Security

What lnk-openclaw installs and runs, beyond what Link's sandbox guarantees every harness (Link's Agents Security page).

Installing it

  • It runs OpenClaw's official installer, what openclaw.ai/install-cli.sh serves, pinned: the script comes from OpenClaw's repository at a release's commit, and runs only if its SHA-256 is the one in this adapter's source.
  • It installs that release with --version, from npm, which checks the package against the registry's hash.
  • It runs over HTTPS, in the home and the sandbox: it can download anything, but write only the home.
  • OpenClaw's npm dependencies are resolved at install time, since the package ships no lockfile: they aren't pinned.
  • It brings its own Node, checked against Node's published checksums, with no Homebrew, no onboarding and no service of its own.
  • A new OpenClaw release comes with a release of this adapter.

Running it

  • Link generates a token for OpenClaw's local gateway, on 127.0.0.1, passed to openclaw config set on its command line. The model's key and the channels' tokens go in ~/.openclaw/.env in its home, never on a command line.
  • Its workspace, its log and what links WhatsApp (~/.openclaw/credentials/whatsapp) are in its home. Its mDNS is off and it runs with OPENCLAW_DISABLE_BONJOUR=1, so it doesn't announce itself on your network.
  • Signal's signal-cli asks for no credential, so on a Mac, where a harness's ports are on the machine's loopback, it listens on a unix socket in OpenClaw's home (700), signal-cli.sock, which only you can reach. OpenClaw checks before each connection that the socket and its folder are yours alone. A home whose path is longer than a socket's can be (103 bytes, about 47 characters of user and agent name together) keeps the port, open to every user and program of the Mac, and lnk agent start warns that it does: a shorter agent name keeps it on the socket. On Linux it listens on a port in the agent's block, which behind its proxy stays in the sandbox's own network; with lan, or without the sandbox, every user and program of the machine can reach it.
  • The canvas is on the gateway's port, behind its token, and so is browser control, which has no port of its own. Its extension relay starts at the first browser call, on the gateway's port +10, and asks for a token too; behind the proxy it can't take that port, so it doesn't start.
  • The managed browser's debugging port asks for no credential, and is on the machine's loopback while the browser runs. On a Mac the sandbox gives OpenClaw no browser to run (it looks for Chrome in /Applications, which the sandbox closes), so it opens only without the sandbox: with OpenAI on a Mac, or when you turn the sandbox off.
  • Without the sandbox, or on Linux with lan, its browser is off unless you allow it. Link tells lnk-openclaw whether it runs behind its proxy; where its browser's ports would be on the machine's loopback (no sandbox anywhere; on Linux, lan too, which Slack and Discord need), lnk-openclaw needs names it, browser, and the start asks in a terminal; no, --yes, or no terminal leaves it off (browser.enabled: false in its config) and OpenClaw runs without it. A yes in a terminal, or lnk agent openclaw allow browser, turns it on: then its debugging port, and its extension relay's, are open to every user and program of the machine while it runs. In the sandbox on a Mac, and behind its proxy on Linux, it stays on.
  • Slack needs lan, so with Slack or Discord it asks for lan before it starts, and once allowed runs without the proxy's filtering (Limits).
  • With OpenAI on a Mac it asks for no sandbox at all: Codex's runtime runs ps, which no sandbox on macOS runs. Allowed, it reads your whole home folder, and every start warns.
  • With WhatsApp on your own number, it answers only an @mention in a group, not a reply.

Its ports

Its gateway, 18789 for main (another agent's is in its own block), and the ports OpenClaw derives from it: +2 to +4 (browser control on +2, when it has a port of its own), the managed browsers' debugging ports (+11 to +110), and signal-cli's (+5) where it listens on a port: on Linux, or on a Mac whose home path is too long for its socket. These, and a local model's, are the localhost ports the sandbox lets it connect to.

Outside its home

Unsandboxed, OpenClaw writes ~/.openclaw, ~/openclaw, ~/.local/bin/openclaw, its own service (the LaunchAgent ai.openclaw.gateway, or the systemd unit openclaw-gateway.service), /tmp/openclaw and /tmp/openclaw-state-locks-<uid>. lnk agent openclaw show looks for these; lnk agent openclaw remove removes them with its home. Its own service would run outside the sandbox, so lnk agent start stops it and moves it aside (*.lnk-off): Link runs OpenClaw.