µ±AI¸±ÊÖÔì³É¡°ÌØÂåÒÁľÂí¡±£ºOpenClaw°²È«Î£»úÖÇʾ¼
°ä²¼¹¦·ò 2026-03-11¡°ÎªÖÇÄÜʱÆÚÁ¢ÐÅ£¬Îª´´Ð¼ÛÖµ»¤º½¡£¡ª¡ª ±¦ÔËÀ³¹Ù·½ÍøÕ¾¡±
2026Äê3Ô£¬±»ÓþΪ"Ôö³¤×î¿ìµÄ¿ªÔ´AI AgentÏîÄ¿"µÄOpenClawÔâ·êÑϸñ°²È«¿¼Ñé¡£°²È«×êÑÐÕßÔڶ̹¦·òÄÚ×·×Ùµ½Õë¶ÔÆäÓû§µÄÈ«Á´Ìõ¹¥»÷¾ØÕ󣺹¥»÷Õßͨ¹ýNPM¶ñÒâÒÀÀµ°ü¡¢Î±ÔìGitHub×é¼þ²Ö¿âÖ´Ðй©¸øÁ´Í¶¶¾£¬²¢ÀûÓÃÈÏÖ¤½ÚÔìÂ߼ȱµãʵÏÖÉøÈë¡£ÕâһϵÁнṹ»¯¹¥»÷Åú×¢£¬Õë¶ÔOpenClawµÄ³£Ì¬»¯¡¢µÍÃż÷ÉøÈëÄÜÁ¦ÒÑÐγɡ£
¸üÁîÈËÓÇÓôµÄÊǶ³öÃæ¡£¾ÝOpenClaw Exposure Watchboard×îÐÂ²â»æÊý¾Ý£¨2026Äê3ÔÂ10ÈÕ£©£¬È«ÇòÒÑÓг¬¹ý27Íò¸öOpenClawÊ·ý¶³öÔÚ¹«Íø£¬ÆäÖÐÔ¼40%ÓëÒÑÖªAPT×éÖ¯´æÔÚ¹ØÁª¡£³¯ÏʵÄAPT37¡¢Kimsuky£¬¶íÂÞ˹µÄAPT28¡¢Sandworm TeamµÈ¹ú¶È¼¶¹¥»÷ÕßÔÚ»ý¼«ÀûÓÃÕâЩ±©Â©µÄ½Úµã¡£Ã¿Ò»Ì¨±»¹¥ÏµÄÖ÷»ú£¬¶¼¿ÉÄܳÉΪËûÃÇÉî¿ÌÆóÒµÄÚÍøµÄÌø°å¡£
±¾»ã±¨½«ÏµÍ³ÊáÀíÕâЩ¹¥»÷ÊÂÎñµÄ¼¼Êõϸ½Ú£¬·Ö½âµ±Ç°°²È«¼Ü¹¹ÖеÄÓÄ΢»·½Ú£¬²¢Îª·ÖÆçÓû§ÈºÌåÌṩ¿ÉÂ䵨µÄ·ÀÓù½¨Òé¡£ÎÒÃǵ«Ô¸Í¨¹ýÕâ·Ý»ã±¨£¬Ô®ÊÖ¿Í»§³ÉÁ¢´ÓÍþвÈÏÖªµ½·çÏÕ»º½âµÄÆëȫ֪ʶ¿ò¼Ü¡£
AI AgentʱÆÚµÄ°²È«ÐÂÌôÕ½
1¡¢Ê§¿ØµÄÔö³¤Óëʧ¿ØµÄ·çÏÕ
2026Äê1ÔµÄ×îºóÒ»ÖÜ£¬OpenClawÔÚGitHubÉϵ¥ÈÕÕ¶»ñ25,000¿ÅStar£¬´´ÔìÁË¿ªÔ´ÏîÄ¿º¹ÇàÉÏǰËùδÓеÄÔö³¤¼Í¼¡£µ½±¾Îİ䲼ʱ£¬ÕâÒ»Êý×ÖÒѾìÉýÖÁ296,000¡£¹è¹ÈµÄͶ×ÊÈ˳ÆÖ®Îª"ÏÂÒ»¸öChatGPTʱ¿Ì"£¬¿ª·¢ÕßÉçÇøÎªÖ®·ÐÌÚ£¬ÎÞÊý¼¼Êõ°®ºÃÕ߯ðÍ·ÔÚ×Ô¼ºµÄµçÄÔÉϲ¿ÊðÕâ¸ö¸³ÓèAI"ÉϵÛģʽ"µÄ¸±ÊÖ¡£

ͼ1 OpenClaw StarÔö³¤ÇúÏßͼ
ͼ1չʾÁË2026Äê1ÔÂÖÁ3ÔÂÆÚ¼ä£¬OpenClawÏîÄ¿GitHub StarÊýÁ¿´Ó0¼±¾çÔö³¤ÖÁ296,000µÄ¾ªÈËÇúÏߣ¬Ö±¹Û³öÏÖÁË"Ê·ÉÏÔö³¤×î¿ì¿ªÔ´ÏîÄ¿"µÄÊý¾Ý¡£µ«ºÜÉÙÓÐÈËÒâʶµ½£¬µ±Ò»¸öAI´úÀíÄܹ»²»ÊÜÏ޶ȵضÁдÄãµÄÎļþ¡¢·¢ËÍÄãµÄÐÂÎÅ¡¢½ÚÔìÄãµÄÖÕ¶Ëʱ£¬Ã¿Ò»´Î°²È«·ì϶¶¼¿ÉÄÜÒâζ×Å¿àÄÑÐԵĺó¹û¡£
ÈýÀà¶ÁÕߣ¬ÇëÕÒµ½ÊôÓÚÄãµÄ·çÏÕ»Ïñ£º
ÈôÊÇÄãÊÇÒ»Ãûͨ³£Óû§£¬ÄãµÄiMessage¡¢WhatsApp¡¢ÒøÐÐÑéÖ¤Âë¡¢¼ÓÃÜÇ®±ÒÇ®°ü¿ÉÄÜÕý´¦ÓÚΣÏÕÖ®ÖС£¹¥»÷ÕßÒѾ¿ª·¢³öרÃÅÕë¶ÔOpenClawÅäÖõÄÐÅÏ¢ÇÔÈ¡·¨Ê½£¬Ò»µ©ÄãµÄµçÄÔ±»ÈëÇÖ£¬ËùÓÐÕâЩÃô¸ÐÊý¾Ý¶¼½«³ÉΪÄÒÖÐÖ®Îï¡£
ÈôÊÇÄãÊÇÒ»Ãû¿ª·¢Õߣ¬ÄãµÄGitHubÁîÅÆ¡¢AWSƾ֤¡¢DockerÃÜÔ¿¿ÉÄÜÒѾ¶³ö¡£¶à¸öºÚ¿Í×éÖ¯ÔÚ×Ô¶¯É¨Ã軥ÁªÍøÉϵÄOpenClawÊ·ý£¬Ñ°ÕÒÄÇЩÅäÖò»µ±µÄ²¿Ê𣬶øºóÉÏ´«´øºóÃŵÄ"¼¼Êõ"À´ÇÔÈ¡ÄãµÄ¿ª·¢»·¾³½Ó¼ûȨÏÞ¡£
ÈôÊÇÄãÕÆ¹ÜÆóÒµ°²È«£¬Äã±ØÒªÁ¢¼´Ðж¯¡£×êÑÐÏÔʾ£¬³¬¹ý40,000¸öOpenClawÊ·ý¶³öÔÚ¹«¹²»¥ÁªÍøÉÏ£¬ÆäÖÐ63%Äܹ»±»µÈÏÐÀûÓᣵ±¹¥»÷Õßͨ¹ýÒ»¸ö´¹µöÁ´½Ó¾ÍÄÜÔÚÔ±¹¤µçÄÔÉϲ¿ÊðºóÃÅʱ£¬Õû¸öÄÚÍø¶¼½«´¦ÓÚΣÏÕÖ®ÖС£
2¡¢OpenClaw³ÉΪ¹¥»÷Ö¸±êµÄÉî²ãÔÒò
Õâ²¢·ÇºÚÌì¶ìÊÂÎñ£¬¶øÊÇ´«Í³Ììǵ·ÀÓùÄ£ÐÍÓëAI AgentÌìȻ˵»°Çý¶¯ÀíÏë²úÉú·¶Ê½Ä¦²ÁµÄ±ØÈ»¼ÛÖµ¡£
ÒÔÍùµÄ°²È«Æ¥µÐÒÀÀµÓÚÑϸñµÄÈíÓ²¼þɳÏä»úÔìÓë¿ç¹ý³ÌÄÚ´æ¸ôÀ룬¶øAI AgentµÄÇý¶¯Ö÷ÌâÊÇ´ó˵»°Ä£Ð͵ÄÓïÒåÀí½â¡£¹¥»÷ÔØºÉ±»Ö±½Ó±àÂëÔÚÌáÐÑ´ÊÐòÁлòÖ¸ÁÄÚ£¬ÕâÖ±½Ó»÷´©ÁË´«Í³µÄ¹æ¶¨Æ¥ÅäÓëɳºÐ¸ôÀë·À»¤ÏµÍ³¡£
OpenClaw¹ýÓÚ¿í·ºµÄ¡°È¨ÏÞ¼´·þÎñ¡±Éè¼ÆÀíÏë·Å´óÁËÕâÒ»´àÈõÐÔ¡£ÆäÉú̬Éè¼ÆÀíÂÛÉÏÔÊÐíÖ±½Ó¿çºÍ̸ŲÓÃÓëÎÞÏ޶ȵÄÖն˲Ù×÷£¬ÕâÒ»¸öÐÔÔÚÂú×ã¸ß¶È×ÔÓɶ¨ÔìµÄͬʱ£¬Ò²Ê¹Æä³ÉΪÁ˺ڿͽøÐÐPayload×é×°¹¥»÷µÄÌìÈ»¡°È⼦¡±¡£ ´Ë±í£¬³äÈβå¼þ¼¯É¢µØµÄClawHubÊг¡ÑϳÁ²»×㰲ȫ×óÒÆµÄ»ù´¡ÉóºË»úÔì¡£×êÑÐÈËÔ±Åû¶£¬ÔçÆÚ³¬¹ý800¸ö¶ñÒâ×é¼þ³É¹¦Éϼܣ¬³äÈÎÁ˻Ҳú¼°¹©¸øÁ´´«È¾µÄδ²¡£½áºÏ½üÆÚÊý¾ÝÏÔʾµÄ37.2%µÄÍ´´¦Ð¹Â¶Âʼ°¾ÞÁ¿Â¶³öÃæÎÊÌ⣨Ïê¼ûµÚ¶þÕ£©£¬OpenClawÒѳÉΪȫÇò¹¥»÷ÕßÑÛÖеĸ߼ÛÖµ°Ð»ú³Ø¡£
¸üÁîÈËÓÇÓôµÄÊDzúÆ·µÄµü´úËÙ¶È¡£´ÓClawdbotµ½MoltbotÔÙµ½OpenClaw£¬Õâ¸öÏîÄ¿Ôڶ̶ÌÈýÖÜÄÚ¾ÀúÁËÁ½´Î¸ÄÃû£¬Ã¿´Î¸ÄÃû¶¼Åã°é×ÅеÄÖ°ÄÜÉÏÏߺͰ²È«»úÔìµÄ³ÁÐÂÉè¼Æ¡£ÕâÖÖ½üºõ¿ñÒ°µÄ¿ª·¢½ÚÅĹÌÈ»Âú×ãÁËÓû§¶ÔÐÂÖ°ÄܵİÍÍû£¬µ«Ò²Èð²È«É󼯳ÉΪÁËÒ»¸ö²»³ÉÄÜʵÏֵŤ×÷¡£
ClawHubÊг¡µÄ´æÔÚÈÃÎÊÌâÑ©ÉϼÓ˪¡£Õâ¸öÔÊÐíÓû§×ÔÓÉÉÏ´«"¼¼Êõ"µÄÊг¡£¬±¾ÒâÊdzÉÁ¢Ò»¸ö·á˶µÄ²å¼þÉú̬ϵͳ£¬µ«ÓÉÓÚ²»×ãÓÐЧµÄÉóºË»úÔ죬ËüѸËÙ³ÉΪÁ˶ñÒâ´úÂëµÄ¼¯É¢µØ¡£×êÑÐÈËÔ±·¢ÏÖ£¬Ôڶ̶̼¸ÖÜÄÚ¾ÍÓг¬¹ý800¸ö¶ñÒâ¼¼Êõ±»ÉÏ´«µ½Êг¡£¬ÆäÖÐÏ൱һ²¿Ãųɹ¦ÆÈ¡ÁËÓû§µÄÐÅÀµ¡£
×îºóÊǶ³öÃæµÄʧ¿Ø¡£µ±Óû§½«OpenClaw²¿Êðµ½ÔÆ·þÎñÆ÷ÒÔ±ãËæÊ±½Ó¼ûʱ£¬ËûÃÇ¿ÉÄÜûÓÐÒâʶµ½×Ô¼ºµÄµçÄÔÒѾ³ÉΪÁË»¥ÁªÍøÉϵÄÒ»¸ö»î°Ð×Ó¡£Æ¾¾Ý2026Äê3ÔÂ10ÈÕµÄ×îÐÂɨÃèÊý¾Ý£¬È«Çò¹²ÓÐ273,548¸öOpenClawÊ·ý¶³öÔÚ»¥ÁªÍøÉÏ£¬ÆäÖÐ37.2%´æÔÚÍ´´¦Ð¹Â¶£¬40.7%ÓëÒÑÖªÍþв×éÖ¯´æÔÚ¹ØÁª¡£¾ßÌåÊý¾Ý½«ÔÚµÚ¶þÕµÚ4½Ú"È«Çò¶³öÌ¬ÊÆ"ÖÐÏêÊö¡£
3¡¢±¾»ã±¨µÄÈý¸öÖ÷Ìâά¶È
±¾»ã±¨ÖØÒª×ñÑÈý²ã½â¹¹½øÐУºÊ×Ïȸ´ÅÌÒÑ´¥·¢µÄ¹©¸øÁ´´«È¾¡¢ÈÏÖ¤»úÔìÈÆ¹ý¼°¹æÄ£»¯Êý¾Ý±íйµÈ±êÖ¾ÐÔ°²È«ÊÂÎñ£»Æä´ÎÏòÏÂ×êÈ¡AI Agentµ××ùÉè¼ÆµÄ°²È«»ý±×ÓëÐÅÀµÁ´×è¶Ï£»×îºóÊä³öÃæÏò¶à·½½ÇÉ«µÄ¹¤³Ì»¯»º½â¹æ»®¡£
ÕæÊµ¹¥»÷ÊÂÎñÉî¶È·Ö½â
1¡¢¹©¸øÁ´¹¥»÷µÄ¶à²ãÉøÈë
ÈôÊÇÄãÒÔΪֻ´Ó¹Ù·½Çþ·ÏÂÔØÈí¼þ¾Í×ã¹»°²È«£¬ÄÇOpenClawµÄ¹ÊÊ»áÈÃÄã³ÁÐÂ˼ÂÇÕâ¸öÈç¹û¡£

ͼ2 ¹©¸øÁ´¹¥»÷Á´Â·
ͼ2չʾÁËÕë¶ÔOpenClawÓû§µÄµäÐ͹©¸øÁ´¹¥»÷Á´Â·£º´Ó¶ñÒâNPM°üÉÏ´«¡¢Óû§×°ÖᢼÙCLI½çÃæÓÕµ¼¡¢KeychainÇÔÈ¡¡¢µ½×îÖÕÊý¾Ý±í´«µÄÆëÈ«¹¥»÷Á÷³Ì¡£
¼Ù×°NPM°üµÄ¹¥»÷ÊÇÕⳡ¹©¸øÁ´Ø¬Ãεijõ²½¡£2026Äê3Ô£¬JFrog°²È«×êÑÐÍŶÓÅû¶ÁËһ·Õë¶Ô¿ª·¢ÕßȺÌåµÄGhostClaw¹©¸øÁ´¹¥»÷ÊÂÎñ¡£¹¥»÷ÕßÔÚnpm²Ö¿â°ä²¼¶ñÒâÈí¼þ°ü @openclaw-ai/openclawai£¬¸ÃÈí¼þ°ü¼ÙװΪºÏ·¨AI¿ª·¢¹¤¾ß OpenClaw µÄÓйØ×é¼þ£¬ÓÕµ¼¿ª·¢ÕßÏÂÔØ×°Öá£Ò»µ©¿ª·¢ÕßÔÚ±¾µØ»·¾³ÖÐ×°ÖøÃÒÀÀµ£¬¶ñÒâ´úÂë±ã»áÔÚÈí¼þ×°Öý׶Î×Ô¶¯Ö´ÐУ¬´Ó¶øÊµÏÖ¶Ô¿ª·¢ÕßÖն˵ijõʼÈëÇÖ¡£

ͼ3 ¡°@openclaw-ai/openclawai¡±°ü¾ßÌåÐÅÏ¢
¹¥»÷µÄ¾«ÃîÖ®´¦ÔÚÓÚËüµÄÉç»á¹¤³ÌѧÉè¼Æ¡£µ±Óû§×°ÖÃÕâ¸ö°üʱ£¬Ëü»áÏÔʾһ¸ö¾«ÐÄÔì×÷µÄ¼ÙºÅÁîÐнçÃæ£¬´øÓж¯»½ø¶ÈÌõ£¬ÈÃÈËÏàÐÅOpenClawÔÚ±»×°Öá£×°ÖÃʵÏֺ󣬾籾»áµ¯³öÒ»¸öαÔìµÄiCloud KeychainÊÚȨÌáÐÑ¿ò£¬ÒªÇóÓû§ÊäÈëϵͳÃÜÂë¡£Óë´Ëͬʱ£¬¶ñÒâ´úÂëÔÚºó¶Ü͵͵Óë¹¥»÷ÕߵĺÅÁî½ÚÔì·þÎñÆ÷ͨѶ¡£

ͼ4 ÐéαµÄ×°ÖýçÃæÓëÊÚȨÌáÐÑÈÏÖ¤
ÔÚÓû§½»»¥¹ý³ÌÖУ¬¶ñÒⷨʽ»á´Ó¹¥»÷Õß½ÚÔìµÄ·þÎñÆ÷trackpipe[.]devÏÂÔØµÚ¶þ½×¶Î¼ÓÃÜÔØºÉ£¬²¢Í¨¹ý½âÃܺóÔÚºó¶ÜÖ´ÐС£¸ÃÔØºÉÄÚ²¿×é¼þ±»¶¨ÃûΪ GhostLoader£¬ÄÚ²¿´úÂë¹æÄ£½Ï´ó£¬¾ß±¸ÐÅÏ¢ÇÔÈ¡ºÍÔ¶³Ì½ÚÔìÄÜÁ¦¡£

ͼ5 ¼ÓÃܵĵڶþ½×¶ÎÔØºÉÄÚÈÝ
³É¹¦Ï°È¾ºó£¬¶ñÒⷨʽ»áÔÚ°µ²ØÄ¿Â¼ÖгÉÁ¢Óƾû¯»úÔ죨ÈçshellÆô¶¯¾ç±¾»òcron¹¤×÷£©£¬²¢²¿Êð¾ß±¸Ô¶³ÌºÅÁîÖ´ÐÓ×¢SOCKS5´úÀí¡¢¼ôÌù°å¼àÌý¡¢ä¯ÀÀÆ÷»á»°¿Ë¡µÈÖ°ÄܵĺóÃÅÄ£¿é¡£Óë´Ëͬʱ£¬¶ñÒⷨʽ»¹»áϵͳÐÔÇÔÈ¡Ãô¸ÐÊý¾Ý£¬Ô̺¬ä¯ÀÀÆ÷ÃÜÂëÓëCookie¡¢SSHÃÜÔ¿¡¢ÔÆ·þÎñƾ֤¡¢¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡¢macOS KeychainÊý¾ÝÒÔ¼°iMessageº¹Çà¼Í¼£¬²¢Í¨¹ý¶à¸öͨѶÇþ·»Ø´«ÖÁ¹¥»÷Õß¡£
ClawHubÊг¡µÄÂÙÏÝÌ¬ÊÆ´¥Ä¿¾ªÐÄ¡£×êÑÐÈËÔ±¶ÔClawHubÉϵÄ2,857¸ö¼¼Êõ½øÐÐÁËÈ«ÃæÉ󼯣¬Á˾ַ¢ÏÖÁË341¸ö¶ñÒâ¼¼Êõ¡ª¡ªÕâÒâζ×Åÿ°Ë¸ö¼¼ÊõÖоÍÓÐÒ»¸öÊÇ»µµÄ¡£Õâ¸öÊý×ÖÔÚºóÐøµ÷²éÖгÖÐøÔö³¤£¬×îÖÕ´ïµ½ÁË824¸ö¡£

ͼ6 ¶ñÒâ¼¼ÊõÉ¢²¼
ͼ6չʾÁËClawHubÊг¡É϶ñÒâ¼¼ÊõµÄ¼Ù×°ÀàÐÍÉ¢²¼£¬ÆäÖмÓÃÜÇ®±ÒÓйع¤¾ßÕ¼±È×î¸ß£¬»¹Ô̺¬YouTube¹¤¾ß¡¢Polymarket»úеÈË¡¢Google Workspace¼¯³ÉµÈ¶àÖÖ¼Ù×°´ó¾Ö¡£
ÕâЩ¶ñÒâ¼¼ÊõµÄ¼Ù×°ÊÖ·¨¶àÖÖ¶àÑù¡£ËüÃǰÑ×Ô¼º°ü×°³ÉÊ¢ÐеŤ¾ß£ºSolanaÇ®°ü×·×ÙÆ÷¡¢YouTubeÊÓÆµÏÂÔØÆ÷¡¢PolymarketÂòÂô»úеÈË¡¢Google Workspace¼¯³É¹¤¾ß¡£Ã¿Ò»¸ö¶¼ÅäÓп´ÆðÀ´¼«¶ÈרҵµÄÎĵµºÍ½Ì³Ì¡£
¹¥»÷µÄ¹Ø¼üÔÚÓÚ"ǰÖÃǰÌá"Õâ¸öÆæÃîµÄÉè¼Æ¡£ÕâЩ¶ñÒâ¼¼Êõ»á֪ͨÓû§£¬ÎªÁËʹÓøü¼Êõ£¬Äã±ØÒªÏÈ×°ÖÃ"±ØÐë×é¼þ"¡£ÔÚWindowsÉÏ£¬ÏÂÔØÒ»¸öÃûΪ"openclaw-agent.zip"µÄѹËõ°ü£»ÔÚmacOSÉÏ£¬ÊÇÒ»ÐбØÒªÕ³Ìùµ½Öն˵ĺÅÁî¡£
GitHub²Ö¿âͶ¶¾¡£Ôڻ㱨°ä²¼Ê±£¬OpenClaw¹Ù·½Skill²Ö¿âÖÐÈÔ´æÔÚ¶ñÒâSkill¡£¸ÃSkill¼Ù×°³É"LinkedInÖÇÄÜÇóְϵͳ"£¬Ðû³ÆÌṩ»ùÓÚAIµÄְλËÑË÷¡¢¼òÀú¶¨Ôì¡¢Ò»¼üÉêÇë¡¢¿ÚÊÔ¸ú×Ù¼°ÖÇÄÜɸѡµÈÖ°ÄÜ£¬ÓµÓи߶ȹƻóÐÔ¡£¶ñÒâ²Ö¿âµØÖ·£ºhttps://github.com/openclaw/skills/blob/main/skills/zaycv/linkedin-job-application/SKILL.md¡£

ͼ7 OpenClaw¹Ù·½Skill²Ö¿âͶ¶¾
ͼ7չʾÁËÀûÓÃGithubͶ¶¾£¬¶ñÒâSkillÊèµ¼AIÏÂÔØÖ´ÐжñÒâ´úÂëµÄÃèÊöÐÅÏ¢£¬¸Ã¼¼ÊõµÄÎĵµÒªÇóÓû§£ºWindowsÓû§ÐèÏÂÔØÃûΪ"AuthTool.exe"µÄ·¨Ê½£¨ÃÜÂë1234£¬ÏÂÔØµØÖ·Îª£ºhttps://github.com/Aslaep123/clawd-authtool/releases/download/released/AuthTool.zip£¬Ä¿Ç°¸Ã¶ñÒâÕË»§ÒѾÎÞ·¨½Ó¼û£©£¬macOSÓû§Ôò±»Êèµ¼ÔÚÖÕ¶ËÔËÐÐÒ»ÐкÅÁÐû³ÆÊµÏÖÅäÖã¬ÏÖʵ»áÏÂÔØ²¢Ö´ÐжñÒâÈí¼þ¡£Ò»µ©Óû§Ö´ÐУ¬¹¥»÷Õß¾ÍÄܹ»Ö´Ðй¥»÷£¬Ô̺¬ÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°ü¡¢ÂòÂôÕË»§Í´´¦µÈ¸ß¼ÛÖµÊý¾Ý¡£
ÎÒÃÇ»¹·¢ÏÖÁËÁíÒ»¸ö²¿ÊðÔÚGitHubÉϵĶñÒâSkill£¬ÊôÓÚͳһ¹¥»÷ÍÅ»ïµÄ·ÖɢͶ¶¾Õ½Êõ¡£¸Ã¶ñÒâSkillÍйÜÓÚSkill·ÖÏíÆ½Ì¨SundialHub£¨https://www.sundialhub.com/£©µÄ¹Ù·½²Ö¿âsundial-org/awesome-openclaw-skillsÖУ¬¾ßÌåÎļþõ辶Ϊhttps://github.com/sundial-org/awesome-openclaw-skills/blob/main/skills/bybit-trading/SKILL.md¡£¸ÃSkill¼Ù×°³É"Bybit Trading Agent"¼ÓÃÜÇ®±ÒÂòÂô´úÀí£¬ÓµÓм«Ç¿µÄÖ¸±êÈËȺÕë¶ÔÐÔ¡£¾Éî¿Ì·ÖÎö£¬¸ÃSkillÏÂÔØµÄ¶ñÒâÎļþµØÖ·Óë´ËǰOpenClaw¹Ù·½²Ö¿âͶ¶¾ÊÂÎñÖеĵØÖ·ÆëȫһÖ£¬ÓÉ´Ë¿ÉÈ·ÈÏÁ½ÆðÊÂÎñΪͳһ¹¥»÷ÍÅ»ïËùΪ£¬Æäͨ¹ýÏò¶à¸ö¸ßÁ÷Á¿²Ö¿âÖ²Èë¶ñÒâSkillÒÔÀ©´ó¹¥»÷¸²¸ÇÃæ¡£

ͼ8 sundial-org/awesome-openclaw-skills²Ö¿âͶ¶¾
¹¥»÷Õß»¹Í¨¹ýGitHub´´½¨Î±ÔìµÄ"openclaw-installer"²Ö¿â£¬ÀûÓÃSEOʹÆä³Ê´Ë¿ÌËÑË÷Á˾ÖÖС£Ô´Âë½öÊÇmoltworkerÏîÖ÷ÕŸ´ÔìÕ³Ìù£¬ÕæÕýµÄ¶ñÒâÔØºÉÔÚReleaseÒ³ÃæµÄOpenClaw_x64.exeÖС£

ͼ9 αÔìµÄopenclaw-installer²Ö¿âÃèÊöÐÅÏ¢
Windowsƽ̨¿ªÊÍcloudvideo.exe£¨ÇÔÈ¡·¨Ê½£¬´ÓTelegram/Steam»ñÈ¡C2£©ºÍserverdrive.exe£¨GhostSocks´úÀí£¬Í¨¹ý×¢²á±íÓÆ¾Ã»¯£©£»macOSƽ̨ÔòÓÃOpenClawBotÇÔÈ¡ÎĵµÄ¿Â¼¡£GhostSocksÔø±»Black BastaÀÕË÷Èí¼þʹÓã¬Åú×¢OpenClawÓû§ÒѾíÈë¸ü¿í·ºµÄÍøÂç·¸×ïÉú̬¡£
2¡¢ÈÏÖ¤»úÔì·ì϶Óë¹¥»÷õè¾¶
ÈôÊÇ˵¹©¸øÁ´¹¥»÷±ØÒªÓû§×Ô¶¯"¹²Í¬"ÄÜÁ¦³É¹¦£¬ÄÇô½ÓÏÂÀ´Òª»áÉ̵ķì϶ÔòÔ½·¢Ð×¶ñ¡ª¡ªËüÃÇÄܹ»ÔÚÓû§ºÁÎÞ¾õ²ìµÄÇé¿öÏÂʵÏÖ¹¥»÷¡£
CVE-2026-25253ÊÇOpenClawº¹ÇàÉÏ×îÑϳÁµÄ·ì϶֮һ¡£°²È«×êÑÐÈËÔ±¸øËüÆðÁËÒ»¸ö´úºÅ£º"ClawJacked"¡£Õâ¸ö·ì϶ÔÊÐí¹¥»÷Õßͨ¹ýÒ»¸ö¶ñÒâÁ´½ÓʵÏÖ"Ò»¼üÔ¶³Ì´úÂëÖ´ÐÐ"¡ª¡ªÊܺ¦ÕßÖ»±ØÖصã»÷Ò»¸öÁ´½Ó£¬¹¥»÷Õß¾ÍÄÜÆëÈ«½ÚÔìËûÃǵÄAI´úÀíºÍϵͳ¡£

ͼ10 ·ì϶¹¥»÷Á´
ͼ10չʾÁËCVE-2026-25253·ì϶µÄÆëÈ«¹¥»÷Á´Â·£º¶ñÒâÁ´½Ó¡úURL²ÎÊý¶ÁÈ¡¡úWebSocketÏνӡú±©Á¦ÆÆ½âÃÜÂë¡ú×¢²á¶ñÒâÉ豸¡úÆëÈ«½ÚÔìÊܺ¦ÕßµÄAI´úÀí¡£
·ì϶µÄ¼¼Êõϸ½ÚÁîÈ˲»°²¡£ÎÊÌâµÄ±¾ÔÔÚÓÚOpenClawµÄÍø¹Ø×é¼þ»á´ÓURL²éÎÊ×Ö·û´®ÖжÁÈ¡gatewayUrl²ÎÊý£¬¶øºó×Ô¶¯³ÉÁ¢WebSocketÏνӡ£ÓÉÓÚOpenClaw¶Ô±¾µØÏνӲÉÈ¡ÁË¿íËɵݲȫսÊõ¡ª¡ªÃ»ÓÐÃÜÂ뱩Á¦ÆÆ½âÏÞ¶È¡¢ÐÂÉ豸×Ô¶¯ºË×¼¡ª¡ª¹¥»÷ÕßÄܹ»ÏÈÈÃÊܺ¦ÕßµÄä¯ÀÀÆ÷Ïνӵ½±¾µØÍø¹Ø£¬¶øºó±©Á¦ÆÆ½âÃÜÂ룬×îºó×¢²áÒ»¸ö¶ñÒâÉ豸¡£Õû¸ö¹ý³ÌÖ»±ØÒª¼¸ÃëÖÓ¡£
ÈÕÖ¾´«È¾·ì϶ͬÑùÁîÈËÓÇÓô¡£OpenClawµÄ´úÀí²Ç¶ÁÈ¡×ÔÉíÈÕÖ¾À´½øÐйÊÕÏÅųý£¬ÕâÒâζ׏¥»÷ÕßÄܹ»ÔÚÈÕÖ¾ÎļþÖÐÖ²Èë¶ñÒâÖ¸Áî¡£ÏÖ´úÀí¶ÁÈ¡ÕâЩÈÕ־ʱ£¬ÕâЩָÁî¾Í»á±»Ö´ÐУ¬´Ó¶øÊµÏÖËùνµÄ"¼ä½ÓÌáÐÑ×¢Èë"¡£
3¡¢Êý¾Ý¿âÅäÖÃʧÎóÓëMoltbookй¶
µ±Óû§½«OpenClaw²¿Êðµ½ÔÆ·þÎñÆ÷ÒÔ±ãÔ¶³Ì½Ó¼ûʱ£¬ËûÃÇ¿ÉÄÜûÓÐÒâʶµ½×Ô¼ºÔÚ´´½¨Ò»¸ö¿ÉÄܱ»¹¥»÷µÄ»¥ÁªÍøÂ¶³öÃæ¡£
MoltbookÊý¾Ýй¶ÔòÊÇÁíÒ»¸öά¶ÈµÄ¿àÄÑ¡£MoltbookÊÇOpenClawÊ×´´ÈË·¢ÏÖµÄ"AIÉç½»ÍøÂç"¡ª¡ªÒ»¸öÔÊÐíAI´úÀí·¢Ìû¡¢ÆÀÂÛ¡¢Í¶Æ±µÄƽ̨¡£Wiz°²È«×êÑз¢ÏÖ£¬Õâ¸öƽ̨ʹÓõÄSupabaseÊý¾Ý¿âAPIÃÜÔ¿¾¹È»Â¶³öÔÚ¿Í»§¶ËJavaScript´úÂëÖС£
й¶µÄÊý¾ÝÔ̺¬150Íò¸öAPIÈÏÖ¤ÁîÅÆ¡¢35,000¸öµç×ÓÓʼþµØÖ·£¬ÒÔ¼°AI´úÀíÖ®¼äµÄ¸öÈËÐÂÎÅ¡£¹ÌÈ»MoltbookÐû³ÆÕ¼ÓÐ150Íò×¢²á´úÀí£¬µ«Êý¾Ý¿âÏÔʾ±³ºóÖ»ÓÐ17,000¸öÕæÊµµÄÈËÀàÓû§¡£
4¡¢È«Çò¶³öÌ¬ÊÆÊý¾Ý·ÖÎö
ÈôÊÇËµÇ°ÃæµÄÊý¾ÝÒѾÈÃÄã¸ÐÓ¦²»°²£¬ÄÇôÀ´×Ô¡°OpenClaw Exposure Watchboard¡±£¨¹ÙÍø£º
https://openclaw.allegro.earth/£©µÄ×îÐÂÊý¾Ý¿ÉÄÜ»áÈÃÄã³ÁÐÂ˼¿¼ÊÇ·ñ³ÖÐøÊ¹ÓÃOpenClaw¡£
ͼ11 2026Äê03ÔÂ10ÈÕOpenClaw¶³öÌ¬ÊÆµÄ×ÛºÏͳ¼Æ
ͼ11չʾÁËÈ«ÇòOpenClaw¶³öÌ¬ÊÆµÄ×ÛºÏͳ¼Æ£¬Ô̺¬£º°´¹ú¶È/µØÓòÉ¢²¼(×óÉÏ)£¬ÖйúÕ¼42.3%¾ÓÊ×£»Í´´¦Ð¹Â¶Çé¿ö(ÓÒÉÏ)£¬37.2%µÄ¶³öÖ÷»ú´æÔÚÍ´´¦Ð¹Â¶£»Íþв×éÖ¯¹ØÁª(×óÏÂ)£¬40.7%µÄÖ÷»ú¹ØÁªÒÑÖªAPT×éÖ¯£»TOP 8Íþв×é֯ɢ²¼(ÓÒÏÂ)£¬APT37ºÍKimsuky¹ØÁª×î¶à¡£
»¥ÁªÍø²â»æµÄÊý¾ÝÏÔʾÁËÒ»¸ö¸üΪÑϸñµÄÏÖʵ¡£Õë¶ÔOpenClawÊ¢¿ª·þÎñµÄ´ó¹æÄ£É¨Ãè·¢ÏÖ£¬È«Çò¹²ÓÐ273,548¸ö¶³öÔÚ»¥ÁªÍøÉϵÄOpenClawÊ·ý¡ª¡ªÕâ¸öÊý×ÖÔ¶Ô¶³¬³öÁË´ËǰµÄ¹À¼Æ¡£È«Çò¶³öÖ÷»úÉ¢²¼ Top10£º
ÅÅÃû | ¹ú¶È/µØÓò | ¶³öÊýÁ¿ | Õ¼±È |
1 | Öйú | 115,751 | 42.3% |
2 | ÃÀ¹ú | 73,109 | 26.7% |
3 | µÂ¹ú | 14,430 | 5.3% |
4 | Ïã¸Û | 5,043 | 1.8% |
5 | ·ÒÀ¼ | 3,796 | 1.4% |
6 | ÈÕ±¾ | 3,627 | 1.3% |
7 | Ó¢¹ú | 2,919 | 1.1% |
8 | ·¨¹ú | 2,848 | 1.0% |
9 | ºÉÀ¼ | 2,697 | 1.0% |
10 | ¶íÂÞ˹ | 982 | 0.4% |
±í1 È«Çò¶³öÖ÷»úÉ¢²¼ Top10
ÎÒ¹úÒÔ³¬¹ý11.5ÍòµÄ¶³öÖ÷»úÊýÁ¿Î»¾ÓÈ«ÇòÊ×λ£¬Õ¼×ÜÁ¿µÄ42.3%¡£ÃÀ¹ú½ôËæÆäºó£¬ÓÐ7.3Íò¸ö¶³öÊ·ý¡£ÕâÁ½¸ö¹ú¶È¼ÆËãÕ¼¾ÝÁ˽ü70%µÄÈ«Çò¶³öÁ¿¡£
Í´´¦Ð¹Â¶Çé¿öÏÔʾÔÚ273,548¸ö¶³öÖ÷»úÖУ¬ÓÐ101,755¸ö£¨37.2%£©±»·¢ÏÖ´æÔÚÍ´´¦Ð¹Â¶ÎÊÌâ¡£ÕâÒâζ×ų¬¹ýÈý·ÖÖ®Ò»µÄ¶³öÖ÷»úÉÏ£¬¹¥»÷ÕßÄܹ»Ö±½Ó»ñÈ¡µ½ÓÐЧµÄÈÏ֤ʹ´¦¡£
ÓëÍþв×éÖ¯µÄ¹ØÁª½«·çÏÕÌáÉýµ½ÁËÒ»¸öеĵµ´Î¡£Êý¾ÝÏÔʾ£¬ÓÐ111,389¸ö¶³öÖ÷»ú£¨40.7%£©ÓëÒÑÖªÍþв×éÖ¯´æÔÚ¹ØÁª¡£Õâ¸öÊý×ÖÒâζ×Å£¬½«½üÒ»°ëµÄ¶³öÊ·ý¿ÉÄÜÒѾ±»¹ú¶È¼¶¹¥»÷Õß»òÍøÂç·¸×ï×éÖ¯ËùÀûÓá£Íþв×é֯ͼÆ×¸²¸ÇÁ˶à¸ö³ÛÃûµÄAPT×éÖ¯£º
Íþв×éÖ¯ | ¹ØÁªÂ¶³öÖ÷»úÊýÁ¿ |
APT37 (³¯ÏÊ) | 92,659 |
Kimsuky (³¯ÏÊ) | 81,754 |
APT28 (¶íÂÞ˹) | 79,422 |
Sandworm Team (¶íÂÞ˹) | 74,456 |
The Shadow Brokers | 65,634 |
Gamaredon Group | 64,795 |
MuddyWater Group | 62,006 |
Salt Typhoon | 61,491 |
±í2 ¶à¸öAPT×éÖ¯ÓëOpenClaw¶³öÖ÷»úÓйØÁª
ÕâЩÊý¾Ý½ÒʾÁËÒ»¸öÁîÈ˲»°²µÄÊÂʵ£ºOpenClawµÄ¶³öÖ÷»úÒѾ³ÉΪ¹ú¶È¼¶ÍøÂç¹¥»÷ÕߵijÁÒªÖ¸±ê¡£APT37ºÍKimsukyÕâÁ½¸ö³¯ÏÊAPT×éÖ¯¹ØÁªµÄ¶³öÖ÷»úÊýÁ¿×î¶à¡ª¡ªÕâ¿ÉÄÜÓëOpenClawƵÈÔ±»ÓÃÓÚ¼ÓÃÜÇ®±ÒÂòÂôºÍ½ðÈÚ²Ù×÷Óйء£¶íÂÞ˹²¼¾°µÄAPT28ºÍSandworm TeamͬÑù»îÔ¾£¬ËüÃǹØÁªµÄ¶³öÖ÷»úÊýÁ¿Ò²¶¼³¬¹ýÁË7Íò¸ö¡£
ΪʲôAI AgentÈç´Ë´àÈõ
1¡¢¼Ü¹¹Éè¼ÆµÄÔ×ï
ÒªÀí½âOpenClawΪʲô»á³öÏÖÕâô¶à°²È«ÎÊÌ⣬ÎÒÃDZØÒª´ÓËüµÄ¼Ü¹¹Éè¼ÆËµÆð¡£
OpenClawµÄÖ÷ÌâÊÇÒ»¸öÃûΪ"Gateway"µÄ±¾µØ×é¼þ£¬ËüÐÔÖÊÉÏÊÇÒ»¸öWebSocket·þÎñÆ÷£¬ÕƹÜе÷AI´úÀíÓë¸÷À๤¾ßºÍ·þÎñÖ®¼äµÄ½»»¥¡£Õâ¸öÉè¼Æ¸³ÓèÁËAI´úÀí¼«´óµÄÄÜÁ¦£¬µ«Ò²´´ÔìÁ˾޴óµÄ¹¥»÷Ãæ¡£

ͼ12 ¼Ü¹¹·çÏÕ
ͼ12չʾÁËOpenClawµÄ¼Ü¹¹¼°·çÏյ㣺Gateway×÷ΪWebSocket·þÎñÆ÷ÓëShell¡¢Îļþ¡¢Óʼþ¡¢É罻ýÌåµÈ·þÎñÏνӣ¬Ã¿¸öÏνӵ㶼´æÔÚDZÔÚ°²È«·çÏÕ¡£
±¾µØÏνӵÄÐÅÀµ¹ý¶ÈÊÇ×î´óµÄÎÊÌâÖ®Ò»¡£OpenClawµÄÉè¼ÆÈç¹û±¾µØÏνÓÊÇ¿ÉÐŵģ¬Òò¶ø¶ÔÀ´×ÔlocalhostµÄÏνÓÖ´ÐÐÁ˶àÏȫ·ÅËÉ£ºÎÞÃÜÂ뱩Á¦ÆÆ½âÏÞ¶È¡¢ÐÂÉ豸×Ô¶¯ºË×¼¡¢È¨ÏÞÌáÉý²»±ØÒª¶þ´ÎÈ·ÈÏ¡£ÕâÖÖÉè¼ÆÔÚµ¥»ú»·¾³Ï¿ÉÄÜÊǺÏÀíµÄ£¬µ«ÔÚÏÖ´úÍøÂç»·¾³ÖÐÈ´³ÉΪÁËÖÂÃüÈõµã¡£
ÎÊÌâµÄ±¾ÔÔÚÓÚä¯ÀÀÆ÷µÄ¿çÓòÕ½Êõ¡£WebSocketÓëHTTP·ÖÆç¡ª¡ªä¯ÀÀÆ÷²»»á×èÖ¹¿çÓòµÄWebSocketÏνӡ£ÕâÒâζ×ŵ±Äã½Ó¼ûÈκÎÍøÕ¾Ê±£¬¸ÃÍøÕ¾ÉϵĶñÒâJavaScript¶¼Äܹ»³¢ÊÔÏνÓÄã±¾µØÔËÐеÄOpenClawÍø¹Ø¡£
¹¤¾ßÖ´ÐеÄȨÏÞ¹ý´óÊÇÁíÒ»¸öÉè¼ÆÈ±µã¡£OpenClawÄܹ»Ö´ÐÐËÁÒâshellºÅÁÕâÒâζ×ÅÈôÊǹ¥»÷Õß»ñµÃÁË´úÀíµÄ½ÚÔìȨ£¬ËûÃÇÄܹ»ÔÚÄãµÄϵͳÉÏ×öÈκÎʼþ¡£
2¡¢ÊäÈëÑéÖ¤µÄÓïÒåÌìǵ
ÔÚÊäÈëÑéÖ¤²ã£¬OpenClawµÄexternal-content.tsÄ£¿éÕë¶ÔÌáÐÑ´Ê×¢ÈëµÄ·ÀÓù´æÔÚÑϳÁµÄÓïÒå¸ÐÖªÍѽڡ£¸ÃÄ£¿éÇ¿ÒÀÀµ´«Í³µÄ´Ê·¨Æ¥Å䣨ÕýÔò±í°×ʽ£©£¬ÊÔͼͨ¹ý¹Ø¼ü´Ê¹ýÂËÀ´×èÖ¹¶ñÒâÖ¸ÁȻ¶ø£¬´ó˵»°Ä£ÐÍ£¨LLM£©µÄ´¦ÖÃÂß¼ÊÇ»ùÓÚTokenµÄ¸ßάÓïÒåÓ³É䣬¶ø·Ç×ÖÃæÁ¿×Ö·û´®Æ¥Åä¡£¹¥»÷Õßͨ¹ý×¢ÈëUnicodeתÒåÐòÁлòBase64±àÂëÔØºÉ£¬¿ÉÄÜÃÀÂúÈÆ¹ýÕýÔòÒýÇæµÄ¾²Ì¬´Ê·¨·ÖÎö¡£µ¹ØâЩ±àÂëºóµÄÔØºÉ½øÈëLLMµÄ¸ßµÍÎÄ´°¿Úʱ£¬Ä£ÐÍÔÉúµÄ½âÂëÄÜÁ¦»á½«Æä»¹ÔΪ¼«¾ß·ÛËéÐÔµÄÌØÈ¨Ö¸Áµ¼ÖÂ˼ÏëÁ´£¨Chain-of-Thought£©±»³¹µ×¶¾»¯¡£

ͼ13 »ùÓÚ´Ê·¨¹ýÂ˵ÄPrompt Injection¼ì²â¼°ÆäUnicode/Base64ÈÆ¹ý¶ÈÎö
ÕâÖÖ¹¥»÷·½Ê½µÄÒñ±ÎÐÔÔÚÓÚ£º´«Í³µÄ°²È«É¨Ã蹤¾ßµ××ÓÎÞ·¨¼ø±ðBase64×Ö·û´®ÖеĶñÒâÄÚÈÝ£¬¶øLLMÈ´ÄÜÃÀÂúÀí½â²¢Ö´ÐС£
3¡¢¹©¸øÁ´µÄÐÅÀµÈ±¿Ú
OpenClawµÄÉú̬ϵͳÒÀÀµÓÚÒ»¸ö¿´ËÆÃÀºÃµÄÀíÏ룺ʢ¿ªºÏ×÷¡£ÈκÎÈ˶¼Äܹ»ÉÏ´«¼¼Êõ£¬ÈκÎÈ˶¼Äܹ»°ä²¼NPM°ü£¬ÈκÎÈ˶¼Äܹ»ÔÚGitHubÉÏ·ÖÏí´úÂë¡£µ«ÕâÖÖÊ¢¿ªÐÔÔÚûÓÐ×ã¹»°²È«»úÔì±£»¤µÄÇé¿öÏ£¬Ò²³ÉΪÁ˹¥»÷ÕßµÄÀÖÔ°¡£
ClawHubÉóºË»úÔìµÄȱʧÊÇ×îÏÔÖøµÄÎÊÌâ¡£Õâ¸öÊг¡Î¨Ò»µÄÃż÷Êǰ䲼Õß±ØÒªÕ¼ÓÐÒ»¸öÖÁÉÙÒ»ÖÜÁäµÄGitHubÕË»§¡£×êÑÐÈËÔ±·¢ÏÖ£¬¹¥»÷Õ߻ᴴ½¨¶à¸öÕË»§¡¢Ê¹ÓÃÀàËÆÃû³Æ½øÐÐÓòÃû·Âð¡¢¾«ÐÄÔì×÷¿´ÆðÀ´ÆëÈ«ºÏ·¨µÄÎĵµ¡£
4¡¢Â¶³öÃæÓëÖÎÀíÕæ¿Õ
ÅäÖò»µ±µÄÆÕ±éÐÔÁîÈËÕ𾪡£ºÜ¶àÓû§ÎªÁËʹÓ÷½±ã£¬Ñ¡Ôñ¹Ø¹ØÉí·ÝÑéÖ¤»òʹÓÃÈõÃÜÂë¡£ÕâʹµÃËûÃǵÄOpenClawÊ·ýÔì³ÉÁË"ÈíÊÁ×Ó"¡ª¡ªÖ»±ØÒªµ¥Ò»µÄɨÃèºÍ×î»ù´¡µÄ±©Á¦ÆÆ½â¾ÍÄÜ»ñµÃ½Ó¼ûȨÏÞ¡£
¸üÐÂÖͺó¼Ó¾çÁËÎÊÌâ¡£´Ó·ì϶±»¹«¿ªÅû¶µ½Óû§ÏÖʵÀûÓý¨¸´Ö®¼ä£¬´æÔÚÒ»¸öΣÏյŦ·ò´°¿Ú¡£´Ó»¥ÁªÍøÉϱ©Â©µÄÊý¾ÝÏÔʾ£¬ºÜ¶àOpenClawÊ·ýÔËÐеÄÊǹýÆÚ°æ±¾£¬ÕâʹËüÃdzÉΪÒÑÖª·ì϶µÄÁÔÎï¡£
5¡¢¹¤¾ßÁ´µÄ¹¥»÷ת»¯õè¾¶
ÔÚÖ´Ðв㣬OpenClawµÄÄ£Ð͸ߵÍÎĺÍ̸£¨MCP£©²»×ãÔËÐÐʱµÄϸÁ£¶ÈÖ¸ÁîÀ¹½Ø¡£Ò»µ©ÉÏÊöµÄÓïÒå¶¾»¯ÉúЧ£¬AI´úÀí±ã»áÓɱ»¶¯ÏìӦ״̬ת±äΪ×Ô¶¯¹¥»÷ÒýÇæ¡£

ͼ14 AI Agent ÓïÒå¿Õ¼äÖÁÎïÀí»·¾³µÄ¹¥»÷ÑݽøÍ¼Æ×
´ÓÉÏͼÄܹ»¿´³ö¹¥»÷Õß¿Éͨ¹ýÏÂÃæÁ½Ìõõ辶ʵÏÖ±øÆ÷»¯£º
? SSRF¹¥»÷õè¾¶£ºOpenClawÄÚÖõÄä¯ÀÀÆ÷ÓëÍøÂ繤¾ß°ü±»½Ù³ÖÎªÌø°å£¬Ö´ÐзþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©£¬ÓÃÓÚ̽²âÄÚÍø·þÎñ»òÇÔÈ¡ÔÆ»·¾³ÔªÊý¾Ý£¨È磺AWS IMDSv1µÄһʱƾ֤£©¡£
? RCE¹¥»÷õè¾¶£º±¾µØShell ½Ó¿Ú½«ÌìȻ˵»°µÄÂß¼Îó²îÖ±½Ó·Å´óΪÎÞÐèÌáȨµÄÔ¶³Ì´úÂëÖ´ÐУ¬ÊµÏÖ´ÓÐé¹¹ÈÏÖª²ãµ½ÎïÀíËÞÖ÷ϵͳµÄÖÕ¼«´©Ô½¡£
CVE-2026-24763ÓëCVE-2026-25157¶³öµÄ²¢·Ç±í²ã±à³Ìȱµã£¬¶øÊÇAI Agent°²È«Éè¼Æ·¶Ê½µÄµ××ÓÐÔȱµã£ºÒÔÀûÓòã·ÀÓù»úÔìÆ¥µÐÓïÒå¿Õ¼ä¹¥»÷£¬ÎÞÒìÓÚÒÔ³ÇǽÕÐ¼Ü¿ÕÆø´«²¼µÄ²¡¶¾¡£
·ÀÓùÕ½ÊõÓë×î¼Ñʵ¼Ê
1¡¢Í¨³£Óû§µÄ×ÔÎÒ±£»¤
ÈôÊÇÄãÖ»ÊÇÔÚÓ×ÎÒµçÄÔÉÏÔËÐÐOpenClaw£¬ÒÔÏÂÊÇÄã±ØÒªÁ¢¼´²ÉÈ¡µÄÐж¯£º

ͼ15 °²È«×Ô²éÇåµ¥
ͼ15չʾÁËOpenClawÓû§Ó¦×ñѵÄ5ÏîÖ÷Ìⰲȫ´ëÊ©£º£¨1£©Á¢¼´¸üа汾£¨2£©¾¯Ìè¿ÉÒÉÁ´½Ó£¨3£©½ö´Ó¹Ù·½Çþ·װÖã¨4£©ÏÞ¶ÈÊÚȨÁìÓò£¨5£©¶¨ÆÚ²é³»á»°×´Ì¬¡£
Á¢¼´¸üе½×îа汾¡£ÕâÌýÆðÀ´ÏñÊÇÐëÉú³£Ì¸£¬µ«ÔÚOpenClawµÄ°¸ÀýÖÐÓÈΪ¹Ø¼ü¡£×êÑÐÈËÔ±Åû¶µÄ¶à¸öÑϳÁ·ì϶¶¼ÒѾÔÚа汾Öеõ½½¨¸´¡£ÔËÐÐ"openclaw update"Ö»±ØÒª¼¸ÃëÖÓ¡£
ʼÖÕ²»Öصã»÷¿ÉÒÉÁ´½Ó¡£ÈκÎÒªÇóÄã½Ó¼ûÌØ¶¨ÍøÕ¾»òÖ´ÐÐ×°ÖúÅÁîµÄÁ´½Ó¶¼Ó¦¸ÃÒýÆð¾¯Ìè¡£ÈôÊÇÓÐÈËÐû³Æ±ØÒªÄã"×°Ööî±í×é¼þ"ÄÜÁ¦Ê¹ÓÃij¸öÖ°ÄÜ£¬ÕâÏÕЩע¶¨ÊÇÒ»¸öȦÌס£
Ö»´Ó¹Ù·½Çþ·װÖá£OpenClawµÄ¹Ù·½GitHub²Ö¿âÊÇgithub.com/openclaw/openclaw¡£ÈÎºÎÆäËûµÄ"¹Ù·½¾µÏñ"¡¢µÚÈý·½×°Ö÷¨Ê½¶¼¿ÉÄÜÊǶñÒâµÄ¡£
ÏÞ¶ÈÊÚȨÁìÓò¡£¶¨ÆÚ²é³ÄãµÄOpenClaw¼¯³ÉÁËÄÄЩ·þÎñ£¬È¡µÞÄÇЩÄã²»ÔÙʹÓûò²»±ØÒªµÄOAuthÊÚȨ¡£
2¡¢¿ª·¢Õߵݲȫ¹æ·¶
ÈôÊÇÄãÔÚ¿ª·¢»·¾³ÖÐʹÓÃOpenClaw£¬Äã±ØÒª²ÉÈ¡¸üÑϸñµÄ°²È«´ëÊ©£º
È·ÈÏGateway°ó¶¨Ä£Ê½¡£Ä¬ÈÏÇé¿öÏ£¬OpenClaw Gateway½ö¼àÌý±¾µØ»Ø»·µØÖ·£¨127.0.0.1£©£¬ÕâÊǰ²È«µÄÉè¼Æ¡£Äܹ»Í¨¹ýÒÔϺÅÁîÈ·ÈÏ£º
openclaw config get gateway.bind
openclaw gateway status
Êä³öÓ¦¸ÃÏÔʾ bind=loopback¡£ÈôÊÇÏÔʾÆäËûÖµ£¬Ó¦Á¢¼´½¨¸ÄΪ£º
openclaw config set gateway.bind "loopback"
²é³ÈÏ֤ģʽ¡£¹Ù·½Ä¬ÈÏʹÓÃtokenÈÏ֤ģʽ£¬¿Éͨ¹ýÒÔϺÅÁî²é³£º
openclaw config get gateway.auth
¶¨ÆÚÉ󼯻îÔ¾»á»°¡£Ñø³É¶¨ÆÚ²é³»á»°ÁбíµÄϰ¹ß£¬¼ø±ðÈκοÉÒɵÄÏνӣº
openclaw sessions
ÅäÖÃÃô¸ÐºÅÁîÏÞ¶È¡£OpenClawÔÊÐíͨ¹ýnodesÅäÖÃÏÞ¶ÈÃô¸ÐºÅÁîµÄÖ´ÐÐȨÏÞ£¬¹Ù·½Ä¬ÈÏÒѲ»Èݲ¿ÃŸ߷çÏÕ²Ù×÷£º
openclaw config get gateway.nodes.denyCommands
ʹÓÃרÓûúе¡£¾¡Á¿²»ÒªÔÚÈÕ³£¿ª·¢»úеÉÏÔËÐÐOpenClaw£¬Ê¹ÓÃһ̨¸ôÀëµÄרÓûúеÀ´ÔËÐÐÕâ¸öAI¸±ÊÖ¡£
¸ôÀëÅäÖô洢¡£ÅäÖÃÎļþλÓÚ~/.openclaw/openclaw.json£¬ÆäÖÐÔ̺¬Ãô¸ÐÍ´´¦ÐÅÏ¢£¬Ó¦Í×ÉÆÉú»î¡£
3¡¢ÆóÒµ¼¶²¿ÊðÖ¸ÄÏ
ÆóÒµÂ䵨OpenClaw£¬Ö÷Ìâ²»ÊÇ¡°°Ñ·þÎñÅÜÆðÀ´¡±£¬¶øÊÇÏȰѷçÏչؽøÌìǵ¡£½¨Òé°´¡°ÍøÂç·ÖÇø¡¢Ç¿ÈÏÖ¤¡¢¼¯ÖÐÉ󼯡¢·ÖÖÓ¼¶ÏìÓ¦¡±ËÄÌõÖ÷Ïß½¨É裬ÏÈ´ï³É×îÓ׿ÉÓð²È«»ùÏߣ¬ÔÙÖð²½À©´óÄÜÁ¦¡£
µÚÒ»£¬ÏÈ×öÍøÂçÓë¶³öÃæÊÕÁ²¡£
³ö²ú»·¾³Ñ¡È¡DMZ/ÀûÓÃÇø/ÖÎÀíÇøÈý²ã·ÖÇø£ºDMZÖ»·Å·´Ïò´úÀí»òWAF£¬ÀûÓÃÇø²¿ÊðGateway/Agent£¬ÖÎÀíÇø³ÐÔØµï±¤»ú¡¢ÈÕÖ¾ÓëÃÜԿϵͳ¡£ÔÆÉϽ¨ÒéʹÓÃVPC + ˽ÓÐ×ÓÍø£¬Ä¬ÈϻؾøÈëÕ¾£¬½ö·ÅÐбØÒª¶Ë¿Ú£»OpenClaw½Úµã²»·ÖÅä¹«ÍøIP¡£Gateway½ö°ó¶¨loopback»òÄÚÍøµØÖ·£¬Ô¶³ÌÔËάͳÒѾVPN»òZTNA¡£Ã¿ÔÂ×öÒ»´Î±íÍøÂ¶³öÃæÉ¨Ã裬²¢Óë×ʲų́Õ˽»²æ²é¶Ô£¬·¢ÏÖ¶³öÊ·ýÁ¢¼´ÏÂÏßÕû¸Ä¡£
µÚ¶þ£¬Éí·ÝºÍȨÏÞÓÅÏÅ×ÚÏνӷ½±ã¡£
ÖÎÀíÃæ½ÓÈëӦͳһ×߯óÒµIdP£¨SAML/OIDC£©²¢Ç¿ÔìMFA£¬¾µï±¤»ú½øÈ룻²»Èݹ²ÏíÕ˺ţ¬¸ßȨÏÞ²Ù×÷±ØÐë¿É×·Òäµ½Ó×ÎÒ¡£ÏµÍ³¼äͨѶʹÓöÌTTL token»òmTLS£¬Í´´¦Í³Ò»ÍйÜÔÚSecret Manager£¨Vault/KMS£©£¬²»ÈÝÃ÷ÎÄдÈë¾ç±¾¡¢¾µÏñºÍ²Ö¿â¡£È¨ÏÞÄ£ÐÍÒÔRBACΪ»ù´¡£¬×ñÑĬÈϻؾøÓë×îÓ×ÊÚȨ£ººÅÁîÖ´ÐÓ×¢Îļþ¶Áд¡¢±íÁªÄÜÁ¦°´¹¤µ¥Ò»Ê±·ÅȨ£¬µ½ÆÚ×Ô¶¯»ØÊÕ£»ShellÖ´ÐÓ×¢Ãô¸ÐĿ¼½Ó¼û¡¢±í·¢APIŲÓõȸ߷çÏÕ×÷ΪÆôÓöþ´ÎÉóÅú¡£
µÚÈý£¬°ÑÉó¼ÆÄÜÁ¦Ç°Öõ½ÉÏÏßǰ¡£
ÖÁÉٲɼ¯ËÄÀàÈÕÖ¾£ºÍø¹Ø½Ó¼û¡¢Ö´ÐÐÉ󼯡¢Îļþ½Ó¼û¡¢ÍøÂçÏνӡ£ÈÕ־ͳһ»ã¾Ûµ½SIEM£¬Ô¤·À½ö±¾µØÁô´æ¡£Áô´æÖÜÆÚ½¨Ò飺ͨÓÃÉó¼ÆÈÕÖ¾²»ÉÙÓÚ180Ì죬¹Ø¼ü²Ù×÷ÈÕÖ¾±£Áô1ÄꣻͬʱÆôÓöÔÏóËø/WORM/ÊðÃûУÑ飬Ԥ·ÀºÛ¼£±»´Û¸Ä¡£¸æ¾¯¹æ¶¨¿ÉÏÈ´Ó×îÓ×¼¯ÖÐÆð²½£ºÒì³£ÆðÔ´½Ó¼û¡¢¶Ìʱ¸ßƵÈÏ֤ʧ°Ü¡¢Òì³£²¢·¢»á»°¡¢¸ßΣºÅÁîģʽ¡¢Ãô¸ÐĿ¼½Ó¼û¡¢·Ç°×Ãûµ¥±íÁª¡£
µÚËÄ£¬°´¡°Ð¹Â¶ÒѲúÉú¡±Èç¹û±£»¤Êý¾Ý¡£
¶Ô¿É½Ó¼ûÊý¾Ý×ö·Ö¼¶£¨¹«¿ª/ÄÚ²¿/Ãô¸Ð/ÊÜÏÞ£©£¬Ä¬ÈϽöÊ¢¿ª¹«¿ªÓëÄÚ²¿Êý¾Ý£»³ö²úÊý¾ÝÓÅÏÈÌṩÍÑÃô¸±±¾»ò×îÓ××Ö¶ÎÊÓͼ¡£´«Êä²ãÇ¿ÔìTLS 1.2+£¬ÄÚ²¿·þÎñÓÅÏÈmTLS£»ÈÕÖ¾¡¢»á»°¡¢»º´æÆôÓüÓÃÜ´æ´¢£¬ÃÜÔ¿½»ÓÉKMS/HSMÍйܡ£¶ÔÓʼþ¡¢IM¡¢Webhook¡¢±í²¿APIµÈ³ö¿Ú²¿ÊðDLP£¬À¹½ØÍ´´¦ºÍÃô¸Ð±êʶ£»Í¬Ê±³ÖÐø½øÐÐrepo¡¢¾µÏñ¡¢ÈÕÖ¾°ÂÃØÉ¨Ã裬ÉäÖм´´¥·¢Í´´¦ÂÖ»»¡£
µÚÎ壬ÊÂÎñÏìÓ¦Òª¿ÉÔÚ·ÖÖÓ¼¶Ö´ÐС£
´¥·¢Ç°ÌὨÒéÃ÷ȷΪËÄÀࣺÒì³£»á»°¡¢¿ÉÒɺÅÁî¡¢Ãô¸ÐÊý¾ÝÒì³£½Ó¼û¡¢Î´ÊÚȨ±íÁª¡£´ëÖýÚÅĿɹ̶¨Îª£º15·ÖÖÓÄÚ¸ôÀë½Úµã²¢³·³ýÍ´´¦£¬4Ó×ʱÄÚʵÏÖÈë¿ÚÓëÓ°ÏìÁìÓòÑÐÅв¢Ï·¢IOC£¬24Ó×ʱÄÚʵÏÖÅäÖý¨²¹Óë»Ø¹éÑéÖ¤£¬48Ó×ʱÄÚÌá½»¸´Å̲¢³Áµí¼ì²â¹æ¶¨µ½SIEM/SOAR¡£
ÕâÌ׹滮ÓëOpenClaw¹Ù·½¡°±¾µØ¼àÌý¡¢Ä¬ÈÏÈÏÖ¤¡¢×îÓ×¶³öÃæ¡±µÄ×¼ÔòÒ»Ö£¬Ò²ÓëÆóÒµÁãÐÅÀµ¡¢×îÓ×ȨÏÞ¡¢·Ö²ã·ÀÓùµÄͨÓÃʵ¼Ê¶ÔÆë¡£
4¡¢ÃæÏò½«À´µÄ°²È«Ë¼ÂÇ
OpenClawµÄ°²È«Î£»úԤʾ×ÅÕû¸öAI AgentÐÐÒµ¶¼½«Ãæ¶ÔÀàËÆµÄ°²È«ÌôÕ½¡£
ȨÏÞÓëÖ°ÄܵÄÓÀºãì¶Ü½«³ÖÐø´æÔÚ¡£AI´úÀí±ØÒª×ã¹»µÄȨÏÞÄÜÁ¦²ûÑï×÷Ó㬵«Ã¿Ôö³¤Ò»ÏîȨÏ޾ͿÉÄÜ´´ÔìÒ»¸öÐµĹ¥»÷Ãæ¡£
¹©¸øÁ´°²È«±ØÐëµÃµ½µ××ÓÐÔÆ÷³Á¡£ÎÒÃDZØÒª¸üºÃµÄ»úÔìÀ´ÑéÖ¤ºÍÉóºËµÚÈý·½×é¼þ¡£
ÁãÐÅÀµ¼Ü¹¹Ó¦¸ÃÊÇ×îÖÕÖ¸±ê¡£ÔÚÁãÐÅÀµÄ£ÐÍÏ£¬Ã¿¸öÒªÇ󡪡ªÎÞÂÛÀ´×ÔÄÄÀ¡ª¶¼±ØÒª±»ÑéÖ¤¡£
OpenClaw´ÓGitHubº¹ÇàÉÏÔö³¤×î¿ìµÄ¿ªÔ´ÏîÄ¿£¬µ½³ÉΪ°²È«Î£»úµÄ½¹µã£¬Ö»ÓÃÁ˶̶̼¸Öܹ¦·ò¡£Õâ²¢·ÇÎÞÒâ¶øÊÇAI Agent°²È«·¶Ê½×ª±ä´øÀ´µÄϵͳÐÔ·çÏյļ¯ÖÐÌåÏÖ¡£
µ±AI±»¸³Óè"ÉϵÛģʽ"µÄȨÏÞʱ£¬Ëü¾Í³ÉΪÁËÒ»¸ö¼«¾ßÎüÒýÁ¦µÄ¹¥»÷Ö¸±ê¡£¹¥»÷ÕßÖ»±ØÒªÓÕÆÓû§µã»÷Ò»¸öÁ´½Ó£¬»òÕßÉÏ´«Ò»¸ö¿´ËÆÎÞº¦µÄ²å¼þ£¬¾ÍÄÜ»ñµÃ¶ÔÊܺ¦ÕßϵͳµÄÈ«Ãæ½ÚÔì¡£
µ«Î£»úÖÐÒ²Ô̺¬×Å»úÔµ¡£OpenClaw¶³ö³öµÄÎÊÌâÔÚÍÆ¶¯Õû¸öÐÐÒµ³ÁÐÂ˼ÂÇAI AgentµÄ°²È«Éè¼Æ¡£
¶ÔÓÚÒѾʹÓûò´òËãʹÓÃOpenClawµÄÓû§£¬±¦ÔËÀ³¹Ù·½ÍøÕ¾½¨ÒéºÜµ¥Ò»£º²»Òª·¢¼±£¬µ«Ò²²»Òª²»ÒÔΪÒâ¡£²ÉÈ¡¸ù»ùµÄ·À»¤´ëÊ©¡ª¡ª¸üе½×îа汾¡¢Ï޶ȶ³öÃæ¡¢¾¯Ìè¿ÉÒÉÁ´½Ó¡ª¡ªÄܹ»ÓÐЧµØ½«·çÏÕ½µµ½¿É½ÓÊܵÄˮƽ¡£
×îºó£¬Î¬³Ö¹Ø×¢¡£Õâ¸öÁìÓòµÄ¼±¾ç·¢Õ¹Òâζ×ÅеÄÍþвºÍеķÀ»¤´ëÊ©¶¼ÔÚ²»ÐÝÓ¿ÏÖ¡£


¾©¹«Íø°²±¸11010802024551ºÅ