safe-execSafe command execution for OpenClaw Agents with automatic danger pattern detection, risk assessment, user approval workflow, and audit logging. Use when agen...
Install via ClawdBot CLI:
clawdbot install ottttto/safe-execGrade Excellent — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/sys/Calls external URL not in known-safe list
https://github.com/OTTTTTO/safe-exec.gitAI Analysis
The skill's primary function is to add safety controls and audit logging for shell command execution, which is a legitimate security enhancement. The external URL is for cloning the skill's source code from a public GitHub repository, which is a standard installation method and not indicative of runtime data exfiltration. No evidence of credential harvesting, hidden instructions, or obfuscated malicious behavior was found in the provided definition.
Generated Mar 1, 2026
Integrate SafeExec into CI/CD pipelines to automatically intercept and log potentially destructive commands like rm -rf or system modifications. This ensures automated deployments have oversight, preventing accidental data loss while maintaining audit trails for compliance.
Use SafeExec for system administrators managing servers, where commands like dd or chmod 777 require approval. It provides real-time risk assessment and logging, reducing human error in critical operations and enhancing security posture.
Deploy SafeExec in automated data processing scripts to safely handle file deletions or system calls. It allows data scientists to run risky commands with oversight, logging all actions for reproducibility and risk management.
Implement SafeExec in computer labs or training sessions to teach command-line operations safely. It intercepts dangerous commands like fork bombs, providing a controlled learning environment with audit logs for instructor review.
Utilize SafeExec in regulated industries to enforce approval workflows for high-risk commands. It automatically logs all executions, helping organizations meet compliance requirements for system changes and data handling.
Offer SafeExec as a free, open-source tool with paid enterprise support, customization, and advanced features. Revenue comes from consulting, training, and premium support contracts for large organizations needing enhanced security.
Develop a cloud-based version of SafeExec that integrates with popular DevOps tools like Jenkins or Kubernetes. Charge subscription fees based on usage tiers, providing centralized audit logs and team management features.
Market SafeExec as a compliance solution for industries with strict regulatory requirements. Sell licenses to companies needing automated risk assessment and audit trails, with revenue from one-time purchases or annual renewals.
💬 Integration Tip
Start by enabling SafeExec in non-critical environments to test its interception workflow, then integrate it into automated scripts using the OPENCLAW_AGENT_CALL variable for seamless agent support.
Scored Apr 19, 2026
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.