Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
86 lines
4.3 KiB
Markdown
86 lines
4.3 KiB
Markdown
---
|
|
summary: "How to contribute to the OpenClaw threat model"
|
|
title: "Contributing to the threat model"
|
|
read_when:
|
|
- You want to contribute security findings or threat scenarios
|
|
- Reviewing or updating the threat model
|
|
---
|
|
|
|
The [threat model](/security/THREAT-MODEL-ATLAS) is a living document. Contributions are welcome from anyone; you do not need security or MITRE ATLAS background.
|
|
|
|
<Note>
|
|
This is for adding to the threat model, not reporting live vulnerabilities. If you found an exploitable vulnerability, follow the responsible-disclosure instructions on the [Trust page](https://trust.openclaw.ai) instead.
|
|
</Note>
|
|
|
|
## Ways to contribute
|
|
|
|
**Add a threat.** Open an issue on [openclaw/trust](https://github.com/openclaw/trust/issues) describing the attack scenario in your own words. Helpful but not required:
|
|
|
|
- The attack scenario and how it could be exploited.
|
|
- Which components are affected (CLI, gateway, channels, ClawHub, MCP servers, etc.).
|
|
- Your estimate of severity (low / medium / high / critical).
|
|
- Links to related research, CVEs, or real-world examples.
|
|
|
|
Maintainers assign the ATLAS mapping, threat ID, and risk level during review.
|
|
|
|
**Suggest a mitigation.** Open an issue or PR referencing the threat. Be specific and actionable: "per-sender rate limiting of 10 messages/minute at the gateway" is more useful than "implement rate limiting."
|
|
|
|
**Propose an attack chain.** Attack chains show how multiple threats combine into a realistic scenario. Describe the steps and how an attacker would chain them; a short narrative beats a formal template.
|
|
|
|
**Fix or improve existing content.** Typos, clarifications, outdated info, better examples: PRs welcome, no issue needed.
|
|
|
|
## Framework reference
|
|
|
|
Threats are mapped to [MITRE ATLAS](https://atlas.mitre.org/) (Adversarial Threat Landscape for AI Systems), a framework for AI/ML-specific threats like prompt injection, tool misuse, and agent exploitation. You do not need to know ATLAS to contribute; maintainers map submissions during review.
|
|
|
|
**Threat IDs.** Each threat gets an ID like `T-EXEC-003`, assigned by maintainers during review.
|
|
|
|
| Code | Category |
|
|
| ------- | ------------------------------------------ |
|
|
| RECON | Reconnaissance - information gathering |
|
|
| ACCESS | Initial access - gaining entry |
|
|
| EXEC | Execution - running malicious actions |
|
|
| PERSIST | Persistence - maintaining access |
|
|
| EVADE | Defense evasion - avoiding detection |
|
|
| DISC | Discovery - learning about the environment |
|
|
| EXFIL | Exfiltration - stealing data |
|
|
| IMPACT | Impact - damage or disruption |
|
|
|
|
**Risk levels.** If you are unsure about the level, just describe the impact; maintainers assess it.
|
|
|
|
| Level | Meaning |
|
|
| ------------ | ----------------------------------------------------------------- |
|
|
| **Critical** | Full system compromise, or high likelihood + critical impact |
|
|
| **High** | Significant damage likely, or medium likelihood + critical impact |
|
|
| **Medium** | Moderate risk, or low likelihood + high impact |
|
|
| **Low** | Unlikely and limited impact |
|
|
|
|
## Review process
|
|
|
|
1. **Triage** - new submissions are reviewed within 48 hours.
|
|
2. **Assessment** - maintainers verify feasibility, assign ATLAS mapping and threat ID, validate risk level.
|
|
3. **Documentation** - formatting and completeness pass.
|
|
4. **Merge** - added to the threat model and visualization.
|
|
|
|
## Resources
|
|
|
|
- [ATLAS website](https://atlas.mitre.org/)
|
|
- [ATLAS techniques](https://atlas.mitre.org/techniques/)
|
|
- [ATLAS case studies](https://atlas.mitre.org/studies/)
|
|
|
|
## Contact
|
|
|
|
- **Security vulnerabilities:** [Trust page](https://trust.openclaw.ai) for reporting instructions, or `security@openclaw.ai`.
|
|
- **Threat model questions:** open an issue on [openclaw/trust](https://github.com/openclaw/trust/issues).
|
|
- **General chat:** Discord `#security` channel.
|
|
|
|
## Recognition
|
|
|
|
Contributors to the threat model are recognized in the threat model acknowledgments, release notes, and the OpenClaw security hall of fame for significant contributions.
|
|
|
|
## Related
|
|
|
|
- [Threat model](/security/THREAT-MODEL-ATLAS)
|
|
- [Incident response](/security/incident-response)
|
|
- [Formal verification](/security/formal-verification)
|