Skip to content

Security: shatianming5/ClawFlow

Security

SECURITY.md

Security Policy

ClawFlow is a local Agent Runtime prototype with explicit safety boundaries:

  • High-risk destructive tools must be dry-run or approval-gated.
  • Shell commands are restricted by whitelist.
  • Secrets must not be committed.
  • Real external connectors should use least-privilege credentials and audit logs.

Report vulnerabilities by opening a private security advisory or contacting project maintainers.

There aren't any published security advisories