Is jzOcb/config-guard safe?
Yes. jzOcb/config-guard is safe to install. Oathe's behavioral security audit gave the config-guard skill by jzOcb a trust score of 92/100 with 3 findings, none critical or high.
https://github.com/jzOcb/config-guard
Is jzOcb/config-guard safe to install?
This skill appears to be a legitimate configuration validation and safety tool for OpenClaw AI agents. It provides backup, validation, and rollback capabilities to prevent agents from breaking their configuration files. While it contains executable code and influences agent workflows, these appear to serve legitimate safety purposes rather than malicious intent.
What security issues were found in jzOcb/config-guard?
Category Scores
Findings (3)
MEDIUM Executable Shell Scripts Present -15 ▶
The skill contains shell scripts (config-guard.sh, safe-config-patch.sh, pre-config-hook.sh) that perform configuration management tasks. While these appear legitimate, executable code always carries inherent risk.
LOW Configuration File Access -10 ▶
Scripts access and modify OpenClaw configuration files, which is expected behavior for a configuration management tool but represents data access nonetheless.
LOW Workflow Instructions for AI Agents -5 ▶
The skill provides specific instructions to AI agents on mandatory workflows and commands to use. While appearing legitimate for safety purposes, this does influence agent behavior.
Should I install jzOcb/config-guard?
Oathe's verdict for jzOcb/config-guard is SAFE with a trust score of 92/100. Recommendation: Install.