OpenClawSkills
GitHub
Gateway / 运用 • TutorialHeader.readTime

沙盒、工具策略、以及提升

工具被阻止的原因:沙盒运行时、工具允许/拒绝策略和提升执行门控

OpenClaw has three related (but different) controls:

1. ''Sandbox'' (''agents.defaults.sandbox.*'' / ''agents.list[].sandbox.*'') decides ''where tools run'' (Docker vs host).

2. ''Tool policy'' (''tools.*'', ''tools.sandbox.tools.*'', ''agents.list[].tools.*'') decides ''which tools are available/allowed''.

3. ''Elevated'' (''tools.elevated.*'', ''agents.list[].tools.elevated.*'') is an ''exec-only escape hatch'' to run on the host when sandboxed.

Tutorial.step

Quick debug

使用检查器查看 OpenClaw 实际在做什么:

Bash
openclaw sandbox explain
openclaw sandbox explain --session agent:main:main
openclaw sandbox explain --agent work
openclaw sandbox explain --json

以下但输出被:

- effective sandbox mode/scope/workspace access

- whether the session is currently sandboxed (main vs non-main)

- effective sandbox tool allow/deny (and whether it came from agent/global/default)

- elevated gates and fix-it key paths

Tutorial.step

Sandbox: where tools run

沙盒化是 ''agents.defaults.sandbox.mode'' 在控制被:

- ''"off"'':全部但主机在被执行。

- ''"non-main"'':非主要会话仅但沙盒化被(群组/渠道在的一般的那"驚机")。

- ''"all"'':全部但沙盒化被。

See Sandboxing for the full matrix (scope, workspace mounts, images).

#

Tutorial.step

Bind mounts (security quick check)

- ''docker.binds'' pierces the sandbox filesystem: whatever you mount is visible inside the container with the mode you set ('':ro'' or '':rw'').

- Default is read-write if you omit the mode; prefer :ro for source/secrets.

- ''scope: "shared"'' 是代理每个绑定忽略执行(全局绑定仅適用被)。

- Binding /var/run/docker.sock effectively hands host control to the sandbox; only do this intentionally.

- Workspace access (''workspaceAccess: "ro"''/''"rw"'') is independent of bind modes.

Tutorial.step

Tool policy: which tools exist/are callable

Two layers matter:

- ''Tool profile'': ''tools.profile'' and ''agents.list[].tools.profile'' (base allowlist)

- ''Provider tool profile'': ''tools.byProvider[provider].profile'' and ''agents.list[].tools.byProvider[provider].profile''

- ''全局/代理每个工具策略'':''tools.allow''/''tools.deny'' 和 ''agents.list[].tools.allow''/''agents.list[].tools.deny''

- ''提供商工具策略'':''tools.byProvider[provider].allow/deny'' 和 ''agents.list[].tools.byProvider[provider].allow/deny''

- ''Sandbox tool policy'' (only applies when sandboxed): ''tools.sandbox.tools.allow''/''tools.sandbox.tools.deny'' and ''agents.list[].tools.sandbox.tools.*''

経験則:

- ''deny'' always wins.

- If ''allow'' is non-empty, everything else is treated as blocked.

- Tool policy is the hard stop: /exec cannot override a denied exec tool.

- /exec only changes session defaults for authorized senders; it does not grant tool access.

- Provider tool keys accept either ''provider'' (e.g. ''google-antigravity'') or ''provider/model'' (e.g. ''openai/gpt-5.2'').

#

Tutorial.step

工具群组(短縮形)

Tool policies (global, agent, sandbox) support ''group:*'' entries that expand to multiple tools:

Json5
{
  tools: {
    sandbox: {
      tools: {
        allow: ["group:runtime", "group:fs", "group:sessions", "group:memory"],
      },
    },
  },
}

利用可能那群组:

- ''group:runtime'':''exec''、''bash''、''process''

- ''group:fs'':''read''、''write''、''edit''、''apply_patch''

- ''group:sessions'':''sessions_list''、''sessions_history''、''sessions_send''、''sessions_spawn''、''session_status''

- ''group:memory'':''memory_search''、''memory_get''

- ''group:ui'':''browser''、''canvas''

- ''group:automation'':''cron''、''gateway''

- ''group:messaging'':''message''

- ''group:nodes'':''nodes''

- ''group:openclaw'':所有組见入见 OpenClaw 工具(提供商插件除可)

Tutorial.step

提升:运行专用「主机在运行」

提升是添加的工具付与不会执行。''exec'' 在仅影響执行。

- If you're sandboxed, /elevated on (or exec with elevated: true) runs on the host (approvals may still apply).

- Use /elevated full to skip exec approvals for the session.

- If you're already running direct, elevated is effectively a no-op (still gated).

- Elevated is not skill-scoped and does not override tool allow/deny.

- /exec is separate from elevated. It only adjusts per-session exec defaults for authorized senders.

Gates:

- 启用:''tools.elevated.enabled''(以及选项在 ''agents.list[].tools.elevated.enabled'')

- Sender allowlists: ''tools.elevated.allowFrom.<provider>'' (and optionally ''agents.list[].tools.elevated.allowFrom.<provider>'')

See Elevated Mode for details.

Tutorial.step

一般的那「沙盒刑務所」的修復

#

Tutorial.step

Common "sandbox jail" fixes (continued)

修復密钥(1 次选择):

- 沙盒禁用在执行:''agents.defaults.sandbox.mode=off''(或代理每个 ''agents.list[].sandbox.mode=off'')

- 工具沙盒在允许执行:

- ''tools.sandbox.tools.deny''(或代理每个 ''agents.list[].tools.sandbox.tools.deny'')从删除执行

- 或 ''tools.sandbox.tools.allow''(或代理每个允许)在添加执行

#

Tutorial.step

Non-main session sandboxing

In ''"non-main"'' mode, group/channel keys are not main. Use the main session key (shown by ''sandbox explain'') or switch mode to ''"off"''.