Trent OpenClaw Security Assessment
Assess your Agent deployment against security risks using Trent. Skill: Trent OpenClaw Security Assessment Owner: trent-ai-release Summary: Assess your Agent deployment against security risks using Trent. Tags: assessment:1.4.0, latest:1.4.0, security:1.4.0, threat-modeling:1.4.0, trent:1.4.0, trentai:1.4.0, trentclaw:1.4.0 Version history: v1.4.0 | 2026-05-29T12:45:24.769Z | auto trentclaw 1.4.0 - Updated internal modules: SKILL.md, __init__.py, and trent_client.py updated for im
Rank
62
Safety
84
Downloads
2.0k
Updated
Oct 9, 2026
Version
1.4.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.4.0release · observed May 29, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17595dbkcgr3m7z80jegj93nd83h8ey:trentclaw- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/snapshot"
Documentation
CLAWHUB
55,801 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
---
name: trent-openclaw-security
description: Assess your Agent deployment against security risks using Trent.
version: 1.4.0
homepage: https://trent.ai
user-invocable: true
tags:
- trentai
- trent
- trentclaw
- security
- assessment
- threat-modeling
metadata:
openclaw:
requires:
env:
- TRENT_API_KEY
optionalEnv:
- TRENT_CHAT_API_URL
- TRENT_AGENT_API_URL
- OPENCLAW_WORKSPACE
primaryEnv: TRENT_API_KEY
---
# Trent OpenClaw Security Assessment
Audit your OpenClaw deployment for security risks. Identifies misconfigurations,
chained attack paths, and provides severity-rated findings with fixes.
## Setup
All tools are bundled — no external installer needed.
Set the `TRENT_API_KEY` environment variable. Get a key at https://trent.ai/openclaw/
## Instructions
This audit runs in three phases. Run them in order.
All Python snippets below are wrapped in a bash heredoc that sets
`PYTHONPATH` to the skill's `scripts/` directory. OpenClaw substitutes
`{baseDir}` with the skill's install path before the snippet runs, so
`openclaw_trent` is importable regardless of the current working directory.
Run each block exactly as shown.
### Phase 1 — Configuration Audit
Collect metadata and send to Trent for analysis:
```bash
cd "{baseDir}"
PYTHONPATH="{baseDir}/scripts:${PYTHONPATH:-}" python3 - <<'PY'
from openclaw_trent.openclaw_config.collector import collect_openclaw_metadata
from openclaw_trent.lib.audit_prompt import build_audit_prompt
from openclaw_trent.lib import trent_client
metadata = collect_openclaw_metadata()
message = build_audit_prompt(metadata)
response = trent_client.chat(message=message)
PY
```
Save `response["thread_id"]` for Phase 3.
Present findings grouped by severity (see "Present results" below).
Summarize: "Phase 1 complete. N findings from configuration analysis.
Phase 2 will scan your skills for deeper analysis — I'll show you exactly
what would be uploaded before anything is sent. Ready to continue?"
Optional: specify a custom config path. Same wrapper as the main Phase 1
block; replace the `metadata = …` line with:
```python
from pathlib import Path
metadata = collect_openclaw_metadata(openclaw_path=Path("/path/to/openclaw/config"))
```
### Phase 2 — Skill Upload
Scan the workspace first (nothing is uploaded yet):
```bash
cd "{baseDir}"
PYTHONPATH="{baseDir}/scripts:${PYTHONPATH:-}" python3 - <<'PY'
from openclaw_trent.lib.package_skills import scan_workspace
skills = scan_workspace()
PY
```
Present what was found and how it will be protected. Example:
> I found N skills in your workspace:
>
> | Skill | Type | Size |
> |---|---|---|
> | skill-name | installed-skill | 12KB |
>
> Before upload, each skill is packaged with its source code and metadata
> (name, version, dependencies). Files like .env, .pem, .key, and .db are
> excluded, and secrets in standard formats (API keys, tokens, AWS credentials,
> connection strings) are automatically redacted locally. I_meta.json
{
"ownerId": "kn7d78jjayn4ypbtjkf9t83829829wm8",
"slug": "trentclaw",
"version": "1.4.0",
"publishedAt": 1780058724769
}skill-card.md
## Description: Assess your Agent deployment against security risks using Trent. This skill is ready for commercial/non-commercial use. ## Publisher: [trent-ai-release](https://clawhub.ai/user/trent-ai-release) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineers use this skill to audit OpenClaw deployments, identify misconfigurations and chained attack paths, and receive severity-rated findings with fixes. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill sends redacted OpenClaw metadata and packaged local skill/code archives to Trent for analysis. Mitigation: Review the generated .skill archives and proceed only if sharing that material with Trent is acceptable. Risk: Custom TRENT_CHAT_API_URL or TRENT_AGENT_API_URL values can receive the Trent API key. Mitigation: Use the default Trent endpoints, or set custom endpoints only when they are trusted and intended to receive TRENT_API_KEY. ## Reference(s): - [ClawHub skill listing](https://clawhub.ai/trent-ai-release/skills/trentclaw) - [Trent](https://trent.ai) - [Trent OpenClaw API key setup](https://trent.ai/openclaw/) ## Skill Output: **Output Type(s):** [Text, Markdown, Shell commands, Configuration guidance, Analysis] **Output Format:** [Markdown with severity-grouped findings, inline bash snippets, JSON summaries, and diff snippets] **Output Parameters:** [1D] **Other Properties Related to Output:** [Findings are grouped by CRITICAL, HIGH, MEDIUM, and LOW severity.] ## Skill Version(s): 1.4.0 (source: frontmatter and server release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/trent-ai-release/skills/trentclaw",
"sourceUrl": "https://clawhub.ai/trent-ai-release/skills/trentclaw",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T21:16:13.200Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T21:16:13.200Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2K downloads",
"href": "https://clawhub.ai/trent-ai-release/trentclaw",
"sourceUrl": "https://clawhub.ai/trent-ai-release/trentclaw",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T21:16:13.200Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.4.0",
"href": "https://clawhub.ai/trent-ai-release/trentclaw",
"sourceUrl": "https://clawhub.ai/trent-ai-release/trentclaw",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-29T12:45:24.769Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.4.0",
"description": "trentclaw 1.4.0 - Updated internal modules: SKILL.md, __init__.py, and trent_client.py updated for improved assessment workflow or maintenance. - Removed skill-card.md (legacy or redundant documentation). - No major changes to end-user instructions or usage flow. - Version bump from 1.3.0 to 1.4.0.",
"href": "https://clawhub.ai/trent-ai-release/trentclaw",
"sourceUrl": "https://clawhub.ai/trent-ai-release/trentclaw",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-29T12:45:24.769Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
