other

OpenClaw gateway denial report

2026-04-24

OpenClaw gateway denial report

Generated: 2026-04-23 17:00 PDT

Window analyzed: 2026-04-16 17:00:20 PDT through 2026-04-23 17:00:20 PDT, rolling 7 days ending at analysis time.

Findings summary

Total denial count

25 true logged denial events

Daily counts

Local dayLogged denials
2026-04-164
2026-04-170
2026-04-180
2026-04-190
2026-04-200
2026-04-211
2026-04-226
2026-04-2314
Total25

Counts by command family

Command familyTotal04-1604-1704-1804-1904-2004-2104-2204-23
pwd/ls probe720000005
find scan500000041
python3 heredoc500000014
python3 script/file510000013
cat file read100000001
openclaw cli100000100
ripgrep search110000000

Top exact command shapes

Command shapeTotalBy day
python3 heredoc504-22: 1, 04-23: 4
`find records -maxdepth 2 -type fsortsed -n 1,120p`204-22: 2
ls -1 $WORKSPACE/data/lantronix-uas-workbench-phase1/records/companies204-23: 2
pwd204-16: 1, 04-23: 1
python3 lantronix_backfill_filter_fields.py204-23: 2
cat $WORKSPACE/data/lantronix-uas-workbench-phase1/records/companies/company-{...}.json104-23: 1
`find $WORKSPACE/data/lantronix-uas-workbench-phase1 -maxdepth 3 -type fsort`104-22: 1
`find $WORKSPACE/data/lantronix-uas-workbench-phase1/records -maxdepth 2 (companies/evidence/customer-segments)sortsed -n '1,60p'`104-22: 1
`find $WORKSPACE/scripts -maxdepth 1 -type fsed 's#^#/##'sort`104-23: 1
ls $WORKSPACE/scripts/lantronix_broader_migrate.py104-23: 1

Representative examples

  1. 2026-04-16 17:02:05 PDT
  1. 2026-04-21 21:35:27 PDT
  1. 2026-04-22 16:30:57 PDT
  1. 2026-04-23 10:45:11 PDT
  1. 2026-04-23 11:34:46 PDT
  1. 2026-04-23 16:39:37 PDT

True denials versus excluded nearby events

Counted as true denials

Only records that explicitly logged:

These records carry a timestamp, a gateway id, and the denied command shape. They are the cleanest command-level evidence found.

Explicitly excluded from the 25 count

The following were observed but not counted because they are related failures, not the same thing as a direct logged denial record:

  1. Sandbox-runtime errors in /tmp/openclaw/openclaw-2026-04-23.log
  1. Approval followup dispatch warnings in /tmp/openclaw/openclaw-2026-04-23.log
  1. Artifact text or analysis text that quoted denial strings

Evidence paths and sources used

Config and gateway access

Session index

Denial-bearing session files

Standalone gateway log files checked

Uncertainties and limits

Recommendation

Keep exec security unchanged for now. You now have a clean evidence-backed baseline: 25 actual logged gateway denial events in the last 7 rolling days, all approval-timeout, concentrated on 2026-04-22 and 2026-04-23, mostly read-only probes and data-inspection commands. If you want the next step, add a dedicated denial log sink that records timestamp, command, deny reason, and session key in one place. That would remove the need to reconstruct counts from session history.

Validation summary