Security Sentinel
Scan the workspace for security vulnerabilities, exposed secrets, and misconfigurations. Skill: Security Sentinel Owner: autogame-17 Summary: Scan the workspace for security vulnerabilities, exposed secrets, and misconfigurations. Tags: latest:1.0.1 Version history: v1.0.1 | 2026-02-17T16:06:20.900Z | user batch sync Archive index: Archive v1.0.1: 6 files, 7850 bytes Files: _meta.json (136b), index.js (4884b), package-lock.json (5518b), package.json (305b), scan.js (5657b), SKILL.md (1456b) File v1.0.1:S
Rank
62
Safety
84
Downloads
1.5k
Updated
Oct 10, 2026
Version
1.0.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.5K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.0.1release · observed Feb 17, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: medium.
clawhub skill install s174qjf2384d46r16zkn04qam183hbm3:security-sentinel- Node.js workspace detected. Install dependencies securely: run `npm ci --ignore-scripts` to prevent post-install lifecycle triggers from running arbitrary code, then selectively audit the dependency tree.
- Setup complexity is MEDIUM. Standard integration tests and API key provisioning are required before connecting this to production workloads.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-autogame-17-security-sentinel/snapshot"
Documentation
CLAWHUB
7,938 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: security-sentinel
description: Scan the workspace for security vulnerabilities, exposed secrets, and misconfigurations.
---
# Security Sentinel
A unified security scanner for OpenClaw workspaces. Detects vulnerabilities in dependencies (npm audit), exposed secrets (regex patterns), and unsafe file permissions.
## Usage
### CLI
Run a full security scan:
```bash
node skills/security-sentinel/index.js
```
This will output a JSON report to stdout.
If risks are detected (high/critical vulnerabilities, secrets, or bad permissions), it exits with code 1.
### Options
- `--skip-audit`: Skip the npm audit step (faster)
- `--no-fail`: Do not exit with code 1 even if risks are detected (useful for monitoring only)
### Programmatic
```javascript
const sentinel = require('./skills/security-sentinel');
const report = await sentinel.scan();
if (report.status === 'risk_detected') {
console.error('Security issues found:', report);
}
```
## Features
1. **Dependency Audit**: Runs `npm audit` to check `package.json` dependencies for known CVEs.
2. **Secret Detection**: Scans workspace files for patterns resembling API keys, passwords, and private keys.
3. **Permission Check**: Verifies critical files (`package.json`, `.env`) are not world-writable.
## Configuration
- **Ignored Paths**: `node_modules`, `.git`, `logs`, `temp`, `.openclaw/cache`.
- **Secret Patterns**: Generic API Key, Password, Private Key, Feishu App Secret._meta.json
{
"ownerId": "kn7apafdj4thknczrgxdzfd2v1808svf",
"slug": "security-sentinel",
"version": "1.0.1",
"publishedAt": 1771344380900
}package-lock.json
{
"name": "security-sentinel",
"version": "1.0.0",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "security-sentinel",
"version": "1.0.0",
"dependencies": {
"fs-extra": "^11.1.0",
"glob": "^8.1.0"
}
},
"node_modules/balanced-match": {
"version": "1.0.2",
"resolved": "https://registry.npmjs.org/balanced-match/-/balanced-match-1.0.2.tgz",
"integrity": "sha512-3oSeUO0TMV67hN1AmbXsK4yaqU7tjiHlbxRDZOpH0KW9+CeX4bRAaX0Anxt0tx2MrpRpWwQaPwIlISEJhYU5Pw==",
"license": "MIT"
},
"node_modules/brace-expansion": {
"version": "2.0.2",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.0.2.tgz",
"integrity": "sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==",
"license": "MIT",
"dependencies": {
"balanced-match": "^1.0.0"
}
},
"node_modules/fs-extra": {
"version": "11.3.3",
"resolved": "https://registry.npmjs.org/fs-extra/-/fs-extra-11.3.3.tgz",
"integrity": "sha512-VWSRii4t0AFm6ixFFmLLx1t7wS1gh+ckoa84aOeapGum0h+EZd1EhEumSB+ZdDLnEPuucsVB9oB7cxJHap6Afg==",
"license": "MIT",
"dependencies": {
"graceful-fs": "^4.2.0",
"jsonfile": "^6.0.1",
"universalify": "^2.0.0"
},
"engines": {
"node": ">=14.14"
}
},
"node_modules/fs.realpath": {
"version": "1.0.0",
"resolved": "https://registry.npmjs.org/fs.realpath/-/fs.realpath-1.0.0.tgz",
"integrity": "sha512-OO0pH2lK6a0hZnAdau5ItzHPI6pUlvI7jMVnxUQRtw4owF2wk8lOSabtGDCTP4Ggrg2MbGnWO9X8K1t4+fGMDw==",
"license": "ISC"
},
"node_modules/glob": {
"version": "8.1.0",
"resolved": "https://registry.npmjs.org/glob/-/glob-8.1.0.tgz",
"integrity": "sha512-r8hpEjiQEYlF2QU0df3dS+nxxSIreXQS1qRhMJM0Q5NDdR386C7jb7Hwwod8Fgiuex+k0GFjgft18yvxm5XoCQ==",
"deprecated": "Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting [email protected]",
"license": "ISC",
"dependencies": {
"fs.realpath": "^1.0.0",
"inflight": "^1.0.4",
"inherits": "2",
"minimatch": "^5.0.1",
"once": "^1.3.0"
},
"engines": {
"node": ">=12"
},
"funding": {
"url": "https://github.com/sponsors/isaacs"
}
},
"node_modules/graceful-fs": {
"version": "4.2.11",
"resolved": "https://registry.npmjs.org/graceful-fs/-/graceful-fs-4.2.11.tgz",
"integrity": "sha512-RbJ5/jmFcNNCcDV5o9eTnBLJ/HszWV0P73bc+Ff4nS/rJj+YaS6IGyiOL0VoBYX+l1Wrl3k63h/KrH+nhJ0XvQ==",
"license": "ISC"
},
"node_modules/inflight": {
"version": "1.0.6",
"resolved": "https://registry.npmjs.org/inflight/-/inflight-1.0.6.tgz",
"intepackage.json
{
"name": "security-sentinel",
"version": "1.0.1",
"description": "Unified security scanner for OpenClaw workspace (dependencies, secrets, permissions).",
"main": "index.js",
"scripts": {
"test": "node index.js"
},
"dependencies": {
"fs-extra": "^11.1.0",
"glob": "^8.1.0"
}
}AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/autogame-17/skills/security-sentinel",
"sourceUrl": "https://clawhub.ai/autogame-17/skills/security-sentinel",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T11:04:27.504Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-autogame-17-security-sentinel/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-autogame-17-security-sentinel/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T11:04:27.504Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.5K downloads",
"href": "https://clawhub.ai/autogame-17/security-sentinel",
"sourceUrl": "https://clawhub.ai/autogame-17/security-sentinel",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T11:04:27.504Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.1",
"href": "https://clawhub.ai/autogame-17/security-sentinel",
"sourceUrl": "https://clawhub.ai/autogame-17/security-sentinel",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-17T16:06:20.900Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-autogame-17-security-sentinel/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-autogame-17-security-sentinel/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.1",
"description": "batch sync",
"href": "https://clawhub.ai/autogame-17/security-sentinel",
"sourceUrl": "https://clawhub.ai/autogame-17/security-sentinel",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-17T16:06:20.900Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
