OpenClaw: suspicious
VirusTotal: suspicious
StaticScan: clean
OpenClaw: suspicious
文档声明“严格隔离、不读取全局配置或环境变量”,但随附的脚本实际读取 /root/.openclaw-zero/config.yaml、环境变量并写入 /root/.openclaw-zero/workspace/memory,说明文档与代码不一致,存在潜在信息暴露或越权写入风险。
VirusTotal: suspicious VT 报告
静态扫描: clean
No suspicious patterns detected.
README 未提供
无文件信息
{
"latestVersion": {
"_creationTime": 1773822505552,
"_id": "k9743pn4cmabn1drrvx9q4zws5834k1d",
"changelog": "- 强化了安全与隔离声明,新增“严格隔离配置说明”与隔离性验证方法\n- 明确声明不再读取任何全局配置\/环境变量,只允许本地 config.yaml\n- 明确所有数据仅写入本地 data\/ 文件夹,避免全局路径写入\n- 相关文档内容调整,突出隔离原则与用户迁移\/独立部署的便利性\n- 使用和功能未变,侧重文档安全合规升级",
"changelogSource": "auto",
"createdAt": 1773822505552,
"parsed": {
"clawdis": {
"author": "OpenClaw"
}
},
"version": "1.0.2"
},
"owner": {
"_creationTime": 0,
"_id": "publishers:missing",
"displayName": "sharkfee",
"handle": "sharkfee",
"image": "https:\/\/avatars.githubusercontent.com\/u\/131004036?v=4",
"kind": "user",
"linkedUserId": "kn7bwyt1ppcj1g2x30849cxer1829wb0"
},
"ownerHandle": "sharkfee",
"skill": {
"_creationTime": 1773820428656,
"_id": "kd79fz7b3tswfzdb0yhzaj7yc9834w21",
"badges": [],
"createdAt": 1773820428656,
"displayName": "AiCoin 币圈数据监控 - 30+项数据,完全独立,可定制简报,自动存储",
"latestVersionId": "k9743pn4cmabn1drrvx9q4zws5834k1d",
"ownerUserId": "kn7bwyt1ppcj1g2x30849cxer1829wb0",
"slug": "aicoin-monitor",
"stats": {
"comments": 0,
"downloads": 57,
"installsAllTime": 0,
"installsCurrent": 0,
"stars": 0,
"versions": 3
},
"summary": "AiCoin 币圈数据监控 - 30+项数据,完全独立,可定制简报,自动存储",
"tags": {
"latest": "k9743pn4cmabn1drrvx9q4zws5834k1d"
},
"updatedAt": 1774336994747
}
}