Claim this agent
agentCLAWHUBUnverified

ClawSecCheck — OpenClaw Security Self-Audit

Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills...

OpenClaw

Rank

62

Safety

84

Downloads

5.2k

Updated

Oct 9, 2026

Version

4.3.1

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 5.2K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
5.2K downloadsadoption · observed Oct 9, 2026
Latest release
4.3.1release · observed Sep 29, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17fbcrwqqa08r1f5aqqcxzh7s88zmmc:clawseccheck
  1. Install using `clawhub skill install s17fbcrwqqa08r1f5aqqcxzh7s88zmmc:clawseccheck` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/gl0di/clawseccheck before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/snapshot"

Documentation

CLAWHUB

160,000 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: clawseccheck
version: 4.3.1
description: Free, local, read-only security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, logs, agent session logs, and installed skills, plus a bounded host-security scan; writes only its own local report/history (removable with --purge). Grades your setup A-F when all five check layers ran, naming what's missing otherwise. --monitor records a local baseline so every later run alerts on what changed - a new MCP server, an edited skill, config drift, a finding that appeared or cleared. No API key, no network calls; the only external command it runs is your own read-only openclaw security audit (skip with --no-native). Only two opt-in flags write anything: --apply-ignore-proposals and --pdf. Use it when you want to check or audit your OpenClaw agent's security, find prompt-injection or misconfiguration risks, see your A-F security score, watch your OpenClaw setup for changes, or ask what changed since the last check.
license: MIT
metadata: {"openclaw":{"emoji":"\ud83e\udd9e","os":["darwin","linux","win32"],"user-invocable":true},"display_name":{"en":"ClawSecCheck \u2014 OpenClaw Security Self-Audit"},"display_description":{"en":"Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills \u2014 read-only against your OpenClaw setup, plus a bounded host-security scan; writes only its own local report/history (removable with --purge). Reports the most urgent holes, and grades your setup A\u2013F when all five check layers ran \u2014 short of that it names the missing layers instead of printing a number. It is built to be run again, not once: --monitor records a local baseline and every later run alerts on what changed \u2014 a new MCP server, a new or edited skill, config drift, a finding that appeared or cleared. Nothing here ever changes your OpenClaw config, a skill, or a bootstrap file: only two opt-in flags write inside your OpenClaw setup at all \u2014 --apply-ignore-proposals (confirmation-gated; appends only suppressions you approved to .clawseccheckignore) and a no-PATH --pdf (auto-resolves inside your OpenClaw home when its own attachment directory exists). No API key; the scanner itself makes no network calls, and the single external command it can run is your own read-only openclaw security audit (skip it with --no-native). Use it when you want to check or audit your OpenClaw agent's security, find prompt-injection or misconfiguration risks, see your A\u2013F security score, watch your OpenClaw setup for changes, or ask what changed since the last check."},"tags":{"en":["security","openclaw","ai-agent","audit","prompt-injection","llm-security","self-audit","sarif"]}}
---

<!-- markdownlint-disable MD040 MD032 -->
<!-- Formatting-only rules (fence language tags, blanks around lists) are relaxed
     for this agent-facing manifest, whose fence/list layout is delibera

docs/README.md

# ClawSecCheck documentation

Reading order depends on who you are:

## I just want to use it

1. [Project README](../README.md) - what it is, quick start, trust story
2. [USAGE.md](USAGE.md) - the user guide: recipes, monitoring modes, and trust details
3. [FAQ.md](FAQ.md) - common questions, including "what if the host is already
   compromised?"
4. [TROUBLESHOOTING.md](TROUBLESHOOTING.md) - when ClawSecCheck itself won't run,
   crashes, or OpenClaw doesn't see it (not a question about your audited setup)

## I want to understand what it checks and why

1. [CHECKS.md](CHECKS.md) - the generated catalog of every check: verdict
   semantics, remediation, compound risk chains
2. [THREAT_COVERAGE.md](THREAT_COVERAGE.md) - mapping to OWASP LLM Top 10 (2025)
   and OWASP Agentic threat classes
3. [ATTESTATION.md](ATTESTATION.md) - the `--ask` / `--attest` self-report
   layer: what it adds, what it can't prove
4. [../SECURITY_MODEL.md](../SECURITY_MODEL.md) - ClawSecCheck's own capability
   surface, least-privilege posture, and self-defense

## I want the reasoning behind a design decision

Analysis and decision records. They change no code and are not a reference -
read one when you want to know *why* something is the way it is.

1. [design/severity-separability.md](design/severity-separability.md) - why
   FAIL-only recall is roughly half a static peer's, measured on
   SkillTrustBench, and what the recommendation costs
2. [design/judge-topology.md](design/judge-topology.md) - why the LLM judge
   lives in the host agent and never inside the scanner
3. [design/agent-knowledge-enrichment.md](design/agent-knowledge-enrichment.md) -
   whether that agent may add what it knows to a finding, and the four gates
   that bound it

## I want to integrate it

1. [OUTPUT_SCHEMA.md](OUTPUT_SCHEMA.md) - the frozen `--json` / SARIF contract
2. [USAGE.md - CI / automation](USAGE.md#ci--automation) - exit codes,
   `--fail-on`, SARIF upload

## I am the agent running this skill

These are loaded on demand from [SKILL.md](../SKILL.md), not read front to back.
They live outside it so its always-in-context body stays small.

1. [FLOW_CHOICES.md](FLOW_CHOICES.md) - the Step 5 branch protocols
2. [ISOLATION.md](ISOLATION.md) - the context firewall for untrusted content

## I want to contribute

1. [CONTRIBUTING.md](https://github.com/gl0di/clawseccheck/blob/main/CONTRIBUTING.md) - ground rules, dev setup, PR flow
2. [THREAT_INTAKE.md](THREAT_INTAKE.md) - which threat sources are watched, and the
   five-bucket triage that decides what a new signal actually changes
3. [CHECK_AUTHORING.md](CHECK_AUTHORING.md) - how to write a new check
4. [RELEASING.md](RELEASING.md) - the maintainer release protocol

## Reporting

- Bugs and false positives -> [GitHub issues](https://github.com/gl0di/clawseccheck/issues)
- Vulnerabilities -> [../SECURITY.md](../SECURITY.md) (private reporting)

README.md

<p align="center">
  <img src="docs/assets/banner-readme.png" alt="ClawSecCheck - local security audit for your OpenClaw agent, read-only against your config" width="820">
</p>

<p align="center">
  <b>Is your OpenClaw agent safe? Ask it - you get a straight answer in words, right in the chat, and an honest A-F grade once all five audit layers have run.</b><br>
  <sub><i>The claw that checks your claws.</i></sub>
</p>

<p align="center">
  <a href="https://github.com/gl0di/clawseccheck/releases"><img src="https://img.shields.io/github/v/tag/gl0di/clawseccheck?label=version&color=E34234&labelColor=2b2b2b" alt="version"></a>
  <a href="https://github.com/gl0di/clawseccheck/actions/workflows/ci.yml"><img src="https://github.com/gl0di/clawseccheck/actions/workflows/ci.yml/badge.svg" alt="CI"></a>
  <a href="https://clawhub.ai/gl0di/skills/clawseccheck"><img src="https://img.shields.io/badge/ClawHub-clawseccheck-FF6B47?labelColor=2b2b2b" alt="ClawHub"></a>
  <img src="https://img.shields.io/badge/python-3.9%2B-E8A33D?labelColor=2b2b2b" alt="Python 3.9+">
  <a href="LICENSE"><img src="https://img.shields.io/badge/License-MIT-E34234?labelColor=2b2b2b" alt="License: MIT"></a>
</p>

<p align="center">
  <picture>
    <source media="(prefers-color-scheme: dark)" srcset="docs/assets/stats-dark.svg">
    <img src="docs/assets/stats-light.svg" alt="229 security checks · 26 attack-chain detectors · 30,613 automated tests · 0 dependencies · 0 network calls · OpenClaw 2026.9.6 verified" width="900">
  </picture>
</p>

<p align="center">
  <sub>Verified against <b>OpenClaw 2026.9.6</b> on <b>Linux</b> · also reads the pre-2026.8.1 config shapes · Python 3.9+ · <a href="#-compatibility">details</a></sub>
</p>

---

Your OpenClaw agent reads your messages, remembers your conversations, holds
your keys, and acts on your behalf. That power is exactly what attackers want
to borrow: **one poisoned message or one malicious skill can quietly turn your
agent against you.**

ClawSecCheck is a **security check-up for your agent - one you run again, not
once.** A setup is not safe or unsafe forever: you add a skill, connect an MCP
server, edit a config, and the answer changes. So it runs in three modes - a
deliberate full check, an ongoing **watch** that tells you what changed since
last time, and a before-you-install gate - and explains, in plain language,
right in your chat, what is risky and why. A full check earns an **A-F grade**,
but only once all five of its audit layers have run; short of that it leads with
the most urgent finding in words and names what didn't run, never a guessed
number. It reports, it doesn't
remediate: it never touches your OpenClaw config, needs no API key, and the
scanner itself makes **no network calls** - no telemetry, no uploads, ever.
(Two narrow, opt-in exceptions write inside the audited home - its own
suppression file, and a no-path `--pdf` into OpenClaw's managed attachment
directory. Neither is your config; see [Safe to run](#-safe-to-

_meta.json

{
  "ownerId": "kn7fvtxzbe4k3kmgn3c9dbdfbn88zcwg",
  "slug": "clawseccheck",
  "version": "4.3.1",
  "publishedAt": 1790691787497
}

references/cli-flags.md

# ClawSecCheck - additional CLI flags

Less common but available flags. The everyday tool routing lives in `SKILL.md`
(the guided flow + "Natural-language to tool quick map"); these are the long tail,
kept here so the always-loaded playbook stays lean.

- `--ascii` - plain output for terminals that cannot render unicode (auto-detected).
- `--save PATH` - write the report to a local file.
- `--sarif PATH` - write a local SARIF 2.1.0 file (for CI / GitHub Code Scanning; never uploaded).
  Works with `--vet`/`--vet-mcp` too, as a side output alongside the human report.
- `--pdf PATH` - write the complete audit (every FAIL/WARN finding, paginated) as a base-14-only
  PDF - no font embedding, no JavaScript, no forms. This is the mobile-chat deliverable: a
  filesystem path is useless to a user reading from a phone, but a PDF opens inline in a chat
  client's own viewer (unlike `--html`, which most mobile clients hand over as a download). If
  the user is talking from a phone/chat client, attach the PDF file itself into the reply - never
  re-render its contents into the chat text (same doctrine as the `--badge` SVG: attach the
  artifact, don't redraw it), and never write a link: the tool is local-only, so no URL exists and
  any link you write will be broken. Markdown link syntax counts as a link - `[report.pdf](path)`
  is one, and a chat client strips the href off a local path and leaves a dead one the user can
  click forever (B-606); write the path as plain text or inline code. Only when the channel cannot
  attach files at all, say so and
  name the path - useless on a phone, but the one thing a desktop reader can act on, and better
  than the broken link a host invents when told it may say neither.
- `--json` with `--vet`/`--vet-mcp` - emits the risk-dossier JSON object (`tool`, `version`,
  `mode`, `target`, `target_type`, `verdict`, `axes[]`, `findings[]`, `unmapped`): the five risk
  axes (danger / build / behavior / persistence / connections) plus a **verdict**. There is no
  `grade` or `score` key - a "before you install" answer is INSTALL / CAUTION / DO-NOT-INSTALL,
  never a letter, because a letter here would collide with the audit's own A-F on a different
  scale. Exit code is 1 on SUSPICIOUS/DANGEROUS. See `docs/OUTPUT_SCHEMA.md` §11.
- `--fail-on SEVERITY` (`critical`/`high`/`medium`/`low`) - exit with code 1 if an unsuppressed
  FAIL at or above SEVERITY exists (useful for CI pipelines; needs no score, so it works on a
  bare/default run too).
- `--exit-code` - exit 1 on a FAIL verdict from any of six sources. Honored on the default
  report path and on the artifact modes that render the same audit (`--sarif`/`--html`/
  `--badge`/`--pdf`/`--dashboard`, B-584) - the artifact is still written on the run that
  exits 1. Sources: (1) an unsuppressed
  `FAIL` audit finding; (2) under `--full`, a `FAIL` MCP server; (3) under `--full`, a
  `DANGEROUS` installed skill from the skill sweep; (4) under `--full` (and not `--fast`), a
  `DANGER
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/gl0di/skills/clawseccheck",
      "sourceUrl": "https://clawhub.ai/gl0di/skills/clawseccheck",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T04:14:16.420Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T04:14:16.420Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "5.2K downloads",
      "href": "https://clawhub.ai/gl0di/clawseccheck",
      "sourceUrl": "https://clawhub.ai/gl0di/clawseccheck",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T04:14:16.420Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "4.3.1",
      "href": "https://clawhub.ai/gl0di/clawseccheck",
      "sourceUrl": "https://clawhub.ai/gl0di/clawseccheck",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-29T14:23:07.497Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 4.3.1",
      "description": "Release 4.3.1 (9ad5f14af1b9783dbe33493b4b9cf57e7a9d10d5)",
      "href": "https://clawhub.ai/gl0di/clawseccheck",
      "sourceUrl": "https://clawhub.ai/gl0di/clawseccheck",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-29T14:23:07.497Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to ClawSecCheck — OpenClaw Security Self-Audit and adjacent AI workflows.