ClawSecCheck — OpenClaw Security Self-Audit
Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills...
Rank
62
Safety
84
Downloads
5.2k
Updated
Oct 9, 2026
Version
4.3.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 5.2K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 5.2K downloadsadoption · observed Oct 9, 2026
- Latest release
- 4.3.1release · observed Sep 29, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17fbcrwqqa08r1f5aqqcxzh7s88zmmc:clawseccheck- Install using `clawhub skill install s17fbcrwqqa08r1f5aqqcxzh7s88zmmc:clawseccheck` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/gl0di/clawseccheck before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/snapshot"
Documentation
CLAWHUB
160,000 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: clawseccheck
version: 4.3.1
description: Free, local, read-only security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, logs, agent session logs, and installed skills, plus a bounded host-security scan; writes only its own local report/history (removable with --purge). Grades your setup A-F when all five check layers ran, naming what's missing otherwise. --monitor records a local baseline so every later run alerts on what changed - a new MCP server, an edited skill, config drift, a finding that appeared or cleared. No API key, no network calls; the only external command it runs is your own read-only openclaw security audit (skip with --no-native). Only two opt-in flags write anything: --apply-ignore-proposals and --pdf. Use it when you want to check or audit your OpenClaw agent's security, find prompt-injection or misconfiguration risks, see your A-F security score, watch your OpenClaw setup for changes, or ask what changed since the last check.
license: MIT
metadata: {"openclaw":{"emoji":"\ud83e\udd9e","os":["darwin","linux","win32"],"user-invocable":true},"display_name":{"en":"ClawSecCheck \u2014 OpenClaw Security Self-Audit"},"display_description":{"en":"Free, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills \u2014 read-only against your OpenClaw setup, plus a bounded host-security scan; writes only its own local report/history (removable with --purge). Reports the most urgent holes, and grades your setup A\u2013F when all five check layers ran \u2014 short of that it names the missing layers instead of printing a number. It is built to be run again, not once: --monitor records a local baseline and every later run alerts on what changed \u2014 a new MCP server, a new or edited skill, config drift, a finding that appeared or cleared. Nothing here ever changes your OpenClaw config, a skill, or a bootstrap file: only two opt-in flags write inside your OpenClaw setup at all \u2014 --apply-ignore-proposals (confirmation-gated; appends only suppressions you approved to .clawseccheckignore) and a no-PATH --pdf (auto-resolves inside your OpenClaw home when its own attachment directory exists). No API key; the scanner itself makes no network calls, and the single external command it can run is your own read-only openclaw security audit (skip it with --no-native). Use it when you want to check or audit your OpenClaw agent's security, find prompt-injection or misconfiguration risks, see your A\u2013F security score, watch your OpenClaw setup for changes, or ask what changed since the last check."},"tags":{"en":["security","openclaw","ai-agent","audit","prompt-injection","llm-security","self-audit","sarif"]}}
---
<!-- markdownlint-disable MD040 MD032 -->
<!-- Formatting-only rules (fence language tags, blanks around lists) are relaxed
for this agent-facing manifest, whose fence/list layout is deliberadocs/README.md
# ClawSecCheck documentation Reading order depends on who you are: ## I just want to use it 1. [Project README](../README.md) - what it is, quick start, trust story 2. [USAGE.md](USAGE.md) - the user guide: recipes, monitoring modes, and trust details 3. [FAQ.md](FAQ.md) - common questions, including "what if the host is already compromised?" 4. [TROUBLESHOOTING.md](TROUBLESHOOTING.md) - when ClawSecCheck itself won't run, crashes, or OpenClaw doesn't see it (not a question about your audited setup) ## I want to understand what it checks and why 1. [CHECKS.md](CHECKS.md) - the generated catalog of every check: verdict semantics, remediation, compound risk chains 2. [THREAT_COVERAGE.md](THREAT_COVERAGE.md) - mapping to OWASP LLM Top 10 (2025) and OWASP Agentic threat classes 3. [ATTESTATION.md](ATTESTATION.md) - the `--ask` / `--attest` self-report layer: what it adds, what it can't prove 4. [../SECURITY_MODEL.md](../SECURITY_MODEL.md) - ClawSecCheck's own capability surface, least-privilege posture, and self-defense ## I want the reasoning behind a design decision Analysis and decision records. They change no code and are not a reference - read one when you want to know *why* something is the way it is. 1. [design/severity-separability.md](design/severity-separability.md) - why FAIL-only recall is roughly half a static peer's, measured on SkillTrustBench, and what the recommendation costs 2. [design/judge-topology.md](design/judge-topology.md) - why the LLM judge lives in the host agent and never inside the scanner 3. [design/agent-knowledge-enrichment.md](design/agent-knowledge-enrichment.md) - whether that agent may add what it knows to a finding, and the four gates that bound it ## I want to integrate it 1. [OUTPUT_SCHEMA.md](OUTPUT_SCHEMA.md) - the frozen `--json` / SARIF contract 2. [USAGE.md - CI / automation](USAGE.md#ci--automation) - exit codes, `--fail-on`, SARIF upload ## I am the agent running this skill These are loaded on demand from [SKILL.md](../SKILL.md), not read front to back. They live outside it so its always-in-context body stays small. 1. [FLOW_CHOICES.md](FLOW_CHOICES.md) - the Step 5 branch protocols 2. [ISOLATION.md](ISOLATION.md) - the context firewall for untrusted content ## I want to contribute 1. [CONTRIBUTING.md](https://github.com/gl0di/clawseccheck/blob/main/CONTRIBUTING.md) - ground rules, dev setup, PR flow 2. [THREAT_INTAKE.md](THREAT_INTAKE.md) - which threat sources are watched, and the five-bucket triage that decides what a new signal actually changes 3. [CHECK_AUTHORING.md](CHECK_AUTHORING.md) - how to write a new check 4. [RELEASING.md](RELEASING.md) - the maintainer release protocol ## Reporting - Bugs and false positives -> [GitHub issues](https://github.com/gl0di/clawseccheck/issues) - Vulnerabilities -> [../SECURITY.md](../SECURITY.md) (private reporting)
README.md
<p align="center">
<img src="docs/assets/banner-readme.png" alt="ClawSecCheck - local security audit for your OpenClaw agent, read-only against your config" width="820">
</p>
<p align="center">
<b>Is your OpenClaw agent safe? Ask it - you get a straight answer in words, right in the chat, and an honest A-F grade once all five audit layers have run.</b><br>
<sub><i>The claw that checks your claws.</i></sub>
</p>
<p align="center">
<a href="https://github.com/gl0di/clawseccheck/releases"><img src="https://img.shields.io/github/v/tag/gl0di/clawseccheck?label=version&color=E34234&labelColor=2b2b2b" alt="version"></a>
<a href="https://github.com/gl0di/clawseccheck/actions/workflows/ci.yml"><img src="https://github.com/gl0di/clawseccheck/actions/workflows/ci.yml/badge.svg" alt="CI"></a>
<a href="https://clawhub.ai/gl0di/skills/clawseccheck"><img src="https://img.shields.io/badge/ClawHub-clawseccheck-FF6B47?labelColor=2b2b2b" alt="ClawHub"></a>
<img src="https://img.shields.io/badge/python-3.9%2B-E8A33D?labelColor=2b2b2b" alt="Python 3.9+">
<a href="LICENSE"><img src="https://img.shields.io/badge/License-MIT-E34234?labelColor=2b2b2b" alt="License: MIT"></a>
</p>
<p align="center">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="docs/assets/stats-dark.svg">
<img src="docs/assets/stats-light.svg" alt="229 security checks · 26 attack-chain detectors · 30,613 automated tests · 0 dependencies · 0 network calls · OpenClaw 2026.9.6 verified" width="900">
</picture>
</p>
<p align="center">
<sub>Verified against <b>OpenClaw 2026.9.6</b> on <b>Linux</b> · also reads the pre-2026.8.1 config shapes · Python 3.9+ · <a href="#-compatibility">details</a></sub>
</p>
---
Your OpenClaw agent reads your messages, remembers your conversations, holds
your keys, and acts on your behalf. That power is exactly what attackers want
to borrow: **one poisoned message or one malicious skill can quietly turn your
agent against you.**
ClawSecCheck is a **security check-up for your agent - one you run again, not
once.** A setup is not safe or unsafe forever: you add a skill, connect an MCP
server, edit a config, and the answer changes. So it runs in three modes - a
deliberate full check, an ongoing **watch** that tells you what changed since
last time, and a before-you-install gate - and explains, in plain language,
right in your chat, what is risky and why. A full check earns an **A-F grade**,
but only once all five of its audit layers have run; short of that it leads with
the most urgent finding in words and names what didn't run, never a guessed
number. It reports, it doesn't
remediate: it never touches your OpenClaw config, needs no API key, and the
scanner itself makes **no network calls** - no telemetry, no uploads, ever.
(Two narrow, opt-in exceptions write inside the audited home - its own
suppression file, and a no-path `--pdf` into OpenClaw's managed attachment
directory. Neither is your config; see [Safe to run](#-safe-to-_meta.json
{
"ownerId": "kn7fvtxzbe4k3kmgn3c9dbdfbn88zcwg",
"slug": "clawseccheck",
"version": "4.3.1",
"publishedAt": 1790691787497
}references/cli-flags.md
# ClawSecCheck - additional CLI flags Less common but available flags. The everyday tool routing lives in `SKILL.md` (the guided flow + "Natural-language to tool quick map"); these are the long tail, kept here so the always-loaded playbook stays lean. - `--ascii` - plain output for terminals that cannot render unicode (auto-detected). - `--save PATH` - write the report to a local file. - `--sarif PATH` - write a local SARIF 2.1.0 file (for CI / GitHub Code Scanning; never uploaded). Works with `--vet`/`--vet-mcp` too, as a side output alongside the human report. - `--pdf PATH` - write the complete audit (every FAIL/WARN finding, paginated) as a base-14-only PDF - no font embedding, no JavaScript, no forms. This is the mobile-chat deliverable: a filesystem path is useless to a user reading from a phone, but a PDF opens inline in a chat client's own viewer (unlike `--html`, which most mobile clients hand over as a download). If the user is talking from a phone/chat client, attach the PDF file itself into the reply - never re-render its contents into the chat text (same doctrine as the `--badge` SVG: attach the artifact, don't redraw it), and never write a link: the tool is local-only, so no URL exists and any link you write will be broken. Markdown link syntax counts as a link - `[report.pdf](path)` is one, and a chat client strips the href off a local path and leaves a dead one the user can click forever (B-606); write the path as plain text or inline code. Only when the channel cannot attach files at all, say so and name the path - useless on a phone, but the one thing a desktop reader can act on, and better than the broken link a host invents when told it may say neither. - `--json` with `--vet`/`--vet-mcp` - emits the risk-dossier JSON object (`tool`, `version`, `mode`, `target`, `target_type`, `verdict`, `axes[]`, `findings[]`, `unmapped`): the five risk axes (danger / build / behavior / persistence / connections) plus a **verdict**. There is no `grade` or `score` key - a "before you install" answer is INSTALL / CAUTION / DO-NOT-INSTALL, never a letter, because a letter here would collide with the audit's own A-F on a different scale. Exit code is 1 on SUSPICIOUS/DANGEROUS. See `docs/OUTPUT_SCHEMA.md` §11. - `--fail-on SEVERITY` (`critical`/`high`/`medium`/`low`) - exit with code 1 if an unsuppressed FAIL at or above SEVERITY exists (useful for CI pipelines; needs no score, so it works on a bare/default run too). - `--exit-code` - exit 1 on a FAIL verdict from any of six sources. Honored on the default report path and on the artifact modes that render the same audit (`--sarif`/`--html`/ `--badge`/`--pdf`/`--dashboard`, B-584) - the artifact is still written on the run that exits 1. Sources: (1) an unsuppressed `FAIL` audit finding; (2) under `--full`, a `FAIL` MCP server; (3) under `--full`, a `DANGEROUS` installed skill from the skill sweep; (4) under `--full` (and not `--fast`), a `DANGER
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/gl0di/skills/clawseccheck",
"sourceUrl": "https://clawhub.ai/gl0di/skills/clawseccheck",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T04:14:16.420Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T04:14:16.420Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "5.2K downloads",
"href": "https://clawhub.ai/gl0di/clawseccheck",
"sourceUrl": "https://clawhub.ai/gl0di/clawseccheck",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T04:14:16.420Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "4.3.1",
"href": "https://clawhub.ai/gl0di/clawseccheck",
"sourceUrl": "https://clawhub.ai/gl0di/clawseccheck",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-29T14:23:07.497Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-gl0di-clawseccheck/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 4.3.1",
"description": "Release 4.3.1 (9ad5f14af1b9783dbe33493b4b9cf57e7a9d10d5)",
"href": "https://clawhub.ai/gl0di/clawseccheck",
"sourceUrl": "https://clawhub.ai/gl0di/clawseccheck",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-29T14:23:07.497Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
