Cyber Security Engineer
Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle tim...
Rank
62
Safety
84
Downloads
552
Updated
Apr 15, 2026
Version
0.1.4
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 552 downloads reported by the source. Last updated 4/15/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Apr 15, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Apr 15, 2026
- Adoption signal
- 552 downloadsadoption · observed Apr 15, 2026
- Latest release
- 0.1.4release · observed Feb 15, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install kn76xzywt869tsh3r3tjtk1ybs814s22:cyber-security-engineer- Install using `clawhub skill install kn76xzywt869tsh3r3tjtk1ybs814s22:cyber-security-engineer` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/FletcherFrimpong/cyber-security-engineer before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/snapshot"
Documentation
CLAWHUB
66,317 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: cyber-security-engineer description: Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle timeout controls, port + egress monitoring, and ISO 27001/NIST-aligned compliance reporting with mitigations. --- # Cyber Security Engineer ## Requirements **Env vars (optional, but documented):** - `OPENCLAW_REQUIRE_POLICY_FILES` - `OPENCLAW_REQUIRE_SESSION_ID` - `OPENCLAW_TASK_SESSION_ID` - `OPENCLAW_APPROVAL_TOKEN` - `OPENCLAW_UNTRUSTED_SOURCE` - `OPENCLAW_VIOLATION_NOTIFY_CMD` - `OPENCLAW_VIOLATION_NOTIFY_ALLOWLIST` **Tools:** `python3` and one of `lsof`, `ss`, or `netstat` for port/egress checks. **Policy files (admin reviewed):** - `~/.openclaw/security/approved_ports.json` - `~/.openclaw/security/command-policy.json` - `~/.openclaw/security/egress_allowlist.json` - `~/.openclaw/security/prompt-policy.json` Implement these controls in every security-sensitive task: 1. Keep default execution in normal (non-root) mode. 2. Request explicit user approval before any elevated command. 3. Scope elevation to the minimum command set required for the active task. 4. Drop elevated state immediately after the privileged command completes. 5. Expire elevated state after 30 idle minutes and require re-approval. 6. Monitor listening network ports and flag insecure or unapproved exposure. 7. Monitor outbound connections and flag destinations not in the egress allowlist. 8. If no approved baseline exists, generate one with `python3 scripts/generate_approved_ports.py`, then review and prune. 9. Benchmark controls against ISO 27001 and NIST and report violations with mitigations. ## Non-Goals (Web Browsing) - Do not use web browsing / web search as part of this skill. Keep assessments and recommendations based on local host/OpenClaw state and the bundled references in this skill. ## Files To Use - `references/least-privilege-policy.md` - `references/port-monitoring-policy.md` - `references/compliance-controls-map.json` - `references/approved_ports.template.json` - `references/command-policy.template.json` - `references/prompt-policy.template.json` - `references/egress-allowlist.template.json` - `scripts/preflight_check.py` - `scripts/root_session_guard.py` - `scripts/audit_logger.py` - `scripts/command_policy.py` - `scripts/prompt_policy.py` - `scripts/guarded_privileged_exec.py` - `scripts/install-openclaw-runtime-hook.sh` - `scripts/port_monitor.py` - `scripts/generate_approved_ports.py` - `scripts/egress_monitor.py` - `scripts/notify_on_violation.py` - `scripts/compliance_dashboard.py` - `scripts/live_assessment.py` ## Behavior - Never keep root/elevated access open between unrelated tasks. - Never execute root commands without an explicit approval step in the current flow. - Enforce command allow/deny policy when configured. - Require confirmation when untrusted content sources are detected (`OPENCLAW_UNTRUSTED_SOURCE=1` + prompt policy). - Enfo
_meta.json
{
"ownerId": "kn76xzywt869tsh3r3tjtk1ybs814s22",
"slug": "cyber-security-engineer",
"version": "0.1.4",
"publishedAt": 1771154770584
}references/approved_ports.template.json
[
{
"port": 18789,
"protocol": "tcp",
"command": "node",
"comment": "OpenClaw gateway (example). Remove if not applicable."
}
]references/command-policy.template.json
{
"allow": [
"^openclaw\\b",
"^python3\\b"
],
"deny": [
"\\brm\\s+-rf\\b",
"\\bshutdown\\b",
"\\breboot\\b"
]
}references/compliance-controls-map.json
[
{
"check_id": "privilege_approval_required",
"title": "Approval required before elevated access",
"iso27001": ["A.5.15", "A.5.18"],
"nist": ["PR.AA-01", "PR.AA-05"],
"default_risk": "high",
"expected_state": "Every privileged action requires explicit user approval."
},
{
"check_id": "least_privilege_enforced",
"title": "Least privilege execution mode",
"iso27001": ["A.5.15", "A.5.18"],
"nist": ["PR.AA-01", "PR.PS-01"],
"default_risk": "high",
"expected_state": "Default mode is non-root and elevated rights are scoped and short-lived."
},
{
"check_id": "elevation_timeout_30m",
"title": "Elevated session idle timeout",
"iso27001": ["A.8.2", "A.8.15"],
"nist": ["PR.AA-03", "DE.CM-01"],
"default_risk": "medium",
"expected_state": "Elevated session expires after 30 minutes of inactivity."
},
{
"check_id": "audit_logging_privileged_actions",
"title": "Privileged action audit logging",
"iso27001": ["A.8.15", "A.8.16"],
"nist": ["DE.AE-03", "DE.CM-01"],
"default_risk": "medium",
"expected_state": "All elevated approvals, commands, and privilege drops are logged."
},
{
"check_id": "open_ports_approved",
"title": "Open ports baseline approval",
"iso27001": ["A.8.20", "A.8.21"],
"nist": ["PR.PS-02", "DE.CM-01"],
"default_risk": "medium",
"expected_state": "All listening ports are approved and business-justified."
},
{
"check_id": "insecure_ports_remediated",
"title": "Insecure ports remediated",
"iso27001": ["A.8.20", "A.8.21"],
"nist": ["PR.PS-02", "PR.DS-02"],
"default_risk": "high",
"expected_state": "Insecure legacy ports are closed or migrated to secure alternatives."
},
{
"check_id": "channel_allowlist_configured",
"title": "Channel allowlist configured",
"iso27001": ["A.5.15", "A.5.16"],
"nist": ["PR.AA-02"],
"default_risk": "high",
"expected_state": "Inbound channels restrict senders via allowlists."
},
{
"check_id": "group_mentions_required",
"title": "Group mention requirement",
"iso27001": ["A.5.16"],
"nist": ["PR.AA-04"],
"default_risk": "medium",
"expected_state": "Group chats require explicit mention before agent responds."
},
{
"check_id": "gateway_loopback_only",
"title": "Gateway bound to loopback",
"iso27001": ["A.8.9", "A.8.10"],
"nist": ["PR.IP-01"],
"default_risk": "high",
"expected_state": "Gateway runs local/loopback with token auth."
},
{
"check_id": "secrets_permissions_hardened",
"title": "Secrets and config permissions hardened",
"iso27001": ["A.8.11"],
"nist": ["PR.DS-01"],
"default_risk": "medium",
"expected_state": "OpenClaw config and secrets are not world/group readable."
},
{
"check_id": "runtime_privilege_hook_installed",
"title": "Runtime privileged execution hook installed",
"iso27001": ["A.5.15", "A.5.18"],
"nist": ["PR.AA-01"]AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/FletcherFrimpong/cyber-security-engineer",
"sourceUrl": "https://clawhub.ai/FletcherFrimpong/cyber-security-engineer",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "552 downloads",
"href": "https://clawhub.ai/FletcherFrimpong/cyber-security-engineer",
"sourceUrl": "https://clawhub.ai/FletcherFrimpong/cyber-security-engineer",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-04-15T00:45:39.800Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.4",
"href": "https://clawhub.ai/FletcherFrimpong/cyber-security-engineer",
"sourceUrl": "https://clawhub.ai/FletcherFrimpong/cyber-security-engineer",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-15T11:26:10.584Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.4",
"description": "Harden notify_on_violation: remove shell execution; require allowlisted notifier executable.",
"href": "https://clawhub.ai/FletcherFrimpong/cyber-security-engineer",
"sourceUrl": "https://clawhub.ai/FletcherFrimpong/cyber-security-engineer",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-15T11:26:10.584Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
