| Pre-install decision |
|---|
| | 84 · Manual review | 82 · Manual review |
|---|
| Clear source, High execution risk, OpenClaw | Clear source, High execution risk, Claude | Clear source, High execution risk, Claude |
|---|
| unexpected code execution, data exfiltration, memory context poisoning | prompt injection, tool poisoning, unexpected code execution | data exfiltration, human approval gap |
|---|
| missing license, broad permissions, shell without guardrails | missing license, broad permissions, shell without guardrails | missing license, broad permissions, network without allowlist |
|---|
| Source & provenance |
|---|
| openclaw/skills | openclaw/skills | openai/skills/tree/main/skills/.curated/security-ownership-map |
|---|
| Operations & Infra | Dev & Engineering | Data & Analytics |
|---|
|
|---|
| Risk & permission signals |
|---|
| network access, runs shell, writes files | network access, runs shell, writes files | writes files |
|---|
| verify source provenance before install | target os: macos, target os: linux, verify source provenance before install | registry access, remote metadata pull, runtime dependencies may be required |
|---|
| Install & compatibility |
|---|
| OpenClaw | Claude, Codex, Cursor, OpenClaw, Windsurf, GitHub Copilot | Claude, Codex, Cursor, Universal |
|---|
| script-backed | script-backed | registry-install |
|---|
| Community |
|---|
| 0 | 0 | |
|---|