agentCLAWHUBUnverified

Trent OpenClaw Security Assessment

Assess your Agent deployment against security risks using Trent. Skill: Trent OpenClaw Security Assessment Owner: trent-ai-release Summary: Assess your Agent deployment against security risks using Trent. Tags: assessment:1.4.0, latest:1.4.0, security:1.4.0, threat-modeling:1.4.0, trent:1.4.0, trentai:1.4.0, trentclaw:1.4.0 Version history: v1.4.0 | 2026-05-29T12:45:24.769Z | auto trentclaw 1.4.0 - Updated internal modules: SKILL.md, __init__.py, and trent_client.py updated for im

OpenClaw

Rank

62

Safety

84

Downloads

2.0k

Updated

Oct 9, 2026

Version

1.4.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
2K downloadsadoption · observed Oct 9, 2026
Latest release
1.4.0release · observed May 29, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17595dbkcgr3m7z80jegj93nd83h8ey:trentclaw
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/snapshot"

Documentation

CLAWHUB

55,801 characters of source documentation, loaded on request.

Extracted files

3 files captured from the source.

SKILL.md

---
name: trent-openclaw-security
description: Assess your Agent deployment against security risks using Trent.
version: 1.4.0
homepage: https://trent.ai
user-invocable: true
tags:
  - trentai
  - trent
  - trentclaw
  - security
  - assessment
  - threat-modeling
metadata:
  openclaw:
    requires:
      env:
        - TRENT_API_KEY
    optionalEnv:
      - TRENT_CHAT_API_URL
      - TRENT_AGENT_API_URL
      - OPENCLAW_WORKSPACE
    primaryEnv: TRENT_API_KEY
---

# Trent OpenClaw Security Assessment

Audit your OpenClaw deployment for security risks. Identifies misconfigurations,
chained attack paths, and provides severity-rated findings with fixes.

## Setup

All tools are bundled — no external installer needed.

Set the `TRENT_API_KEY` environment variable. Get a key at https://trent.ai/openclaw/

## Instructions

This audit runs in three phases. Run them in order.

All Python snippets below are wrapped in a bash heredoc that sets
`PYTHONPATH` to the skill's `scripts/` directory. OpenClaw substitutes
`{baseDir}` with the skill's install path before the snippet runs, so
`openclaw_trent` is importable regardless of the current working directory.
Run each block exactly as shown.

### Phase 1 — Configuration Audit

Collect metadata and send to Trent for analysis:

```bash
cd "{baseDir}"
PYTHONPATH="{baseDir}/scripts:${PYTHONPATH:-}" python3 - <<'PY'
from openclaw_trent.openclaw_config.collector import collect_openclaw_metadata
from openclaw_trent.lib.audit_prompt import build_audit_prompt
from openclaw_trent.lib import trent_client

metadata = collect_openclaw_metadata()
message = build_audit_prompt(metadata)
response = trent_client.chat(message=message)
PY
```

Save `response["thread_id"]` for Phase 3.

Present findings grouped by severity (see "Present results" below).

Summarize: "Phase 1 complete. N findings from configuration analysis.
Phase 2 will scan your skills for deeper analysis — I'll show you exactly
what would be uploaded before anything is sent. Ready to continue?"

Optional: specify a custom config path. Same wrapper as the main Phase 1
block; replace the `metadata = …` line with:

```python
from pathlib import Path
metadata = collect_openclaw_metadata(openclaw_path=Path("/path/to/openclaw/config"))
```

### Phase 2 — Skill Upload

Scan the workspace first (nothing is uploaded yet):

```bash
cd "{baseDir}"
PYTHONPATH="{baseDir}/scripts:${PYTHONPATH:-}" python3 - <<'PY'
from openclaw_trent.lib.package_skills import scan_workspace

skills = scan_workspace()
PY
```

Present what was found and how it will be protected. Example:

> I found N skills in your workspace:
>
> | Skill | Type | Size |
> |---|---|---|
> | skill-name | installed-skill | 12KB |
>
> Before upload, each skill is packaged with its source code and metadata
> (name, version, dependencies). Files like .env, .pem, .key, and .db are
> excluded, and secrets in standard formats (API keys, tokens, AWS credentials,
> connection strings) are automatically redacted locally. I

_meta.json

{
  "ownerId": "kn7d78jjayn4ypbtjkf9t83829829wm8",
  "slug": "trentclaw",
  "version": "1.4.0",
  "publishedAt": 1780058724769
}

skill-card.md

## Description:

Assess your Agent deployment against security risks using Trent.

This skill is ready for commercial/non-commercial use.

## Publisher:

[trent-ai-release](https://clawhub.ai/user/trent-ai-release)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and engineers use this skill to audit OpenClaw deployments, identify misconfigurations and chained attack paths, and receive severity-rated findings with fixes.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The skill sends redacted OpenClaw metadata and packaged local skill/code archives to Trent for analysis.

Mitigation: Review the generated .skill archives and proceed only if sharing that material with Trent is acceptable.

Risk: Custom TRENT_CHAT_API_URL or TRENT_AGENT_API_URL values can receive the Trent API key.

Mitigation: Use the default Trent endpoints, or set custom endpoints only when they are trusted and intended to receive TRENT_API_KEY.

## Reference(s):

- [ClawHub skill listing](https://clawhub.ai/trent-ai-release/skills/trentclaw)
- [Trent](https://trent.ai)
- [Trent OpenClaw API key setup](https://trent.ai/openclaw/)

## Skill Output:

**Output Type(s):** [Text, Markdown, Shell commands, Configuration guidance, Analysis]

**Output Format:** [Markdown with severity-grouped findings, inline bash snippets, JSON summaries, and diff snippets]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Findings are grouped by CRITICAL, HIGH, MEDIUM, and LOW severity.]

## Skill Version(s):

1.4.0 (source: frontmatter and server release evidence)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 8h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/trent-ai-release/skills/trentclaw",
      "sourceUrl": "https://clawhub.ai/trent-ai-release/skills/trentclaw",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:16:13.200Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:16:13.200Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2K downloads",
      "href": "https://clawhub.ai/trent-ai-release/trentclaw",
      "sourceUrl": "https://clawhub.ai/trent-ai-release/trentclaw",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:16:13.200Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.4.0",
      "href": "https://clawhub.ai/trent-ai-release/trentclaw",
      "sourceUrl": "https://clawhub.ai/trent-ai-release/trentclaw",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-29T12:45:24.769Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.4.0",
      "description": "trentclaw 1.4.0 - Updated internal modules: SKILL.md, __init__.py, and trent_client.py updated for improved assessment workflow or maintenance. - Removed skill-card.md (legacy or redundant documentation). - No major changes to end-user instructions or usage flow. - Version bump from 1.3.0 to 1.4.0.",
      "href": "https://clawhub.ai/trent-ai-release/trentclaw",
      "sourceUrl": "https://clawhub.ai/trent-ai-release/trentclaw",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-29T12:45:24.769Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to Trent OpenClaw Security Assessment and adjacent AI workflows.