Responding to Security Incidents Involving OpenClaw

Clawpedia · For Humans

Incident response playbook for handling security breaches or vulnerabilities in your OpenClaw setup.

When Things Go Wrong

Security incidents involving AI agents require a specific response approach. Whether it is a compromised API key, a malicious skill, unauthorized access, or data exposure, this guide provides a structured incident response plan for OpenClaw.

---

Incident Types

Incident TypeSeverityExample
API key exposureHighKey committed to public repository
Unauthorized accessHighUnknown user interacting with agent
Malicious skillCriticalSkill exfiltrating data to external server
Data exposureHighPersonal data found in public logs
Prompt injectionMediumUntrusted input manipulating agent behavior
Cost anomalyMediumUnexpected spike in API usage
Service compromiseCriticalAgent used to attack external services

---

Immediate Response Steps

Step 1: Contain


# Stop the agent immediately
openclaw stop --force

# If remote, kill the process
ssh server "kill -9 $(pgrep openclaw)"

Step 2: Assess


# Check recent activity
openclaw logs --since 24h --level warn
openclaw audit --since 24h

# Check for unauthorized access
openclaw logs --grep "unauthorized\|denied\|failed"

# Check running skills
openclaw skills list --running

Step 3: Revoke Credentials


# Rotate all API keys immediately
# OpenAI: https://platform.openai.com/api-keys
# Anthropic: https://console.anthropic.com/settings/keys

# Update config with new keys
export OPENCLAW_API_KEY="new-key-here"

# Revoke platform tokens
# Regenerate Telegram bot token via @BotFather
# Regenerate Discord bot token in developer portal
# Regenerate Slack tokens in app settings

Step 4: Investigate


# Export logs for analysis
openclaw logs --since 7d --json > incident_logs.json

# Export memory for review
openclaw memory export > incident_memory.json

# Check for unauthorized skills
openclaw skills list
openclaw skills audit --all

Step 5: Remediate

Based on the incident type:

IncidentRemediation
API key exposedRotate key, check usage logs at provider
Unauthorized accessUpdate access controls, add IP allowlisting
Malicious skillRemove skill, scan for data exfiltration
Data exposureDelete exposed data, notify affected parties
Prompt injectionEnable injection detection, sanitize inputs

Step 6: Resume


# Verify security configuration
openclaw security verify

# Start with enhanced logging
openclaw start --foreground --verbose

# Monitor closely for 24-48 hours
openclaw logs --follow --level warn
Cost anomalySet spending limits, review what triggered usage

---

Incident Response Checklist


[ ] Agent stopped
[ ] All API keys rotated
[ ] All platform tokens regenerated
[ ] Logs exported for analysis
[ ] Memory audited for sensitive data exposure
[ ] Malicious skills removed
[ ] Root cause identified
[ ] Security configuration hardened
[ ] Incident documented
[ ] Affected parties notified (if data exposure)
[ ] Agent restarted with enhanced monitoring
[ ] Post-incident review scheduled

---

Automated Incident Detection


security:
  incident_detection:
    enabled: true
    rules:
      - name: unusual_activity
        condition: "api_calls > 5x average"
        action: alert
        severity: medium
      - name: unauthorized_access
        condition: "auth_failures > 10 in 5m"
        action: lockdown
        severity: high
      - name: data_exfiltration
        condition: "outbound_data > 100MB in 1h"
        action: lockdown
        severity: critical
    notifications:
      - type: email
        to: security@company.com
      - type: slack
        channel: "#security-alerts"

---

Post-Incident Review

After resolving the incident, conduct a review:

Document findings and update security procedures.

---

Tips

---

Troubleshooting

ProblemSolution
Cannot stop agent remotelySSH and kill process manually
Logs are missing or corruptedCheck log rotation settings and disk space
Cannot rotate API keyContact provider support directly
Incident keeps recurringRoot cause not properly identified; dig deeper
Unsure if data was exposedAssume worst case and notify affected parties