| Pre-install decision |
|---|
| 85 · Evidence missing | | |
|---|
| Clear source, High execution risk, Universal | Clear source, High execution risk, OpenClaw | Clear source, High execution risk, OpenClaw |
|---|
| prompt injection, tool poisoning, unexpected code execution | unexpected code execution, data exfiltration, memory context poisoning | unexpected code execution, identity privilege abuse, data exfiltration |
|---|
| Permission review, Network, Secrets, Command | Permission review, Network, Command | Permission review, Network, Secrets, Command |
|---|
| | 67% | 67% |
|---|
| Source & provenance |
|---|
| Design & Content | Operations & Infra | Dev & Engineering |
|---|
| 2026-04-02 | 2026-03-29 | 2026-03-31 |
|---|
| Risk & permission signals |
|---|
| needs credentials, network access, runs shell, writes files | network access, runs shell, writes files | needs credentials, network access, runs shell, writes files |
|---|
| verify source provenance before install | verify source provenance before install | requires binary: node, requires binary: npx, requires binary: gp-cli, verify source provenance before install |
|---|
| Install & compatibility |
|---|
| Universal | OpenClaw | OpenClaw |
|---|
| 65 | | 65 |
|---|