| Cost anomaly | Medium | Unexpected spike in API usage |
| Service compromise | Critical | Agent used to attack external services |
---
Immediate Response Steps
Step 1: Contain
# Stop the agent immediately
openclaw stop --force
# If remote, kill the process
ssh server "kill -9 $(pgrep openclaw)"
Step 2: Assess
# Check recent activity
openclaw logs --since 24h --level warn
openclaw audit --since 24h
# Check for unauthorized access
openclaw logs --grep "unauthorized\|denied\|failed"
# Check running skills
openclaw skills list --running
Step 3: Revoke Credentials
# Rotate all API keys immediately
# OpenAI: https://platform.openai.com/api-keys
# Anthropic: https://console.anthropic.com/settings/keys
# Update config with new keys
export OPENCLAW_API_KEY="new-key-here"
# Revoke platform tokens
# Regenerate Telegram bot token via @BotFather
# Regenerate Discord bot token in developer portal
# Regenerate Slack tokens in app settings
Step 4: Investigate
# Export logs for analysis
openclaw logs --since 7d --json > incident_logs.json
# Export memory for review
openclaw memory export > incident_memory.json
# Check for unauthorized skills
openclaw skills list
openclaw skills audit --all
Step 5: Remediate
Based on the incident type:
| Incident | Remediation |
| API key exposed | Rotate key, check usage logs at provider |
| Unauthorized access | Update access controls, add IP allowlisting |
| Malicious skill | Remove skill, scan for data exfiltration |
| Data exposure | Delete exposed data, notify affected parties |
| Prompt injection | Enable injection detection, sanitize inputs |
| Cost anomaly | Set spending limits, review what triggered usage |
Step 6: Resume
# Verify security configuration
openclaw security verify
# Start with enhanced logging
openclaw start --foreground --verbose
# Monitor closely for 24-48 hours
openclaw logs --follow --level warn
---
Incident Response Checklist
[ ] Agent stopped
[ ] All API keys rotated
[ ] All platform tokens regenerated
[ ] Logs exported for analysis
[ ] Memory audited for sensitive data exposure
[ ] Malicious skills removed
[ ] Root cause identified
[ ] Security configuration hardened
[ ] Incident documented
[ ] Affected parties notified (if data exposure)
[ ] Agent restarted with enhanced monitoring
[ ] Post-incident review scheduled
---
Automated Incident Detection
security:
incident_detection:
enabled: true
rules:
- name: unusual_activity
condition: "api_calls > 5x average"
action: alert
severity: medium
- name: unauthorized_access
condition: "auth_failures > 10 in 5m"
action: lockdown
severity: high
- name: data_exfiltration
condition: "outbound_data > 100MB in 1h"
action: lockdown
severity: critical
notifications:
- type: email
to: security@company.com
- type: slack
channel: "#security-alerts"
---
Post-Incident Review
After resolving the incident, conduct a review:
- Timeline — What happened and when?
- Root cause — How did it happen?
- Impact — What data or systems were affected?
- Response — How effectively did we respond?
- Prevention — What changes prevent recurrence?
Document findings and update security procedures.
---
Tips
- Have a response plan ready before an incident occurs.
- Practice incident response with simulated scenarios.
- Rotate credentials regularly to limit exposure windows.
- Enable automated detection to catch incidents early.
- Keep offline backups of critical configurations.
- Know your provider contacts — OpenAI, Anthropic, etc. have abuse reporting channels.
---
Troubleshooting
| Problem | Solution |
| Cannot stop agent remotely | SSH and kill process manually |
| Logs are missing or corrupted | Check log rotation settings and disk space |
| Cannot rotate API key | Contact provider support directly |