We take security seriously. If you discover a vulnerability, please report it responsibly.
Do NOT create a public GitHub issue for security vulnerabilities.
Instead, please:
- Email: Open a private security advisory at GitHub Security
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Type of vulnerability (XSS, injection, etc.)
- Affected versions
- Proof of concept (if safe to share)
- Your contact info (optional)
- Initial response: Within 48 hours
- Status update: Weekly until resolved
- Fix timeline: Depends on severity (critical: 7 days, high: 30 days)
When using this tool:
- Verify archive checksums before importing
- Backup existing configuration before import
- Review manifest.json content
- Use
--mode=replicatefor sharing between machines
- Import archives from untrusted sources
- Use
--mode=fullwhen exporting sensitive data - Share your
~/.openclaw/directory publicly - Import without reviewing the manifest
| Version | Security Updates |
|---|---|
| 1.x.x | ✅ Active |
| < 1.0 | ❌ End of life |
We follow responsible disclosure:
- Report privately first
- Allow reasonable time to fix
- Coordinated public disclosure after fix
Thank you for keeping OpenClaw Migration Tool secure! 🔒