¹ØÓÚ·À±¸OpenClaw£¨¡°ÁúϺ¡±£©¿ªÔ´ÖÇÄÜÌ尲ȫ·çÏյġ°ÁùÒªÁù²»Òª¡±½¨Òé

°ä²¼¹¦·ò 2026-03-11

Õë¶Ô¡°ÁúϺ¡±µäÐÍÀûÓ󡾰ϵݲȫ·çÏÕ£¬¹¤ÒµºÍÐÅÏ¢»¯²¿ÍøÂ簲ȫÍþвºÍ·ì϶ÐÅÏ¢¹²ÏíÆ½Ì¨£¨NVDB£©×éÖ¯ÖÇÄÜÌåÌṩÉÌ¡¢·ìÏ¶ÍøÂçÆ½Ì¨ÔËÓªµ¥Ôª¡¢ÍøÂ簲ȫÆóÒµµÈ£¬×êÑÐÌá³ö¡°ÁùÒªÁù²»Òª¡±½¨Òé¡£


Ò»¡¢µäÐÍÀûÓó¡¾°°²È«·çÏÕ


£¨Ò»£©ÖÇÄܰ칫³¡¾°ÖØÒª´æÔÚ¹©¸øÁ´¹¥»÷ºÍÆóÒµÄÚÍøÉøÈëµÄ͹¹Î·çÏÕ


1.³¡¾°ÃèÊö£ºÍ¨¹ýÔÚÆóÒµÄÚ²¿²¿Êð¡°ÁúϺ¡±£¬¶Ô½ÓÆóÒµÒÑÓÐÖÎÀíϵͳ£¬ÊµÏÖÖÇÄÜ»¯Êý¾Ý·ÖÎö¡¢Îĵµ´¦Öá¢ÐÐÕþÖÎÀí¡¢²ÆÕþ¸¨ÖúºÍ֪ʶÖÎÀíµÈ¡£


2.°²È«·çÏÕ£ºÒýÈëÒì³£²å¼þ¡¢¡°¼¼Êõ°ü¡±µÈÒý·¢¹©¸øÁ´¹¥»÷£»ÍøÂ簲ȫ·çÏÕÔÚÄÚÍøºáÏòÀ©É¢£¬Òý·¢ÒѶԽӵÄϵͳƽ̨¡¢Êý¾Ý¿âµÈÃô¸ÐÐÅϢй¶»òÃÔʧ£»²»×ãÉó¼ÆºÍ×·Òä»úÔìÇé¿öÏÂÒ×Òý·¢ºÏ¹æ·çÏÕ¡£


3.Ó¦¶ÔÕ½Êõ£º¶ÀÁ¢Íø¶Î²¿Êð£¬Óë¹Ø¼ü³ö²ú»·¾³¸ôÀëÔËÐУ¬²»ÈÝÔÚÄÚ²¿ÍøÂçʹÓÃδÉóÅúµÄ¡°ÁúϺ¡±ÖÇÄÜÌåÖÕ¶Ë£»²¿Êðǰ½øÐгä·Ö°²È«²âÊÔ£¬²¿Êðʱ²ÉÈ¡×îÓ×»¯È¨ÏÞÊÚÓ裬²»ÈݷDZØÒªµÄ¿çÍø¶Î¡¢¿çÉ豸¡¢¿çϵͳ½Ó¼û£»Áô´æÆëÈ«²Ù×÷ºÍÔËÐÐÈÕÖ¾£¬È·±£Âú×ãÉó¼ÆµÈºÏ¹æÒªÇó¡£


£¨¶þ£©¿ª·¢ÔËά³¡¾°ÖØÒª´æÔÚϵͳÉ豸Ãô¸ÐÐÅϢй¶ºÍ±»½Ù³Ö½ÚÔìµÄ͹¹Î·çÏÕ


1.³¡¾°ÃèÊö£ºÍ¨¹ýÆóÒµ»òÓ×ÎÒ²¿Êð¡°ÁúϺ¡±£¬½«ÌìȻ˵»°×ª»¯Îª¿ÉÖ´ÐÐÖ¸Á¸¨Öú½øÐдúÂë±àд¡¢´úÂëÔËÐÓ×¢É豸Ѳ¼ì¡¢ÅäÖñ¸·Ý¡¢ÏµÍ³¼à¿Ø¡¢ÖÎÀí¹ý³ÌµÈ¡£


2.°²È«·çÏÕ£º·ÇÊÚȨִÐÐϵͳºÅÁÉ豸ÔâÍøÂç¹¥»÷½Ù³Ö£»ÏµÍ³Õ˺źͶ˿ÚÐÅϢ¶³ö£¬Ôâ·ê±í²¿¹¥»÷»ò¿ÚÁî±¬ÆÆ£»ÍøÂçÍØÆË¡¢ÕË»§¿ÚÁî¡¢API½Ó¿ÚµÈÃô¸ÐÐÅϢй¶¡£


3.Ó¦¶ÔÕ½Êõ£ºÔ¤·À³ö²ú»·¾³Ö±½Ó²¿ÊðʹÓã¬ÓÅÏÈÔÚÐé¹¹»ú»òɳÏäÖÐÔËÐУ»²¿Êðǰ½øÐгä·Ö°²È«²âÊÔ£¬²¿Êðʱ²ÉÈ¡×îÓ×»¯È¨ÏÞÊÚÓ裬²»ÈÝÊÚÓèÖÎÀíԱȨÏÞ£»³ÉÁ¢¸ßΣºÅÁîºÚÃûµ¥£¬³ÁÒª²Ù×÷ÆôÓÃÈËΪÉóÅú»úÔì¡£


£¨Èý£©Ó×ÎÒ¸±ÊÖ³¡¾°ÖØÒª´æÔÚÓ×ÎÒÐÅÏ¢±»ÇÔºÍÃô¸ÐÐÅϢй¶µÄ͹¹Î·çÏÕ


1.³¡¾°ÃèÊö£ºÍ¨¹ýÓ×ÎÒ¼´Ê±Í¨Ñ¶Èí¼þµÈÔ¶³Ì½ÓÈë±¾µØ»¯²¿ÊðµÄ¡°ÁúϺ¡±£¬ÌṩÓ×ÎÒÐÅÏ¢ÖÎÀí¡¢ÈÕ³£ÊÂÎñ´¦Öá¢Êý×Ö×ʲúÕû¶ÙµÈ£¬²¢¿É×÷Ϊ֪ʶ½ø½¨ºÍÉúÑÄÓéÀÖ¸±ÊÖ¡£


2.°²È«·çÏÕ£ºÈ¨ÏÞ¹ý¸ßµ¼Ö¶ñÒâ¶Áд¡¢É¾³ýËÁÒâÎļþ£»»¥ÁªÍø½ÓÈëÇé¿öÏÂÔâ·êÍøÂç¹¥»÷ÈëÇÖ£»Í¨¹ýÌáÐÑ´Ê×¢ÈëÎóÖ´ÐÐΣÏÕºÅÁÉõÖÁÊÕÊÜÖÇÄÜÌ壻Ã÷ÎÄ´æ´¢ÃÜÔ¿µÈµ¼ÖÂÓ×ÎÒÐÅϢй¶»ò±»ÇÔÈ¡¡£


3.Ó¦¶ÔÕ½Êõ£º¼ÓǿȨÏÞÖÎÀí£¬½öÔÊÐí½Ó¼û±ØÒªÄ¿Â¼£¬²»ÈݽӼûÃô¸ÐĿ¼£»ÓÅÏÈͨ¹ý¼ÓÃÜͨ·½ÓÈ룬²»ÈݷDZØÒª»¥ÁªÍø½Ó¼û£¬²»ÈݸßΣ²Ù×÷Ö¸Áî»òÔö³¤¶þ´ÎÈ·ÈÏ£»Ñϸñͨ¹ý¼ÓÃÜ·½Ê½´æ´¢APIÃÜÔ¿¡¢ÅäÖÃÎļþ¡¢Ó×ÎÒ³ÁÒªÐÅÏ¢µÈ¡£


£¨ËÄ£©½ðÈÚÂòÂô³¡¾°ÖØÒª´æÔÚÒý·¢ÃýÎóÂòÂôÉõÖÁÕË»§±»ÊÕÊܵÄ͹¹Î·çÏÕ


1.³¡¾°ÃèÊö£ºÍ¨¹ýÆóÒµ»òÓ×ÎÒ²¿Êð¡°ÁúϺ¡±£¬Å²ÓýðÈÚÓйØÀûÓýӿÚ£¬½øÐÐ×Ô¶¯»¯ÂòÂôÓë·çÏÕ½ÚÔ죬Ìá¸ßÁ¿»¯ÂòÂô¡¢ÖÇÄÜͶÑм°×ʲú×éºÏÖÎÀíЧÄÜ£¬ÊµÏÖÊг¡Êý¾Ýץȡ¡¢Õ½Êõ·ÖÎö¡¢ÂòÂôÖ¸ÁîÖ´ÐеÈÖ°ÄÜ¡£


2.°²È«·çÏÕ£ºÓ°ÏóͶ¶¾µ¼ÖÂÃýÎóÂòÂô£¬Éí·ÝÈÏÖ¤ÈÆ¹ýµ¼ÖÂÕË»§±»·¸·¨ÊÕÊÜ£»ÒýÈëÔ̺¬¶ñÒâ´úÂëµÄ²å¼þµ¼ÖÂÂòÂôƾ֤±»ÇÔÈ¡£»¼«¶ËÇé¿öÏÂÒò²»×ãÈÛ¶Ï»òÓ¦¼±»úÔ죬µ¼ÖÂÖÇÄÜÌåʧ¿ØÆµÈÔϵ¥µÈ·çÏÕ¡£


3.Ó¦¶ÔÕ½Êõ£ºÖ´ÐÐÍøÂç¸ôÀëÓë×îÓ×ȨÏÞ£¬¹Ø¹Ø·Ç±ØÒª»¥ÁªÍø¶Ë¿Ú£»³ÉÁ¢ÈËΪ¸´ºËºÍÈÛ¶ÏÓ¦¼±»úÔ죬¹Ø¼ü²Ù×÷Ôö³¤¶þ´ÎÈ·ÈÏ£»Ç¿»¯¹©¸øÁ´ÉóºË£¬Ê¹Óùٷ½×é¼þ²¢¶¨ÆÚ½¨¸´·ì϶£»ÂäʵȫÁ´Â·Éó¼ÆÓ밲ȫ¼à²â£¬ÊµÊ±·¢ÏÖ²¢´ëÖð²È«·çÏÕ¡£


¶þ¡¢°²È«Ê¹Óý¨Òé


£¨Ò»£©Ê¹Óùٷ½×îа汾¡£Òª´Ó¹Ù·½Çþ·ÏÂÔØ×îв»±ä°æ±¾£¬²¢¿ªÆô×Ô¶¯¸üÐÂÌáÐÑ£»ÔÚÉý¼¶Ç°±¸·ÝÊý¾Ý£¬Éý¼¶ºó³ÁÆô·þÎñ²¢ÑéÖ¤²¹¶¡ÊÇ·ñÉúЧ¡£²»ÒªÊ¹ÓõÚÈý·½¾µÏñ°æ±¾»òº¹Çà°æ±¾¡£


£¨¶þ£©Ñϸñ½ÚÔ컥ÁªÍøÂ¶³öÃæ¡£Òª¶¨ÆÚ×Ô²éÊÇ·ñ´æÔÚ»¥ÁªÍøÂ¶³öÇé¿ö£¬Ò»µ©·¢ÏÖÁ¢¼´ÏÂÏßÕû¸Ä¡£²»Òª½«¡°ÁúϺ¡±ÖÇÄÜÌåÊ·ý¶³öµ½»¥ÁªÍø£¬È·Ð軥ÁªÍø½Ó¼ûµÄÄܹ»Ê¹ÓÃSSHµÈ¼ÓÃÜͨ·£¬²¢Ï޶ȽӼûÔ´µØÖ·£¬Ê¹ÓÃÇ¿ÃÜÂë»òÖ¤Êé¡¢Ó²¼þÃÜÔ¿µÈÈÏÖ¤·½Ê½¡£


£¨Èý£©¶ÔÖÅ×îÓ×ȨÏÞ×¼Ôò¡£ÒªÆ¾¾ÝÒµÎñ±ØÒªÊÚÓèʵÏÖ¹¤×÷±ØÐëµÄ×îÓ×ȨÏÞ£¬¶Ôɾ³ýÎļþ¡¢·¢ËÍÊý¾Ý¡¢Åú¸ÄϵͳÅäÖõȳÁÒª²Ù×÷½øÐжþ´ÎÈ·ÈÏijÈËΪÉóÅú¡£ÓÅÏÈ˼¿¼ÔÚÈÝÆ÷»òÐé¹¹»úÖиôÀëÔËÐУ¬ÐγɶÀÁ¢µÄȨÏÞÇøÓò¡£²»ÒªÔÚ²¿ÊðʱʹÓÃÖÎÀíԱȨÏÞÕ˺Å¡£


£¨ËÄ£©ÉóÉ÷ʹÓü¼ÊõÊг¡¡£ÒªÉóÉ÷ÏÂÔØClawHub¡°¼¼Êõ°ü¡±£¬²¢ÔÚ×°ÖÃǰÉó²é¼¼Êõ°ü´úÂë¡£²»ÒªÊ¹ÓÃÒªÇó¡°ÏÂÔØZIP¡±¡¢¡°Ö´ÐÐshell¾ç±¾¡±»ò¡°ÊäÈëÃÜÂ롱µÄ¼¼Êõ°ü¡£


£¨Î壩·À±¸Éç»á¹¤³Ìѧ¹¥»÷ºÍä¯ÀÀÆ÷½Ù³Ö¡£ÒªÊ¹ÓÃä¯ÀÀÆ÷ɳÏä¡¢ÍøÒ³¹ýÂËÆ÷µÈÀ©´ó×èÖ¹¿ÉÒɾ籾£¬ÆôÓÃÈÕÖ¾Éó¼ÆÖ°ÄÜ£¬Óöµ½¿ÉÒÉÐÐΪÁ¢¼´¶Ï¿ªÍø¹Ø²¢³ÁÖÃÃÜÂë¡£²»Òªä¯ÀÀÀ´Àú²»Ã÷µÄÍøÕ¾¡¢µã»÷İÉúµÄÍøÒ³Á´½Ó¡¢¶ÁÈ¡²»³ÉÐÅÎĵµ¡£


£¨Áù£©³ÉÁ¢³¤Ð§·À»¤»úÔì¡£Òª¶¨ÆÚ²é³­²¢½¨²¹·ì϶£¬ÊµÊ±¹Ø×¢OpenClaw¹Ù·½°²È«²¼¸æ¡¢¹¤ÒµºÍÐÅÏ¢»¯²¿ÍøÂ簲ȫÍþвºÍ·ì϶ÐÅÏ¢¹²ÏíÆ½Ì¨µÈ·ì϶¿âµÄ·çÏÕÔ¤¾¯¡£µ³Õþ»ú¹Ø¡¢ÆóÊÂÒµµ¥ÔªºÍÓ×ÎÒÓû§Äܹ»½áºÏÍøÂ簲ȫ·À»¤¹¤¾ß¡¢Ö÷Á÷ɱ¶¾Èí¼þ½øÐÐʵʱ·À»¤£¬ÊµÊ±´ëÖÿÉÄÜ´æÔڵݲȫ·çÏÕ¡£²»Òª½ûÓþßÌåÈÕÖ¾Éó¼ÆÖ°ÄÜ¡£



¸½Â¼£º²¿ÃŰ²È«»ùÏß¼°ÅäÖòο¼


Ò»¡¢ÖÇÄÜÌ岿Êð


´´½¨OpenClawרÓÐЧ»§£¬ÇÐÎðʹÓÃsudo×飺


sudo adduser --shell /bin/rbash --disabled-password clawuser


ͨ¹ý´´½¨µÄרÓÐЧ»§µÇ¼²Ù×÷ϵͳ¡£


´´½¨ÊÜÏ޵ĺÅÁîĿ¼£¬²»ÈÝrm¡¢mv¡¢dd¡¢format¡¢powershellµÈ£º


sudo mkdir -p /home/clawuser/bin


sudo ln -s /bin/ls /home/clawuser/bin/ls


sudo ln -s /bin/echo /home/clawuser/bin/echo


Ç¿ÔìÉèÖàPATH ²¢Ö»¶Á£¬ÈçÔÚ /etc/profile.d/restricted_clawuser.shÅú¸ÄÅäÖãº


echo 'if [ "$USER" = "clawuser" ]; then export PATH=/home/clawuser/bin; readonly PATH; fi' | sudo tee /etc/profile.d/restricted_clawuser.sh


sudo chmod 644 /etc/profile.d/restricted_clawuser.sh


½ûÓÃrootµÇ¼£º


sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config


sudo systemctl restart sshd


¶þ¡¢ÏÞ¶È»¥ÁªÍø½Ó¼û


£¨Ò»£©Linux·þÎñÆ÷ÅäÖÃ


´´½¨×Ô½ç˵Á´£º


sudo iptables -N ALLOWED_IPS


Ôö³¤ÔÊÐíµÄIP£¨IPµØÖ·ÎªÊ¾Àý£¬²Ù×÷ʱÐè´úÌæÎªÏÖʵIPµØÖ·£©£º


sudo iptables -A ALLOWED_IPS -s 192.168.1.100 -j ACCEPT


sudo iptables -A ALLOWED_IPS -s 10.0.0.5 -j ACCEPT


sudo iptables -A ALLOWED_IPS -s 172.24.57.160 -j ACCEPT


sudo iptables -A ALLOWED_IPS -j RETURN


ÀûÓõ½SSH¶Ë¿Ú£º


sudo iptables -A INPUT -p tcp --dport 22 -j ALLOWED_IPS


sudo iptables -A INPUT -p tcp --dport 17477 -j ALLOWED_IPS


´Ë±í£¬¿É²Î¿¼ÉÏÊöºÅÁî¹Ø¹ØÒÔ϶˿ڻ¥ÁªÍø½Ó¼û»òÉèÖÃIPµØÖ·°×Ãûµ¥£ºTelnet£¨23£©¡¢WindowsÎļþ¹²Ïí£¨135¡¢137¡¢138¡¢139¡¢445£©¡¢WindowsÔ¶³Ì×ÀÃæ£¨3389£©¡¢Ô¶³Ì×ÀÃæ½ÚÔ죨5900-5910£©¡¢Êý¾Ý¿âÀà¶Ë¿Ú£¨3306¡¢5432¡¢6379¡¢27017£©¡£


£¨¶þ£©VPN½ÓÈëµÄÇé¿öÏÂÅäÖÃ


½«OpenClaw Gateway°ó¶¨127.0.0.1£¬ÇÐÎðÖ±½Ó°ó¶¨µ½0.0.0.0¡£


¹Ø¹Ø18789¶Ë¿Ú£º


sudo ufw deny 18789


Ô¶³Ì½Ó¼ûʱǿÔìʹÓÃVPN²¢ÆôÓÃGatewayÈÏÖ¤£¨ÔÚopenclaw.jsonÖÐÉèÖÃgateway.auth.mode: "token"¼°Ç¿ÁîÅÆ£©¡£


Èý¡¢¿ªÆô¾ßÌåÈÕÖ¾


¿ªÆôÈÕÖ¾¼Í¼£º


openclaw gateway --log-level debug >> /var/log/openclaw.log 2>&1


ËÄ¡¢Îļþϵͳ½Ó¼û½ÚÔì


ÔÚDocker²¿ÊðÅäÖÃÎļþ(docker-compose.yml)ÖУ¬ÀûÓÃvolumes²ÎÊý½«ÏµÍ³¹Ø¼üĿ¼¹ÒÔØÎª:ro£¨Ö»¶Á£©Ä£Ê½£¬½ö±£ÁôÌØ¶¨µÄ/workspaceΪ¿Éд״̬¡£


ÔÚËÞÖ÷»úϵͳ²ã£¬Í¨¹ýchmod 700Ö¸Áî¶Ô˽ÃÜÊý¾ÝĿ¼ִÐÐÇ¿Ôì½Ó¼û½ÚÔ죺


sudo chmod 700 /path/to/your/workspace


Îå¡¢µÚÈý·½¼¼ÊõÉó²é


×°ÖÃǰִÐм¼ÊõÉó²éºÅÁ


openclaw skills info


²¢Éó²é~/.openclaw/skills//SKILL.mdÎļþ£¬È·ÈÏÎÞ¶ñÒâÖ¸ÁÈçcurl¡¢bash£©¡£


ÓÅÏÈÑ¡ÓÃÄÚÖÃ55¸öSkill»òÉçÇø¾«Ñ¡ÁÐ±í£¨Èçawesome-openclaw-skills£©¡£


Áù¡¢°²È«×Ô¼ì


¶¨ÆÚÔËÐа²È«Éó¼ÆºÅÁ


openclaw security audit


Õë¶ÔÉ󼯷¢ÏֵݲȫÒþ»¼£¬ÈçÍø¹ØÈÏ֤¶³ö¡¢ä¯ÀÀÆ÷½ÚÔì¶³öµÈ£¬ÊµÊ±ÒÀÕÕÉÏÊö°²È«»ùÏß¼°ÅäÖòο¼¡¢¹Ù·½ÊÖ²áµÈ½øÐдëÖá£


Æß¡¢¸üа汾


ÔËÐа汾¸üкÅÁ


openclaw update


°Ë¡¢Ð¶ÔØ


´ò¿ªÖÕ¶Ë£¬Ö´ÐÐɾ³ýºÅÁ


openclaw uninstall


ʹÓÃÊó±ê¸ßµÍÒÆ¶¯¹â±ê£¬°´¿Õ¸ñ¼ü¹´Ñ¡ËùÓÐÑ¡Ï¶øºó°´»Ø³µ¼üÈ·ÈÏ¡£


Ñ¡Ôñyes²¢°´»Ø³µ£¬´ËºÅÁî»á×Ô¶¯É¾³ýOpenClawµÄ¹¤×÷Ŀ¼¡£


Ð¶ÔØnpm°ü£º


1. Ê¹ÓÃnpm×°ÖÃopenclaw¶ÔÓ¦Ð¶ÔØºÅÁ


npm rm -g openclaw


2. ÈôÊÇʹÓÃpnpm×°ÖÃopenclaw¶ÔÓ¦Ð¶ÔØºÅÁ


pnpm remove -g openclaw


3. ÈôÊÇʹÓÃbun×°ÖÃopenclaw¶ÔÓ¦Ð¶ÔØºÅÁ


bun remove -g openclaw




×ªÔØ×Ô£ºÍøÂ簲ȫÍþвºÍ·ì϶ÐÅÏ¢¹²ÏíÆ½Ì¨¹«¼ÒºÅ