Secure development
This guide covers the practices contributors follow while writing code. For reporting a vulnerability, the trust model and operator hardening, see the Security section of the docs site.Secrets and placeholders
- Never commit real phone numbers, API tokens, videos, or live config values. Use obviously fake placeholders.
- Docs content must be generic. Do not include personal device names, hostnames, or paths. Use placeholders such as
user@gateway-host. - Read the security policy before any security triage or advisory work.
Local credential files
- Web provider credentials live in
~/.openclaw/credentials/. Rerunwednesdayai loginif you are logged out. - Pi and agent sessions live in
~/.openclaw/agents/<agentId>/sessions/*.jsonl(newest by default).
Security scanning
The project usesdetect-secrets for automated secret detection in CI. See .detect-secrets.cfg for configuration and .secrets.baseline for the baseline.
Run it locally:
Dependency policy
- Dependencies listed in
pnpm.patchedDependenciesmust use exact versions (no^or~). Patching a dependency requires explicit approval. @sinclair/typeboxis pinned to an exact version for the same reason.- Never update the Carbon dependency (
@buape/carbon). - Never use
npm linkorpnpm linkfor local installs. Build withnpm packand install the tarball globally.