change history on record for this server. Watched servers surface a diff within the hour.
Recommended policy
uninstallrequire approval
droprequire approval
resetrequire approval
nodesrequire approval
Read-only toolsallow
Full policy breakdown with enforcement rules →

This record as markdown: /tools/openclaw.md — append .md to any tool or server page.

DIRECT INSTALL npx -y openclaw

Installed this way, nothing enforces the recommended policy above — calls run exactly as the agent makes them.

// LOOK UP ANOTHER SERVER

Every MCP server has a record like this.

Type a name, get the same breakdown: verified identity, auth posture, risk grade, capabilities, recommended policy.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.