{"id":"7577be55-7767-4bf3-9dc2-e1e84c6939f1","entityType":"agent","slug":"clawhub-davida-ps-openclaw-audit-watchdog","name":"openclaw-audit-watchdog","canonicalUrl":"https://www.xpersona.co/agent/clawhub-davida-ps-openclaw-audit-watchdog","canonicalPath":"/agent/clawhub-davida-ps-openclaw-audit-watchdog","generatedAt":"2026-10-10T00:15:13.381Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports. Skill: openclaw-audit-watchdog Owner: davida-ps Summary: Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports. Tags: latest:0.1.1 Version history: v0.1.1 | 2026-02-25T11:27:11.675Z | user Release 0.1.1 via CI v0.1.0 | 2026-02-16T16:56:06.117Z | user Release 0.1.0 via CI v0.0.4 | 2026-02-05T22:37:39.793Z | user Release 0.0.4 via CI v0.0.3 | 2026-02-05T2","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 4/15/2026.","installCommand":"clawhub skill install kn76m78f01hqrtpgm895s0jsax80jd8v:openclaw-audit-watchdog","sourceUrl":"https://clawhub.ai/davida-ps/openclaw-audit-watchdog","homepage":"https://clawhub.ai/davida-ps/openclaw-audit-watchdog","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/davida-ps/openclaw-audit-watchdog","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports. Skill: openclaw-audit-watchdog Owner: da"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"stars":null,"forks":null,"downloads":1494,"packageName":null,"latestVersion":"0.1.1","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-02-28T21:47:03.365Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-28T21:47:03.365Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-01T21:47:03.365Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.1","createdAt":"2026-02-25T11:27:11.675Z","changelog":"Release 0.1.1 via CI","fileCount":21,"zipByteSize":35401},{"version":"0.1.0","createdAt":"2026-02-16T16:56:06.117Z","changelog":"Release 0.1.0 via CI","fileCount":21,"zipByteSize":33234},{"version":"0.0.4","createdAt":"2026-02-05T22:37:39.793Z","changelog":"Release 0.0.4 via CI","fileCount":null,"zipByteSize":null},{"version":"0.0.3","createdAt":"2026-02-05T22:33:01.105Z","changelog":"Release 0.0.3 via CI","fileCount":null,"zipByteSize":null},{"version":"0.0.1","createdAt":"2026-02-05T20:50:22.641Z","changelog":"Release 0.0.1 via CI","fileCount":null,"zipByteSize":null}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install kn76m78f01hqrtpgm895s0jsax80jd8v:openclaw-audit-watchdog","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T00:15:13.380Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-openclaw-audit-watchdog/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"Skill: openclaw-audit-watchdog\n\nOwner: davida-ps\n\nSummary: Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports.\n\nTags: latest:0.1.1\n\nVersion history:\n\nv0.1.1 | 2026-02-25T11:27:11.675Z | user\n\nRelease 0.1.1 via CI\n\nv0.1.0 | 2026-02-16T16:56:06.117Z | user\n\nRelease 0.1.0 via CI\n\nv0.0.4 | 2026-02-05T22:37:39.793Z | user\n\nRelease 0.0.4 via CI\n\nv0.0.3 | 2026-02-05T22:33:01.105Z | user\n\nRelease 0.0.3 via CI\n\nv0.0.1 | 2026-02-05T20:50:22.641Z | user\n\nRelease 0.0.1 via CI\n\nArchive index:\n\nArchive v0.1.1: 21 files, 35401 bytes\n\nFiles: CHANGELOG.md (2578b), examples/README.md (3360b), examples/security-audit-config.example.json (413b), README.md (6444b), scripts/codex_review.sh (1038b), scripts/load_suppression_config.mjs (9094b), scripts/render_report.mjs (8046b), scripts/run_audit_and_format.sh (2872b), scripts/runner.sh (2101b), scripts/send_smtp.mjs (4043b), scripts/sendmail_report.sh (1412b), scripts/setup_cron.mjs (8340b), skill.json (1916b), SKILL.md (11013b), test/E2E-TEST-RESULTS.md (5379b), test/empty-suppressions.json (25b), test/invalid-json.json (50b), test/malformed-config.json (99b), test/render_report_suppression.test.mjs (23019b), test/suppression_config.test.mjs (23188b), _meta.json (142b)\n\nFile v0.1.1:SKILL.md\n\n---\nname: openclaw-audit-watchdog\nversion: 0.1.1\ndescription: Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports.\nhomepage: https://clawsec.prompt.security\nmetadata: {\"openclaw\":{\"emoji\":\"🔭\",\"category\":\"security\"}}\nclawdis:\n  emoji: \"🔭\"\n  requires:\n    bins: [bash, curl]\n---\n\n# Prompt Security Audit (openclaw)\n\n## Installation Options\n\nYou can get openclaw-audit-watchdog in two ways:\n\n### Option A: Bundled with ClawSec Suite (Recommended)\n\n**If you've installed clawsec-suite, you may already have this!**\n\nOpenclaw-audit-watchdog is bundled alongside ClawSec Suite to provide crucial automated security audit capabilities. When you install the suite, if you don't already have the audit watchdog installed, it will be deployed from the bundled copy.\n\n**Advantages:**\n- Convenient - no separate download needed\n- Standard location - installed to `~/.openclaw/skills/openclaw-audit-watchdog/`\n- Preserved - if you already have audit watchdog installed, it won't be overwritten\n- Single verification - integrity checked as part of suite package\n\n### Option B: Standalone Installation (This Page)\n\nInstall openclaw-audit-watchdog independently without the full suite.\n\n**When to use standalone:**\n- You only need the audit watchdog (not other suite components)\n- You want to install before installing the suite\n- You prefer explicit control over audit watchdog installation\n\n**Advantages:**\n- Lighter weight installation\n- Independent from suite\n- Direct control over installation process\n\nContinue below for standalone installation instructions.\n\n---\n\n## Goal\n\nCreate (or update) a daily cron job that:\n\n1) Runs:\n- `openclaw security audit --json`\n- `openclaw security audit --deep --json`\n\n2) Summarizes findings (critical/warn/info + top findings)\n\n3) Sends the report to:\n- a user-selected DM target (channel + recipient id/handle)\n\nDefault schedule: **daily at 23:00 (11pm)** in the chosen timezone.\n\nDelivery:\n- DM to last active session\n\n## Usage Examples\n\n### Example 1: Quick Start (Environment Variables)\n\nFor automated/MDM deployments, set environment variables before invoking:\n\n```bash\nexport PROMPTSEC_DM_CHANNEL=\"telegram\"\nexport PROMPTSEC_DM_TO=\"@yourhandle\"\nexport PROMPTSEC_TZ=\"America/New_York\"\nexport PROMPTSEC_HOST_LABEL=\"prod-server-01\"\n\n# Then invoke the skill\n/openclaw-audit-watchdog\n```\n\nThe skill will automatically configure and create the cron job without prompts.\n\n### Example 2: Interactive Setup\n\nIf environment variables aren't set, the skill will prompt minimally:\n\n```\nUser: /openclaw-audit-watchdog\n\nAgent: Setting up daily security audit watchdog...\n       What channel should I use for delivery? (e.g., telegram, slack)\nUser: telegram\n\nAgent: What's the recipient ID or handle?\nUser: @myhandle\n\nAgent: Which timezone for the 23:00 daily run? (default: UTC)\nUser: America/Los_Angeles\n\nAgent: ✓ Created cron job \"Daily security audit (Prompt Security)\"\n       Schedule: Daily at 23:00 America/Los_Angeles\n       Delivery: telegram → @myhandle\n```\n\n### Example 3: Updating Existing Job\n\nIf a job already exists, the skill updates it instead of creating duplicates:\n\n```\nUser: /openclaw-audit-watchdog\n\nAgent: Found existing \"Daily security audit (Prompt Security)\" job.\n       Current: Daily at 23:00 UTC → telegram:@oldhandle\n\n       Update delivery target? (current: telegram:@oldhandle)\nUser: slack:#security-alerts\n\nAgent: ✓ Updated cron job\n       Schedule: Daily at 23:00 UTC\n       Delivery: slack:#security-alerts\n```\n\n### Example 4: What Gets Delivered\n\nEach day at the scheduled time, you'll receive a report like:\n\n```\n🔭 Daily Security Audit Report\nHost: prod-server-01\nTime: 2026-02-16 23:00:00 America/New_York\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nSUMMARY\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n✓ Standard Audit: 12 checks passed, 2 warnings\n✓ Deep Audit: 8 probes passed, 1 critical\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nCRITICAL FINDINGS\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n[CRIT-001] Unencrypted API Keys Detected\n→ Remediation: Move credentials to encrypted vault or use environment variables\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nWARNINGS\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n[WARN-003] Outdated Dependencies Found\n→ Remediation: Run `openclaw security audit --fix` to update\n\n[WARN-007] Weak Permission on Config File\n→ Remediation: chmod 600 ~/.openclaw/config.json\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nRun `openclaw security audit --deep` for full details.\n```\n\n### Example 5: Custom Schedule\n\nWant a different schedule? Set it before invoking:\n\n```bash\n# Run every 6 hours instead of daily\nexport PROMPTSEC_SCHEDULE=\"0 */6 * * *\"\n/openclaw-audit-watchdog\n```\n\n### Example 6: Multiple Environments\n\nFor managing multiple servers, use different host labels:\n\n```bash\n# On dev server\nexport PROMPTSEC_HOST_LABEL=\"dev-01\"\nexport PROMPTSEC_DM_TO=\"@dev-team\"\n/openclaw-audit-watchdog\n\n# On prod server\nexport PROMPTSEC_HOST_LABEL=\"prod-01\"\nexport PROMPTSEC_DM_TO=\"@oncall\"\n/openclaw-audit-watchdog\n```\n\nEach will send reports with clear host identification.\n\n### Example 7: Suppressing Known Findings\n\nTo suppress audit findings that have been reviewed and accepted, pass the `--enable-suppressions` flag and ensure the config file includes the `\"enabledFor\": [\"audit\"]` sentinel:\n\n```bash\n# Create or edit the suppression config\ncat > ~/.openclaw/security-audit.json <<'JSON'\n{\n  \"enabledFor\": [\"audit\"],\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling — reviewed by security team\",\n      \"suppressedAt\": \"2026-02-15\"\n    }\n  ]\n}\nJSON\n\n# Run with suppressions enabled\n/openclaw-audit-watchdog --enable-suppressions\n```\n\nSuppressed findings still appear in the report under an informational section but are excluded from critical/warning totals.\n\n## Suppression / Allowlist\n\nThe audit pipeline supports an opt-in suppression mechanism for managing reviewed findings. Suppression uses defense-in-depth activation: two independent gates must both be satisfied.\n\n### Activation Requirements\n\n1. **CLI flag:** The `--enable-suppressions` flag must be passed at invocation.\n2. **Config sentinel:** The configuration file must include `\"enabledFor\"` with `\"audit\"` in the array.\n\nIf either gate is absent, all findings are reported normally and the suppression list is ignored.\n\n### Config File Resolution (4-tier)\n\n1. Explicit `--config <path>` argument\n2. `OPENCLAW_AUDIT_CONFIG` environment variable\n3. `~/.openclaw/security-audit.json`\n4. `.clawsec/allowlist.json`\n\n### Config Format\n\n```json\n{\n  \"enabledFor\": [\"audit\"],\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling — reviewed by security team\",\n      \"suppressedAt\": \"2026-02-15\"\n    }\n  ]\n}\n```\n\n### Sentinel Semantics\n\n- `\"enabledFor\": [\"audit\"]` -- audit suppression active (requires `--enable-suppressions` flag too)\n- `\"enabledFor\": [\"advisory\"]` -- only advisory pipeline suppression (no effect on audit)\n- `\"enabledFor\": [\"audit\", \"advisory\"]` -- both pipelines honor suppressions\n- Missing or empty `enabledFor` -- no suppression active (safe default)\n\n### Matching Rules\n\n- **checkId:** exact match against the audit finding's check identifier (e.g., `skills.code_safety`)\n- **skill:** case-insensitive match against the skill name from the finding\n- Both fields must match for a finding to be suppressed\n\n## Installation flow (interactive)\n\nProvisioning (MDM-friendly): prefer environment variables (no prompts).\n\nRequired env:\n- `PROMPTSEC_DM_CHANNEL` (e.g. `telegram`)\n- `PROMPTSEC_DM_TO` (recipient id)\n\nOptional env:\n- `PROMPTSEC_TZ` (IANA timezone; default `UTC`)\n- `PROMPTSEC_HOST_LABEL` (label included in report; default uses `hostname`)\n- `PROMPTSEC_INSTALL_DIR` (stable path used by cron payload to `cd` before running runner; default: `~/.config/security-checkup`)\n- `PROMPTSEC_GIT_PULL=1` (runner will `git pull --ff-only` if installed from git)\n\nPath expansion rules (important):\n- In `bash`/`zsh`, use `PROMPTSEC_INSTALL_DIR=\"$HOME/.config/security-checkup\"` (or absolute path).\n- Do not pass a single-quoted literal like `'$HOME/.config/security-checkup'`.\n- On PowerShell, prefer: `$env:PROMPTSEC_INSTALL_DIR = Join-Path $HOME \".config/security-checkup\"`.\n- If path resolution fails, setup now exits with a clear error instead of creating a literal `$HOME` directory segment.\n\nInteractive install is last resort if env vars or defaults are not set.\n\neven in that case keep prompts minimalistic the watchdog tool is pretty straight up configured out of the box.\n\n## Create the cron job\n\nUse the `cron` tool to create a job with:\n\n- `schedule.kind=\"cron\"`\n- `schedule.expr=\"0 23 * * *\"`\n- `schedule.tz=<installer tz>`\n- `sessionTarget=\"isolated\"`\n- `wakeMode=\"now\"`\n- `payload.kind=\"agentTurn\"`\n- `payload.deliver=true`\n\n### Payload message template (agentTurn)\n\nCreate the job with a payload message that instructs the isolated run to:\n\n1) Run the audits\n\n- Prefer JSON output for robust parsing:\n  - `openclaw security audit --json`\n  - `openclaw security audit --deep --json`\n\n2) Render a concise text report:\n\nInclude:\n- Timestamp + host identifier if available\n- Summary counts\n- For each CRITICAL/WARN: `checkId` + `title` + 1-line remediation\n- If deep probe fails: include the probe error line\n\n3) Deliver the report:\n\n- DM to the chosen user target using `message` tool\n\n### Email delivery requirement\n\nAttempt email delivery in this priority order:\n\nA) If an email channel plugin exists in this deployment, use:\n- `message(action=\"send\", channel=\"email\", target=\"target@example.com\", message=<report>)`\n\nB) Otherwise, fallback to local sendmail if available:\n- `exec` with: `printf \"%s\" \"$REPORT\" | /usr/sbin/sendmail -t` (construct To/Subject headers)\n\nIf neither path is possible, still DM the user and include a line:\n- `\"NOTE: could not deliver to target@example.com (email channel not configured)\"`\n\n## Idempotency / updates\n\nBefore adding a new job:\n\n- `cron.list(includeDisabled=true)`\n- If a job with name matching `\"Daily security audit\"` exists, update it instead of adding a duplicate:\n  - adjust schedule tz/expr\n  - adjust DM target\n\n## Suggested naming\n\n- Job name: `\"Daily security audit (Prompt Security)\"`\n\n## Minimal recommended defaults (do not auto-change config)\n\nThe cron’s report should *suggest* fixes but must not apply them.\n\nDo not run `openclaw security audit --fix` unless explicitly asked.\n\nFile v0.1.1:examples/README.md\n\n# Security Audit Configuration Examples\n\n## Overview\n\nThis directory contains example configuration files for the OpenClaw security audit suppression mechanism.\n\n## Configuration File Format\n\nThe suppression configuration file must be valid JSON with the following structure:\n\n```json\n{\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling, reviewed 2026-02-13\",\n      \"suppressedAt\": \"2026-02-13\"\n    }\n  ]\n}\n```\n\n### Required Fields\n\nEach suppression entry must include:\n\n- **`checkId`** (string, required): The security check identifier that flagged the finding\n  - Example: `\"skills.code_safety\"`, `\"skills.permissions\"`, `\"skills.network\"`\n\n- **`skill`** (string, required): The exact skill name being suppressed\n  - Example: `\"clawsec-suite\"`, `\"openclaw-audit-watchdog\"`\n\n- **`reason`** (string, required): Justification for the suppression (audit trail)\n  - Example: `\"First-party security tooling, reviewed 2026-02-13\"`\n  - Example: `\"False positive - validated by security team on 2026-02-10\"`\n\n- **`suppressedAt`** (string, required): ISO 8601 date when suppression was added\n  - Format: `YYYY-MM-DD`\n  - Example: `\"2026-02-13\"`\n\n### Configuration File Locations\n\nThe suppression config is loaded from these locations (in priority order):\n\n1. **Custom path**: Specified via `--config` flag\n2. **Environment variable**: `OPENCLAW_AUDIT_CONFIG` env var\n3. **Primary default**: `~/.openclaw/security-audit.json`\n4. **Fallback**: `.clawsec/allowlist.json`\n\nIf no config file is found, the audit runs normally without suppressions (backward compatible).\n\n## Usage Examples\n\n### Basic Setup\n\n1. Copy the example config:\n```bash\nmkdir -p ~/.openclaw\ncp security-audit-config.example.json ~/.openclaw/security-audit.json\n```\n\n2. Customize the suppressions for your needs\n\n3. Run the audit:\n```bash\nopenclaw security audit --deep\n```\n\n### Using Custom Config Path\n\n```bash\nopenclaw security audit --deep --config /path/to/custom-config.json\n```\n\n### Managing False Positives\n\nWhen you encounter a false positive:\n\n1. Identify the `checkId` and `skill` name from the audit report\n2. Add a suppression entry with a clear reason\n3. Include the current date in ISO format\n4. Re-run the audit to verify the suppression works\n\nExample suppression entry:\n```json\n{\n  \"checkId\": \"skills.permissions\",\n  \"skill\": \"my-internal-tool\",\n  \"reason\": \"Broad permissions required for legitimate functionality, approved by security team\",\n  \"suppressedAt\": \"2026-02-16\"\n}\n```\n\n## Important Notes\n\n- **Transparency**: Suppressed findings remain visible in the audit report under \"INFO - SUPPRESSED\"\n- **Matching**: Suppressions require BOTH `checkId` AND `skill` to match (prevents over-suppression)\n- **Audit Trail**: Always document the reason and date for compliance\n- **Validation**: The config is validated on load - malformed JSON will produce a clear error\n\n## Example Use Case: First-Party Tools\n\nThe example config demonstrates suppressing false positives for ClawSec's own security tools:\n\n- **clawsec-suite**: Legitimately executes CLI commands for security scanning\n- **openclaw-audit-watchdog**: Legitimately accesses environment variables for auditing\n\nThese tools are flagged as \"dangerous\" by the security scanner but are safe first-party tools that have been reviewed.\n\nFile v0.1.1:README.md\n\n# OpenClaw Audit Watchdog 🔭\n\nAutomated daily security audits for OpenClaw/Clawdbot agents with email reporting.\n\n## Overview\n\nThe Audit Watchdog provides automated security monitoring for your OpenClaw agent deployments:\n\n- **Daily Security Scans** - Scheduled via cron for continuous monitoring\n- **Deep Audit Mode** - Comprehensive analysis of agent configurations and behavior\n- **Email Reporting** - Formatted reports delivered to your security team\n- **Git Integration** - Optionally syncs latest configurations before audit\n\n## Quick Start\n\n```bash\n# Install skill\nmkdir -p ~/.openclaw/skills/openclaw-audit-watchdog\ncd ~/.openclaw/skills/openclaw-audit-watchdog\n\n# Download and extract\ncurl -sSL \"https://github.com/prompt-security/clawsec/releases/download/$VERSION_TAG/openclaw-audit-watchdog.skill\" -o watchdog.skill\nunzip watchdog.skill\n\n# Configure\nexport PROMPTSEC_EMAIL_TO=\"security@yourcompany.com\"\nexport PROMPTSEC_HOST_LABEL=\"prod-agent-1\"\n\n# Run\n./scripts/runner.sh\n```\n\n## Configuration\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| `PROMPTSEC_EMAIL_TO` | Email recipient for reports | `target@example.com` |\n| `PROMPTSEC_HOST_LABEL` | Host identifier in reports | hostname |\n| `PROMPTSEC_GIT_PULL` | Pull latest before audit (0/1) | `0` |\n| `OPENCLAW_AUDIT_CONFIG` | Path to suppression config file | Auto-detected |\n\n### Path Expansion and Quoting\n\n- `PROMPTSEC_INSTALL_DIR` and `OPENCLAW_AUDIT_CONFIG` support `~`, `$HOME`, `${HOME}`, `%USERPROFILE%`, and `$env:USERPROFILE`.\n- In `bash`/`zsh`, use double quotes for expandable paths:\n  - `export PROMPTSEC_INSTALL_DIR=\"$HOME/.config/security-checkup\"`\n- Avoid single-quoted literals such as `'$HOME/.config/security-checkup'`.\n- In PowerShell:\n  - `$env:PROMPTSEC_INSTALL_DIR = Join-Path $HOME \".config/security-checkup\"`\n\n## Suppression / Allowlist\n\nManage false-positive findings with the built-in suppression mechanism. Suppressed findings remain visible in reports but are demoted to informational status and do not count toward critical/warning totals.\n\nSuppression is **opt-in with defense in depth**: the audit pipeline requires BOTH a CLI flag AND a config-file sentinel before any finding is suppressed. This prevents accidental or unauthorized suppression.\n\n### Activation (Two Gates)\n\nBoth of the following must be true for audit suppressions to take effect:\n\n1. **CLI flag:** Pass `--enable-suppressions` when invoking the runner.\n2. **Config sentinel:** The configuration file must contain `\"enabledFor\": [\"audit\"]` (or a list that includes `\"audit\"`).\n\nIf either gate is missing, the suppression list is ignored entirely and all findings are reported normally.\n\n### Config File Resolution\n\nThe audit scanner resolves the suppression config file using this 4-tier priority:\n\n1. `--config <path>` CLI argument (highest priority)\n2. `OPENCLAW_AUDIT_CONFIG` environment variable\n3. `~/.openclaw/security-audit.json`\n4. `.clawsec/allowlist.json` (fallback)\n\n### Example Configuration\n\n```json\n{\n  \"enabledFor\": [\"audit\"],\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling, reviewed 2026-02-13\",\n      \"suppressedAt\": \"2026-02-13\"\n    },\n    {\n      \"checkId\": \"skills.permissions\",\n      \"skill\": \"my-internal-tool\",\n      \"reason\": \"Broad permissions required for legitimate functionality\",\n      \"suppressedAt\": \"2026-02-16\"\n    }\n  ]\n}\n```\n\nThe `enabledFor` array controls which pipelines honor the suppression list:\n\n| Value | Effect |\n|-------|--------|\n| `[\"audit\"]` | Only audit suppression active (still requires `--enable-suppressions` flag) |\n| `[\"advisory\"]` | Only advisory suppression active (used by clawsec-suite) |\n| `[\"audit\", \"advisory\"]` | Both pipelines honor suppressions |\n| Missing or `[]` | No suppression in any pipeline (safe default) |\n\n### Required Fields per Suppression Entry\n\n| Field | Description | Example |\n|-------|-------------|---------|\n| `checkId` | Audit check identifier to suppress | `skills.code_safety` |\n| `skill` | Skill name the suppression applies to | `clawsec-suite` |\n| `reason` | Justification for audit trail (required) | `First-party tooling, reviewed by security team` |\n| `suppressedAt` | ISO 8601 date (YYYY-MM-DD) | `2026-02-15` |\n\n**Matching:** Suppression requires an exact `checkId` match and a case-insensitive `skill` name match. Both must match for a finding to be suppressed.\n\n### Usage\n\n```bash\n# Enable suppressions with default config location\n./scripts/runner.sh --enable-suppressions\n\n# Enable suppressions with explicit config path\n./scripts/runner.sh --enable-suppressions --config /path/to/config.json\n\n# Enable suppressions with config via environment variable\nexport OPENCLAW_AUDIT_CONFIG=~/.openclaw/custom-audit.json\n./scripts/runner.sh --enable-suppressions\n```\n\nWithout `--enable-suppressions`, the config file is not consulted for suppressions:\n\n```bash\n# Suppressions NOT active (flag missing)\n./scripts/runner.sh\n./scripts/runner.sh --config /path/to/config.json\n```\n\n### Report Output\n\nSuppressed findings appear in a separate informational section:\n\n```\nCRITICAL (0):\n  (none)\n\nWARNINGS (1):\n  [skills.network] some-skill: Unrestricted network access\n\nINFO - SUPPRESSED (2):\n  [skills.code_safety] clawsec-suite: dangerous-exec detected\n    Reason: First-party security tooling, reviewed 2026-02-13\n  [skills.permissions] my-tool: Broad permission scope\n    Reason: Validated by security team, suppressedAt 2026-02-16\n```\n\nSee `examples/security-audit-config.example.json` for a complete template.\n\n## Scripts\n\n| Script | Purpose |\n|--------|---------|\n| `runner.sh` | Main entry - runs full audit pipeline |\n| `run_audit_and_format.sh` | Core audit execution |\n| `codex_review.sh` | AI-assisted code review |\n| `render_report.mjs` | HTML report generation |\n| `sendmail_report.sh` | Local sendmail delivery |\n| `send_smtp.mjs` | SMTP email delivery |\n| `setup_cron.mjs` | Cron job configuration |\n\n## Requirements\n\n- bash\n- curl\n- Optional: node (for SMTP/rendering), jq (for JSON), sendmail (for email)\n\n## Cron Setup\n\n```bash\n# Daily at 6 AM\n0 6 * * * /path/to/scripts/runner.sh\n```\n\nOr use the setup script:\n\n```bash\nnode scripts/setup_cron.mjs\n```\n\n## License\n\nGNU AGPL v3.0 or later - See [LICENSE](../../LICENSE) for details.\n\n---\n\n**Part of [ClawSec](https://github.com/prompt-security/clawsec) by [Prompt Security](https://prompt.security)**\n\nFile v0.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"openclaw-audit-watchdog\",\n  \"version\": \"0.1.1\",\n  \"publishedAt\": 1772018831675\n}\n\nFile v0.1.1:CHANGELOG.md\n\n# Changelog\n\nAll notable changes to this project will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.1.1]\n\n### Added\n\n- Contributor credit: portability and path-hardening improvements in this release were contributed by [@aldodelgado](https://github.com/aldodelgado) in PR #62.\n- Cross-shell home-path expansion support in watchdog path inputs (`~`, `$HOME`, `${HOME}`, `%USERPROFILE%`, `$env:HOME`).\n- Regression coverage for suppression-config home-token expansion and escaped-token rejection (`test/suppression_config.test.mjs`).\n\n### Changed\n\n- `scripts/codex_review.sh` now resolves the Codex CLI from `CODEX_BIN`, then `PATH`, then Homebrew fallback for improved portability.\n- `scripts/setup_cron.mjs` now normalizes and validates install-dir/home-derived paths before job creation.\n- `scripts/load_suppression_config.mjs` now resolves/normalizes configured file paths consistently across shell styles.\n\n### Security\n\n- Escaped or unresolved home tokens in suppression config paths now fail fast to avoid silently using unintended literal paths.\n\n## [0.1.0]\n\n### Added\n\n- Suppression/allowlist mechanism with explicit opt-in gating (defense in depth).\n- `--enable-suppressions` CLI flag for `run_audit_and_format.sh`, `render_report.mjs`, and `runner.sh`.\n- `enabledFor` config sentinel -- config must declare `\"enabledFor\": [\"audit\"]` for audit suppression to activate.\n- 4-tier config file resolution: explicit `--config` path > `OPENCLAW_AUDIT_CONFIG` env var > `~/.openclaw/security-audit.json` > `.clawsec/allowlist.json`.\n- `INFO-SUPPRESSED` section in report output showing suppressed findings with metadata.\n- Integration tests for suppression behavior (11 tests in `render_report_suppression.test.mjs`).\n- Unit tests for config loading and opt-in gating (15 tests in `suppression_config.test.mjs`).\n- Test fixtures: `empty-suppressions.json`, `invalid-json.json`, `malformed-config.json`.\n\n### Changed\n\n- `load_suppression_config.mjs` now requires explicit `{ enabled: true }` parameter -- returns empty suppressions by default.\n- `render_report.mjs` passes suppression enabled state to config loader.\n- Summary counts in report output are recalculated after filtering suppressed findings.\n\n### Security\n\n- Suppression is never active by default -- requires BOTH CLI flag AND config sentinel (defense in depth).\n- Environment variables alone cannot activate suppression (prevents ambient attack vector).\n\nFile v0.1.1:test/E2E-TEST-RESULTS.md\n\n# E2E Test Results: Suppression Mechanism\n\n## Test Date\n2026-02-16\n\n## Test Overview\nManual end-to-end test of the security audit suppression mechanism using mock audit data that simulates real openclaw security audit output.\n\n## Test Setup\n\n### Mock Data Created\n1. **mock-audit.json**: Simulates standard audit findings\n   - 1 critical finding from `clawsec-suite` (code_safety check)\n   - 1 warning finding from `example-skill` (permissions check)\n\n2. **mock-deep.json**: Simulates deep scan findings\n   - 1 critical finding from `openclaw-audit-watchdog` (code_safety check)\n   - 1 warning finding from `network-tool` (network check)\n\n3. **suppression-config.json**: Suppression rules\n   - Suppress `skills.code_safety` + `clawsec-suite`\n   - Suppress `skills.code_safety` + `openclaw-audit-watchdog`\n\n## Test Execution\n\n### Test 1: Baseline (No Suppression)\n**Command:**\n```bash\nnode render_report.mjs --audit mock-audit.json --deep mock-deep.json --label \"No Suppression\"\n```\n\n**Expected Behavior:**\n- All findings appear in report\n- 2 critical findings shown\n- 2 warning findings shown\n\n**Result:** ✅ PASSED\n- Summary showed: 1 critical · 1 warn\n- All findings displayed in critical/warn section\n- Skill names displayed: [clawsec-suite], [example-skill]\n\n### Test 2: With Suppression Config\n**Command:**\n```bash\nnode render_report.mjs --audit mock-audit.json --deep mock-deep.json \\\n  --label \"With Suppression\" --config suppression-config.json\n```\n\n**Expected Behavior:**\n- Suppressed findings appear in INFO-SUPPRESSED section\n- Summary counts exclude suppressed findings\n- Suppression reason and date displayed\n- Non-suppressed findings remain in active section\n\n**Result:** ✅ PASSED\n\n**Verification Points:**\n1. ✅ INFO-SUPPRESSED section present\n2. ✅ Suppression reason displayed: \"First-party security tooling, reviewed 2026-02-16\"\n3. ✅ Suppression date displayed: \"2026-02-16\"\n4. ✅ clawsec-suite finding suppressed and shown with [clawsec-suite] label\n5. ✅ openclaw-audit-watchdog finding suppressed and shown with [openclaw-audit-watchdog] label\n6. ✅ Non-suppressed findings still present: [example-skill] permission warning\n7. ✅ Critical count reduced to 0 (was 1, now suppressed)\n8. ✅ Warning count remains 1 (non-suppressed finding)\n\n## Sample Output\n\n### Without Suppression\n```\nopenclaw security audit report -- No Suppression\nTime: 2026-02-16T13:55:39.984Z\nSummary: 1 critical · 1 warn · 0 info\n\nFindings (critical/warn):\n- skills.code_safety [clawsec-suite] Dangerous code execution pattern detected\n  Fix: Review code execution patterns\n- skills.permissions [example-skill] Broad permission scope detected\n  Fix: Reduce permission scope\n```\n\n### With Suppression\n```\nopenclaw security audit report -- With Suppression\nTime: 2026-02-16T13:55:40.017Z\nSummary: 0 critical · 1 warn · 0 info\n\nFindings (critical/warn):\n- skills.permissions [example-skill] Broad permission scope detected\n  Fix: Reduce permission scope\n\nINFO-SUPPRESSED:\n- skills.code_safety [clawsec-suite] Dangerous code execution pattern detected\n  Suppressed: First-party security tooling, reviewed 2026-02-16 (2026-02-16)\n- skills.code_safety [openclaw-audit-watchdog] Environment variable access detected\n  Suppressed: First-party audit watchdog, reviewed 2026-02-16 (2026-02-16)\n```\n\n## Key Findings\n\n### ✅ Successes\n1. **Config Loading**: Suppression config loaded successfully from custom path\n2. **Matching Logic**: Findings correctly matched by BOTH checkId AND skill name\n3. **Filtering**: Suppressed findings excluded from critical/warning counts\n4. **Transparency**: Suppressed findings remain visible in INFO-SUPPRESSED section\n5. **Audit Trail**: Reason and date displayed for each suppression\n6. **Backward Compatibility**: Running without config works identically to before\n7. **Skill Name Display**: Skill names now displayed in both active and suppressed sections\n\n### 🔧 Improvements Made During Testing\n1. **Bug Fix**: Added --config flag passthrough in run_audit_and_format.sh\n   - Script was accepting --config but not passing it to render_report.mjs\n   - Fixed by building RENDER_ARGS array with conditional --config inclusion\n\n2. **Enhancement**: Added skill name display to active findings\n   - Improves consistency between active and suppressed findings\n   - Makes it clearer which skill each finding comes from\n   - Format: `[skill-name]` appears after checkId in output\n\n## Test Automation\nCreated `run-e2e-test.mjs` script for automated E2E validation with 8 verification points:\n- Baseline report correctness\n- INFO-SUPPRESSED section presence\n- Suppression reason display\n- Suppression date display\n- clawsec-suite suppression\n- openclaw-audit-watchdog suppression\n- Non-suppressed findings preservation\n- Summary count accuracy\n\n## Conclusion\n✅ **All E2E tests PASSED**\n\nThe suppression mechanism is working correctly end-to-end:\n- Configuration loads from custom paths\n- Matching requires both checkId and skill name (prevents over-suppression)\n- Suppressed findings remain visible with full audit trail\n- Summary counts accurately reflect only active findings\n- Non-suppressed findings continue to be reported normally\n- Skill names provide clear context for all findings\n\n## Next Steps\n1. ✅ Integration tests verified (10/10 passing)\n2. ✅ E2E test completed and documented\n3. ⏭️ Proceed to documentation phase (Phase 5)\n\nFile v0.1.1:examples/security-audit-config.example.json\n\n{\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling, reviewed 2026-02-13\",\n      \"suppressedAt\": \"2026-02-13\"\n    },\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"openclaw-audit-watchdog\",\n      \"reason\": \"First-party security tooling, reviewed 2026-02-13\",\n      \"suppressedAt\": \"2026-02-13\"\n    }\n  ]\n}\n\nFile v0.1.1:skill.json\n\n{\n  \"name\": \"openclaw-audit-watchdog\",\n  \"version\": \"0.1.1\",\n  \"description\": \"Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security\",\n  \"keywords\": [\n    \"security\",\n    \"audit\",\n    \"watchdog\",\n    \"agents\",\n    \"ai\",\n    \"reporting\",\n    \"cron\",\n    \"monitoring\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Audit watchdog skill documentation\"\n      },\n      {\n        \"path\": \"scripts/runner.sh\",\n        \"required\": true,\n        \"description\": \"Main runner script\"\n      },\n      {\n        \"path\": \"scripts/run_audit_and_format.sh\",\n        \"required\": true,\n        \"description\": \"Audit execution and formatting\"\n      },\n      {\n        \"path\": \"scripts/codex_review.sh\",\n        \"required\": false,\n        \"description\": \"Codex-based code review\"\n      },\n      {\n        \"path\": \"scripts/render_report.mjs\",\n        \"required\": false,\n        \"description\": \"Report rendering (Node.js)\"\n      },\n      {\n        \"path\": \"scripts/sendmail_report.sh\",\n        \"required\": false,\n        \"description\": \"Sendmail delivery\"\n      },\n      {\n        \"path\": \"scripts/send_smtp.mjs\",\n        \"required\": false,\n        \"description\": \"SMTP delivery (Node.js)\"\n      },\n      {\n        \"path\": \"scripts/setup_cron.mjs\",\n        \"required\": false,\n        \"description\": \"Cron job setup\"\n      }\n    ]\n  },\n  \"openclaw\": {\n    \"emoji\": \"🔭\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"bash\",\n        \"curl\"\n      ]\n    },\n    \"triggers\": [\n      \"audit watchdog\",\n      \"security audit\",\n      \"daily audit\",\n      \"run audit\",\n      \"audit report\",\n      \"security report\",\n      \"watchdog check\",\n      \"deep audit\"\n    ]\n  }\n}\n\nFile v0.1.1:test/empty-suppressions.json\n\n{\n  \"suppressions\": []\n}\n\nFile v0.1.1:test/invalid-json.json\n\n{\n  \"suppressions\": [\n    invalid json here\n  ]\n}\n\nFile v0.1.1:test/malformed-config.json\n\n{\n  \"suppressions\": [\n    {\n      \"checkId\": \"test.check\",\n      \"skill\": \"test-skill\"\n    }\n  ]\n}\n\nArchive v0.1.0: 21 files, 33234 bytes\n\nFiles: CHANGELOG.md (1619b), examples/README.md (3360b), examples/security-audit-config.example.json (413b), README.md (5967b), scripts/codex_review.sh (804b), scripts/load_suppression_config.mjs (7228b), scripts/render_report.mjs (8046b), scripts/run_audit_and_format.sh (2872b), scripts/runner.sh (2101b), scripts/send_smtp.mjs (4043b), scripts/sendmail_report.sh (1412b), scripts/setup_cron.mjs (6538b), skill.json (1902b), SKILL.md (10579b), test/E2E-TEST-RESULTS.md (5379b), test/empty-suppressions.json (25b), test/invalid-json.json (50b), test/malformed-config.json (99b), test/render_report_suppression.test.mjs (23300b), test/suppression_config.test.mjs (20745b), _meta.json (142b)\n\nFile v0.1.0:SKILL.md\n\n---\nname: openclaw-audit-watchdog\nversion: 0.1.0\ndescription: Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports.\nhomepage: https://clawsec.prompt.security\nmetadata: {\"openclaw\":{\"emoji\":\"🔭\",\"category\":\"security\"}}\nclawdis:\n  emoji: \"🔭\"\n  requires:\n    bins: [bash, curl]\n---\n\n# Prompt Security Audit (openclaw)\n\n## Installation Options\n\nYou can get openclaw-audit-watchdog in two ways:\n\n### Option A: Bundled with ClawSec Suite (Recommended)\n\n**If you've installed clawsec-suite, you may already have this!**\n\nOpenclaw-audit-watchdog is bundled alongside ClawSec Suite to provide crucial automated security audit capabilities. When you install the suite, if you don't already have the audit watchdog installed, it will be deployed from the bundled copy.\n\n**Advantages:**\n- Convenient - no separate download needed\n- Standard location - installed to `~/.openclaw/skills/openclaw-audit-watchdog/`\n- Preserved - if you already have audit watchdog installed, it won't be overwritten\n- Single verification - integrity checked as part of suite package\n\n### Option B: Standalone Installation (This Page)\n\nInstall openclaw-audit-watchdog independently without the full suite.\n\n**When to use standalone:**\n- You only need the audit watchdog (not other suite components)\n- You want to install before installing the suite\n- You prefer explicit control over audit watchdog installation\n\n**Advantages:**\n- Lighter weight installation\n- Independent from suite\n- Direct control over installation process\n\nContinue below for standalone installation instructions.\n\n---\n\n## Goal\n\nCreate (or update) a daily cron job that:\n\n1) Runs:\n- `openclaw security audit --json`\n- `openclaw security audit --deep --json`\n\n2) Summarizes findings (critical/warn/info + top findings)\n\n3) Sends the report to:\n- a user-selected DM target (channel + recipient id/handle)\n\nDefault schedule: **daily at 23:00 (11pm)** in the chosen timezone.\n\nDelivery:\n- DM to last active session\n\n## Usage Examples\n\n### Example 1: Quick Start (Environment Variables)\n\nFor automated/MDM deployments, set environment variables before invoking:\n\n```bash\nexport PROMPTSEC_DM_CHANNEL=\"telegram\"\nexport PROMPTSEC_DM_TO=\"@yourhandle\"\nexport PROMPTSEC_TZ=\"America/New_York\"\nexport PROMPTSEC_HOST_LABEL=\"prod-server-01\"\n\n# Then invoke the skill\n/openclaw-audit-watchdog\n```\n\nThe skill will automatically configure and create the cron job without prompts.\n\n### Example 2: Interactive Setup\n\nIf environment variables aren't set, the skill will prompt minimally:\n\n```\nUser: /openclaw-audit-watchdog\n\nAgent: Setting up daily security audit watchdog...\n       What channel should I use for delivery? (e.g., telegram, slack)\nUser: telegram\n\nAgent: What's the recipient ID or handle?\nUser: @myhandle\n\nAgent: Which timezone for the 23:00 daily run? (default: UTC)\nUser: America/Los_Angeles\n\nAgent: ✓ Created cron job \"Daily security audit (Prompt Security)\"\n       Schedule: Daily at 23:00 America/Los_Angeles\n       Delivery: telegram → @myhandle\n```\n\n### Example 3: Updating Existing Job\n\nIf a job already exists, the skill updates it instead of creating duplicates:\n\n```\nUser: /openclaw-audit-watchdog\n\nAgent: Found existing \"Daily security audit (Prompt Security)\" job.\n       Current: Daily at 23:00 UTC → telegram:@oldhandle\n\n       Update delivery target? (current: telegram:@oldhandle)\nUser: slack:#security-alerts\n\nAgent: ✓ Updated cron job\n       Schedule: Daily at 23:00 UTC\n       Delivery: slack:#security-alerts\n```\n\n### Example 4: What Gets Delivered\n\nEach day at the scheduled time, you'll receive a report like:\n\n```\n🔭 Daily Security Audit Report\nHost: prod-server-01\nTime: 2026-02-16 23:00:00 America/New_York\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nSUMMARY\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n✓ Standard Audit: 12 checks passed, 2 warnings\n✓ Deep Audit: 8 probes passed, 1 critical\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nCRITICAL FINDINGS\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n[CRIT-001] Unencrypted API Keys Detected\n→ Remediation: Move credentials to encrypted vault or use environment variables\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nWARNINGS\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n[WARN-003] Outdated Dependencies Found\n→ Remediation: Run `openclaw security audit --fix` to update\n\n[WARN-007] Weak Permission on Config File\n→ Remediation: chmod 600 ~/.openclaw/config.json\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nRun `openclaw security audit --deep` for full details.\n```\n\n### Example 5: Custom Schedule\n\nWant a different schedule? Set it before invoking:\n\n```bash\n# Run every 6 hours instead of daily\nexport PROMPTSEC_SCHEDULE=\"0 */6 * * *\"\n/openclaw-audit-watchdog\n```\n\n### Example 6: Multiple Environments\n\nFor managing multiple servers, use different host labels:\n\n```bash\n# On dev server\nexport PROMPTSEC_HOST_LABEL=\"dev-01\"\nexport PROMPTSEC_DM_TO=\"@dev-team\"\n/openclaw-audit-watchdog\n\n# On prod server\nexport PROMPTSEC_HOST_LABEL=\"prod-01\"\nexport PROMPTSEC_DM_TO=\"@oncall\"\n/openclaw-audit-watchdog\n```\n\nEach will send reports with clear host identification.\n\n### Example 7: Suppressing Known Findings\n\nTo suppress audit findings that have been reviewed and accepted, pass the `--enable-suppressions` flag and ensure the config file includes the `\"enabledFor\": [\"audit\"]` sentinel:\n\n```bash\n# Create or edit the suppression config\ncat > ~/.openclaw/security-audit.json <<'JSON'\n{\n  \"enabledFor\": [\"audit\"],\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling — reviewed by security team\",\n      \"suppressedAt\": \"2026-02-15\"\n    }\n  ]\n}\nJSON\n\n# Run with suppressions enabled\n/openclaw-audit-watchdog --enable-suppressions\n```\n\nSuppressed findings still appear in the report under an informational section but are excluded from critical/warning totals.\n\n## Suppression / Allowlist\n\nThe audit pipeline supports an opt-in suppression mechanism for managing reviewed findings. Suppression uses defense-in-depth activation: two independent gates must both be satisfied.\n\n### Activation Requirements\n\n1. **CLI flag:** The `--enable-suppressions` flag must be passed at invocation.\n2. **Config sentinel:** The configuration file must include `\"enabledFor\"` with `\"audit\"` in the array.\n\nIf either gate is absent, all findings are reported normally and the suppression list is ignored.\n\n### Config File Resolution (4-tier)\n\n1. Explicit `--config <path>` argument\n2. `OPENCLAW_AUDIT_CONFIG` environment variable\n3. `~/.openclaw/security-audit.json`\n4. `.clawsec/allowlist.json`\n\n### Config Format\n\n```json\n{\n  \"enabledFor\": [\"audit\"],\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling — reviewed by security team\",\n      \"suppressedAt\": \"2026-02-15\"\n    }\n  ]\n}\n```\n\n### Sentinel Semantics\n\n- `\"enabledFor\": [\"audit\"]` -- audit suppression active (requires `--enable-suppressions` flag too)\n- `\"enabledFor\": [\"advisory\"]` -- only advisory pipeline suppression (no effect on audit)\n- `\"enabledFor\": [\"audit\", \"advisory\"]` -- both pipelines honor suppressions\n- Missing or empty `enabledFor` -- no suppression active (safe default)\n\n### Matching Rules\n\n- **checkId:** exact match against the audit finding's check identifier (e.g., `skills.code_safety`)\n- **skill:** case-insensitive match against the skill name from the finding\n- Both fields must match for a finding to be suppressed\n\n## Installation flow (interactive)\n\nProvisioning (MDM-friendly): prefer environment variables (no prompts).\n\nRequired env:\n- `PROMPTSEC_DM_CHANNEL` (e.g. `telegram`)\n- `PROMPTSEC_DM_TO` (recipient id)\n\nOptional env:\n- `PROMPTSEC_TZ` (IANA timezone; default `UTC`)\n- `PROMPTSEC_HOST_LABEL` (label included in report; default uses `hostname`)\n- `PROMPTSEC_INSTALL_DIR` (stable path used by cron payload to `cd` before running runner; default: `~/.config/security-checkup`)\n- `PROMPTSEC_GIT_PULL=1` (runner will `git pull --ff-only` if installed from git)\n\nInteractive install is last resort if env vars or defaults are not set.\n\neven in that case keep prompts minimalistic the watchdog tool is pretty straight up configured out of the box.\n\n## Create the cron job\n\nUse the `cron` tool to create a job with:\n\n- `schedule.kind=\"cron\"`\n- `schedule.expr=\"0 23 * * *\"`\n- `schedule.tz=<installer tz>`\n- `sessionTarget=\"isolated\"`\n- `wakeMode=\"now\"`\n- `payload.kind=\"agentTurn\"`\n- `payload.deliver=true`\n\n### Payload message template (agentTurn)\n\nCreate the job with a payload message that instructs the isolated run to:\n\n1) Run the audits\n\n- Prefer JSON output for robust parsing:\n  - `openclaw security audit --json`\n  - `openclaw security audit --deep --json`\n\n2) Render a concise text report:\n\nInclude:\n- Timestamp + host identifier if available\n- Summary counts\n- For each CRITICAL/WARN: `checkId` + `title` + 1-line remediation\n- If deep probe fails: include the probe error line\n\n3) Deliver the report:\n\n- DM to the chosen user target using `message` tool\n\n### Email delivery requirement\n\nAttempt email delivery in this priority order:\n\nA) If an email channel plugin exists in this deployment, use:\n- `message(action=\"send\", channel=\"email\", target=\"target@example.com\", message=<report>)`\n\nB) Otherwise, fallback to local sendmail if available:\n- `exec` with: `printf \"%s\" \"$REPORT\" | /usr/sbin/sendmail -t` (construct To/Subject headers)\n\nIf neither path is possible, still DM the user and include a line:\n- `\"NOTE: could not deliver to target@example.com (email channel not configured)\"`\n\n## Idempotency / updates\n\nBefore adding a new job:\n\n- `cron.list(includeDisabled=true)`\n- If a job with name matching `\"Daily security audit\"` exists, update it instead of adding a duplicate:\n  - adjust schedule tz/expr\n  - adjust DM target\n\n## Suggested naming\n\n- Job name: `\"Daily security audit (Prompt Security)\"`\n\n## Minimal recommended defaults (do not auto-change config)\n\nThe cron’s report should *suggest* fixes but must not apply them.\n\nDo not run `openclaw security audit --fix` unless explicitly asked.\n\nFile v0.1.0:examples/README.md\n\n# Security Audit Configuration Examples\n\n## Overview\n\nThis directory contains example configuration files for the OpenClaw security audit suppression mechanism.\n\n## Configuration File Format\n\nThe suppression configuration file must be valid JSON with the following structure:\n\n```json\n{\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling, reviewed 2026-02-13\",\n      \"suppressedAt\": \"2026-02-13\"\n    }\n  ]\n}\n```\n\n### Required Fields\n\nEach suppression entry must include:\n\n- **`checkId`** (string, required): The security check identifier that flagged the finding\n  - Example: `\"skills.code_safety\"`, `\"skills.permissions\"`, `\"skills.network\"`\n\n- **`skill`** (string, required): The exact skill name being suppressed\n  - Example: `\"clawsec-suite\"`, `\"openclaw-audit-watchdog\"`\n\n- **`reason`** (string, required): Justification for the suppression (audit trail)\n  - Example: `\"First-party security tooling, reviewed 2026-02-13\"`\n  - Example: `\"False positive - validated by security team on 2026-02-10\"`\n\n- **`suppressedAt`** (string, required): ISO 8601 date when suppression was added\n  - Format: `YYYY-MM-DD`\n  - Example: `\"2026-02-13\"`\n\n### Configuration File Locations\n\nThe suppression config is loaded from these locations (in priority order):\n\n1. **Custom path**: Specified via `--config` flag\n2. **Environment variable**: `OPENCLAW_AUDIT_CONFIG` env var\n3. **Primary default**: `~/.openclaw/security-audit.json`\n4. **Fallback**: `.clawsec/allowlist.json`\n\nIf no config file is found, the audit runs normally without suppressions (backward compatible).\n\n## Usage Examples\n\n### Basic Setup\n\n1. Copy the example config:\n```bash\nmkdir -p ~/.openclaw\ncp security-audit-config.example.json ~/.openclaw/security-audit.json\n```\n\n2. Customize the suppressions for your needs\n\n3. Run the audit:\n```bash\nopenclaw security audit --deep\n```\n\n### Using Custom Config Path\n\n```bash\nopenclaw security audit --deep --config /path/to/custom-config.json\n```\n\n### Managing False Positives\n\nWhen you encounter a false positive:\n\n1. Identify the `checkId` and `skill` name from the audit report\n2. Add a suppression entry with a clear reason\n3. Include the current date in ISO format\n4. Re-run the audit to verify the suppression works\n\nExample suppression entry:\n```json\n{\n  \"checkId\": \"skills.permissions\",\n  \"skill\": \"my-internal-tool\",\n  \"reason\": \"Broad permissions required for legitimate functionality, approved by security team\",\n  \"suppressedAt\": \"2026-02-16\"\n}\n```\n\n## Important Notes\n\n- **Transparency**: Suppressed findings remain visible in the audit report under \"INFO - SUPPRESSED\"\n- **Matching**: Suppressions require BOTH `checkId` AND `skill` to match (prevents over-suppression)\n- **Audit Trail**: Always document the reason and date for compliance\n- **Validation**: The config is validated on load - malformed JSON will produce a clear error\n\n## Example Use Case: First-Party Tools\n\nThe example config demonstrates suppressing false positives for ClawSec's own security tools:\n\n- **clawsec-suite**: Legitimately executes CLI commands for security scanning\n- **openclaw-audit-watchdog**: Legitimately accesses environment variables for auditing\n\nThese tools are flagged as \"dangerous\" by the security scanner but are safe first-party tools that have been reviewed.\n\nFile v0.1.0:README.md\n\n# OpenClaw Audit Watchdog 🔭\n\nAutomated daily security audits for OpenClaw/Clawdbot agents with email reporting.\n\n## Overview\n\nThe Audit Watchdog provides automated security monitoring for your OpenClaw agent deployments:\n\n- **Daily Security Scans** - Scheduled via cron for continuous monitoring\n- **Deep Audit Mode** - Comprehensive analysis of agent configurations and behavior\n- **Email Reporting** - Formatted reports delivered to your security team\n- **Git Integration** - Optionally syncs latest configurations before audit\n\n## Quick Start\n\n```bash\n# Install skill\nmkdir -p ~/.openclaw/skills/openclaw-audit-watchdog\ncd ~/.openclaw/skills/openclaw-audit-watchdog\n\n# Download and extract\ncurl -sSL \"https://github.com/prompt-security/clawsec/releases/download/$VERSION_TAG/openclaw-audit-watchdog.skill\" -o watchdog.skill\nunzip watchdog.skill\n\n# Configure\nexport PROMPTSEC_EMAIL_TO=\"security@yourcompany.com\"\nexport PROMPTSEC_HOST_LABEL=\"prod-agent-1\"\n\n# Run\n./scripts/runner.sh\n```\n\n## Configuration\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| `PROMPTSEC_EMAIL_TO` | Email recipient for reports | `target@example.com` |\n| `PROMPTSEC_HOST_LABEL` | Host identifier in reports | hostname |\n| `PROMPTSEC_GIT_PULL` | Pull latest before audit (0/1) | `0` |\n| `OPENCLAW_AUDIT_CONFIG` | Path to suppression config file | Auto-detected |\n\n## Suppression / Allowlist\n\nManage false-positive findings with the built-in suppression mechanism. Suppressed findings remain visible in reports but are demoted to informational status and do not count toward critical/warning totals.\n\nSuppression is **opt-in with defense in depth**: the audit pipeline requires BOTH a CLI flag AND a config-file sentinel before any finding is suppressed. This prevents accidental or unauthorized suppression.\n\n### Activation (Two Gates)\n\nBoth of the following must be true for audit suppressions to take effect:\n\n1. **CLI flag:** Pass `--enable-suppressions` when invoking the runner.\n2. **Config sentinel:** The configuration file must contain `\"enabledFor\": [\"audit\"]` (or a list that includes `\"audit\"`).\n\nIf either gate is missing, the suppression list is ignored entirely and all findings are reported normally.\n\n### Config File Resolution\n\nThe audit scanner resolves the suppression config file using this 4-tier priority:\n\n1. `--config <path>` CLI argument (highest priority)\n2. `OPENCLAW_AUDIT_CONFIG` environment variable\n3. `~/.openclaw/security-audit.json`\n4. `.clawsec/allowlist.json` (fallback)\n\n### Example Configuration\n\n```json\n{\n  \"enabledFor\": [\"audit\"],\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling, reviewed 2026-02-13\",\n      \"suppressedAt\": \"2026-02-13\"\n    },\n    {\n      \"checkId\": \"skills.permissions\",\n      \"skill\": \"my-internal-tool\",\n      \"reason\": \"Broad permissions required for legitimate functionality\",\n      \"suppressedAt\": \"2026-02-16\"\n    }\n  ]\n}\n```\n\nThe `enabledFor` array controls which pipelines honor the suppression list:\n\n| Value | Effect |\n|-------|--------|\n| `[\"audit\"]` | Only audit suppression active (still requires `--enable-suppressions` flag) |\n| `[\"advisory\"]` | Only advisory suppression active (used by clawsec-suite) |\n| `[\"audit\", \"advisory\"]` | Both pipelines honor suppressions |\n| Missing or `[]` | No suppression in any pipeline (safe default) |\n\n### Required Fields per Suppression Entry\n\n| Field | Description | Example |\n|-------|-------------|---------|\n| `checkId` | Audit check identifier to suppress | `skills.code_safety` |\n| `skill` | Skill name the suppression applies to | `clawsec-suite` |\n| `reason` | Justification for audit trail (required) | `First-party tooling, reviewed by security team` |\n| `suppressedAt` | ISO 8601 date (YYYY-MM-DD) | `2026-02-15` |\n\n**Matching:** Suppression requires an exact `checkId` match and a case-insensitive `skill` name match. Both must match for a finding to be suppressed.\n\n### Usage\n\n```bash\n# Enable suppressions with default config location\n./scripts/runner.sh --enable-suppressions\n\n# Enable suppressions with explicit config path\n./scripts/runner.sh --enable-suppressions --config /path/to/config.json\n\n# Enable suppressions with config via environment variable\nexport OPENCLAW_AUDIT_CONFIG=~/.openclaw/custom-audit.json\n./scripts/runner.sh --enable-suppressions\n```\n\nWithout `--enable-suppressions`, the config file is not consulted for suppressions:\n\n```bash\n# Suppressions NOT active (flag missing)\n./scripts/runner.sh\n./scripts/runner.sh --config /path/to/config.json\n```\n\n### Report Output\n\nSuppressed findings appear in a separate informational section:\n\n```\nCRITICAL (0):\n  (none)\n\nWARNINGS (1):\n  [skills.network] some-skill: Unrestricted network access\n\nINFO - SUPPRESSED (2):\n  [skills.code_safety] clawsec-suite: dangerous-exec detected\n    Reason: First-party security tooling, reviewed 2026-02-13\n  [skills.permissions] my-tool: Broad permission scope\n    Reason: Validated by security team, suppressedAt 2026-02-16\n```\n\nSee `examples/security-audit-config.example.json` for a complete template.\n\n## Scripts\n\n| Script | Purpose |\n|--------|---------|\n| `runner.sh` | Main entry - runs full audit pipeline |\n| `run_audit_and_format.sh` | Core audit execution |\n| `codex_review.sh` | AI-assisted code review |\n| `render_report.mjs` | HTML report generation |\n| `sendmail_report.sh` | Local sendmail delivery |\n| `send_smtp.mjs` | SMTP email delivery |\n| `setup_cron.mjs` | Cron job configuration |\n\n## Requirements\n\n- bash\n- curl\n- Optional: node (for SMTP/rendering), jq (for JSON), sendmail (for email)\n\n## Cron Setup\n\n```bash\n# Daily at 6 AM\n0 6 * * * /path/to/scripts/runner.sh\n```\n\nOr use the setup script:\n\n```bash\nnode scripts/setup_cron.mjs\n```\n\n## License\n\nMIT - See [LICENSE](../../LICENSE) for details.\n\n---\n\n**Part of [ClawSec](https://github.com/prompt-security/clawsec) by [Prompt Security](https://prompt.security)**\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"openclaw-audit-watchdog\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1771260966117\n}\n\nFile v0.1.0:CHANGELOG.md\n\n# Changelog\n\nAll notable changes to this project will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.1.0]\n\n### Added\n\n- Suppression/allowlist mechanism with explicit opt-in gating (defense in depth).\n- `--enable-suppressions` CLI flag for `run_audit_and_format.sh`, `render_report.mjs`, and `runner.sh`.\n- `enabledFor` config sentinel -- config must declare `\"enabledFor\": [\"audit\"]` for audit suppression to activate.\n- 4-tier config file resolution: explicit `--config` path > `OPENCLAW_AUDIT_CONFIG` env var > `~/.openclaw/security-audit.json` > `.clawsec/allowlist.json`.\n- `INFO-SUPPRESSED` section in report output showing suppressed findings with metadata.\n- Integration tests for suppression behavior (11 tests in `render_report_suppression.test.mjs`).\n- Unit tests for config loading and opt-in gating (15 tests in `suppression_config.test.mjs`).\n- Test fixtures: `empty-suppressions.json`, `invalid-json.json`, `malformed-config.json`.\n\n### Changed\n\n- `load_suppression_config.mjs` now requires explicit `{ enabled: true }` parameter -- returns empty suppressions by default.\n- `render_report.mjs` passes suppression enabled state to config loader.\n- Summary counts in report output are recalculated after filtering suppressed findings.\n\n### Security\n\n- Suppression is never active by default -- requires BOTH CLI flag AND config sentinel (defense in depth).\n- Environment variables alone cannot activate suppression (prevents ambient attack vector).\n\nFile v0.1.0:test/E2E-TEST-RESULTS.md\n\n# E2E Test Results: Suppression Mechanism\n\n## Test Date\n2026-02-16\n\n## Test Overview\nManual end-to-end test of the security audit suppression mechanism using mock audit data that simulates real openclaw security audit output.\n\n## Test Setup\n\n### Mock Data Created\n1. **mock-audit.json**: Simulates standard audit findings\n   - 1 critical finding from `clawsec-suite` (code_safety check)\n   - 1 warning finding from `example-skill` (permissions check)\n\n2. **mock-deep.json**: Simulates deep scan findings\n   - 1 critical finding from `openclaw-audit-watchdog` (code_safety check)\n   - 1 warning finding from `network-tool` (network check)\n\n3. **suppression-config.json**: Suppression rules\n   - Suppress `skills.code_safety` + `clawsec-suite`\n   - Suppress `skills.code_safety` + `openclaw-audit-watchdog`\n\n## Test Execution\n\n### Test 1: Baseline (No Suppression)\n**Command:**\n```bash\nnode render_report.mjs --audit mock-audit.json --deep mock-deep.json --label \"No Suppression\"\n```\n\n**Expected Behavior:**\n- All findings appear in report\n- 2 critical findings shown\n- 2 warning findings shown\n\n**Result:** ✅ PASSED\n- Summary showed: 1 critical · 1 warn\n- All findings displayed in critical/warn section\n- Skill names displayed: [clawsec-suite], [example-skill]\n\n### Test 2: With Suppression Config\n**Command:**\n```bash\nnode render_report.mjs --audit mock-audit.json --deep mock-deep.json \\\n  --label \"With Suppression\" --config suppression-config.json\n```\n\n**Expected Behavior:**\n- Suppressed findings appear in INFO-SUPPRESSED section\n- Summary counts exclude suppressed findings\n- Suppression reason and date displayed\n- Non-suppressed findings remain in active section\n\n**Result:** ✅ PASSED\n\n**Verification Points:**\n1. ✅ INFO-SUPPRESSED section present\n2. ✅ Suppression reason displayed: \"First-party security tooling, reviewed 2026-02-16\"\n3. ✅ Suppression date displayed: \"2026-02-16\"\n4. ✅ clawsec-suite finding suppressed and shown with [clawsec-suite] label\n5. ✅ openclaw-audit-watchdog finding suppressed and shown with [openclaw-audit-watchdog] label\n6. ✅ Non-suppressed findings still present: [example-skill] permission warning\n7. ✅ Critical count reduced to 0 (was 1, now suppressed)\n8. ✅ Warning count remains 1 (non-suppressed finding)\n\n## Sample Output\n\n### Without Suppression\n```\nopenclaw security audit report -- No Suppression\nTime: 2026-02-16T13:55:39.984Z\nSummary: 1 critical · 1 warn · 0 info\n\nFindings (critical/warn):\n- skills.code_safety [clawsec-suite] Dangerous code execution pattern detected\n  Fix: Review code execution patterns\n- skills.permissions [example-skill] Broad permission scope detected\n  Fix: Reduce permission scope\n```\n\n### With Suppression\n```\nopenclaw security audit report -- With Suppression\nTime: 2026-02-16T13:55:40.017Z\nSummary: 0 critical · 1 warn · 0 info\n\nFindings (critical/warn):\n- skills.permissions [example-skill] Broad permission scope detected\n  Fix: Reduce permission scope\n\nINFO-SUPPRESSED:\n- skills.code_safety [clawsec-suite] Dangerous code execution pattern detected\n  Suppressed: First-party security tooling, reviewed 2026-02-16 (2026-02-16)\n- skills.code_safety [openclaw-audit-watchdog] Environment variable access detected\n  Suppressed: First-party audit watchdog, reviewed 2026-02-16 (2026-02-16)\n```\n\n## Key Findings\n\n### ✅ Successes\n1. **Config Loading**: Suppression config loaded successfully from custom path\n2. **Matching Logic**: Findings correctly matched by BOTH checkId AND skill name\n3. **Filtering**: Suppressed findings excluded from critical/warning counts\n4. **Transparency**: Suppressed findings remain visible in INFO-SUPPRESSED section\n5. **Audit Trail**: Reason and date displayed for each suppression\n6. **Backward Compatibility**: Running without config works identically to before\n7. **Skill Name Display**: Skill names now displayed in both active and suppressed sections\n\n### 🔧 Improvements Made During Testing\n1. **Bug Fix**: Added --config flag passthrough in run_audit_and_format.sh\n   - Script was accepting --config but not passing it to render_report.mjs\n   - Fixed by building RENDER_ARGS array with conditional --config inclusion\n\n2. **Enhancement**: Added skill name display to active findings\n   - Improves consistency between active and suppressed findings\n   - Makes it clearer which skill each finding comes from\n   - Format: `[skill-name]` appears after checkId in output\n\n## Test Automation\nCreated `run-e2e-test.mjs` script for automated E2E validation with 8 verification points:\n- Baseline report correctness\n- INFO-SUPPRESSED section presence\n- Suppression reason display\n- Suppression date display\n- clawsec-suite suppression\n- openclaw-audit-watchdog suppression\n- Non-suppressed findings preservation\n- Summary count accuracy\n\n## Conclusion\n✅ **All E2E tests PASSED**\n\nThe suppression mechanism is working correctly end-to-end:\n- Configuration loads from custom paths\n- Matching requires both checkId and skill name (prevents over-suppression)\n- Suppressed findings remain visible with full audit trail\n- Summary counts accurately reflect only active findings\n- Non-suppressed findings continue to be reported normally\n- Skill names provide clear context for all findings\n\n## Next Steps\n1. ✅ Integration tests verified (10/10 passing)\n2. ✅ E2E test completed and documented\n3. ⏭️ Proceed to documentation phase (Phase 5)\n\nFile v0.1.0:examples/security-audit-config.example.json\n\n{\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling, reviewed 2026-02-13\",\n      \"suppressedAt\": \"2026-02-13\"\n    },\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"openclaw-audit-watchdog\",\n      \"reason\": \"First-party security tooling, reviewed 2026-02-13\",\n      \"suppressedAt\": \"2026-02-13\"\n    }\n  ]\n}\n\nFile v0.1.0:skill.json\n\n{\n  \"name\": \"openclaw-audit-watchdog\",\n  \"version\": \"0.1.0\",\n  \"description\": \"Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"MIT\",\n  \"homepage\": \"https://clawsec.prompt.security\",\n  \"keywords\": [\n    \"security\",\n    \"audit\",\n    \"watchdog\",\n    \"agents\",\n    \"ai\",\n    \"reporting\",\n    \"cron\",\n    \"monitoring\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Audit watchdog skill documentation\"\n      },\n      {\n        \"path\": \"scripts/runner.sh\",\n        \"required\": true,\n        \"description\": \"Main runner script\"\n      },\n      {\n        \"path\": \"scripts/run_audit_and_format.sh\",\n        \"required\": true,\n        \"description\": \"Audit execution and formatting\"\n      },\n      {\n        \"path\": \"scripts/codex_review.sh\",\n        \"required\": false,\n        \"description\": \"Codex-based code review\"\n      },\n      {\n        \"path\": \"scripts/render_report.mjs\",\n        \"required\": false,\n        \"description\": \"Report rendering (Node.js)\"\n      },\n      {\n        \"path\": \"scripts/sendmail_report.sh\",\n        \"required\": false,\n        \"description\": \"Sendmail delivery\"\n      },\n      {\n        \"path\": \"scripts/send_smtp.mjs\",\n        \"required\": false,\n        \"description\": \"SMTP delivery (Node.js)\"\n      },\n      {\n        \"path\": \"scripts/setup_cron.mjs\",\n        \"required\": false,\n        \"description\": \"Cron job setup\"\n      }\n    ]\n  },\n  \"openclaw\": {\n    \"emoji\": \"🔭\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"bash\",\n        \"curl\"\n      ]\n    },\n    \"triggers\": [\n      \"audit watchdog\",\n      \"security audit\",\n      \"daily audit\",\n      \"run audit\",\n      \"audit report\",\n      \"security report\",\n      \"watchdog check\",\n      \"deep audit\"\n    ]\n  }\n}\n\nFile v0.1.0:test/empty-suppressions.json\n\n{\n  \"suppressions\": []\n}\n\nFile v0.1.0:test/invalid-json.json\n\n{\n  \"suppressions\": [\n    invalid json here\n  ]\n}\n\nFile v0.1.0:test/malformed-config.json\n\n{\n  \"suppressions\": [\n    {\n      \"checkId\": \"test.check\",\n      \"skill\": \"test-skill\"\n    }\n  ]\n}","readmeExcerpt":"Skill: openclaw-audit-watchdog Owner: davida-ps Summary: Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports. Tags: latest:0.1.1 Version history: v0.1.1 | 2026-02-25T11:27:11.675Z | user Release 0.1.1 via CI v0.1.0 | 2026-02-16T16:56:06.117Z | user Release 0.1.0 via CI v0.0.4 | 2026-02-05T22:37:39.793Z | user Release 0.0.4 via CI v0.0.3 | 2026-02-05T2","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"export PROMPTSEC_DM_CHANNEL=\"telegram\"\nexport PROMPTSEC_DM_TO=\"@yourhandle\"\nexport PROMPTSEC_TZ=\"America/New_York\"\nexport PROMPTSEC_HOST_LABEL=\"prod-server-01\"\n\n# Then invoke the skill\n/openclaw-audit-watchdog"},{"language":"text","snippet":"User: /openclaw-audit-watchdog\n\nAgent: Setting up daily security audit watchdog...\n       What channel should I use for delivery? (e.g., telegram, slack)\nUser: telegram\n\nAgent: What's the recipient ID or handle?\nUser: @myhandle\n\nAgent: Which timezone for the 23:00 daily run? (default: UTC)\nUser: America/Los_Angeles\n\nAgent: ✓ Created cron job \"Daily security audit (Prompt Security)\"\n       Schedule: Daily at 23:00 America/Los_Angeles\n       Delivery: telegram → @myhandle"},{"language":"text","snippet":"User: /openclaw-audit-watchdog\n\nAgent: Found existing \"Daily security audit (Prompt Security)\" job.\n       Current: Daily at 23:00 UTC → telegram:@oldhandle\n\n       Update delivery target? (current: telegram:@oldhandle)\nUser: slack:#security-alerts\n\nAgent: ✓ Updated cron job\n       Schedule: Daily at 23:00 UTC\n       Delivery: slack:#security-alerts"},{"language":"text","snippet":"🔭 Daily Security Audit Report\nHost: prod-server-01\nTime: 2026-02-16 23:00:00 America/New_York\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nSUMMARY\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n✓ Standard Audit: 12 checks passed, 2 warnings\n✓ Deep Audit: 8 probes passed, 1 critical\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nCRITICAL FINDINGS\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n[CRIT-001] Unencrypted API Keys Detected\n→ Remediation: Move credentials to encrypted vault or use environment variables\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nWARNINGS\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\n[WARN-003] Outdated Dependencies Found\n→ Remediation: Run `openclaw security audit --fix` to update\n\n[WARN-007] Weak Permission on Config File\n→ Remediation: chmod 600 ~/.openclaw/config.json\n\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━\nRun `openclaw security audit --deep` for full details."},{"language":"bash","snippet":"# Run every 6 hours instead of daily\nexport PROMPTSEC_SCHEDULE=\"0 */6 * * *\"\n/openclaw-audit-watchdog"},{"language":"bash","snippet":"# On dev server\nexport PROMPTSEC_HOST_LABEL=\"dev-01\"\nexport PROMPTSEC_DM_TO=\"@dev-team\"\n/openclaw-audit-watchdog\n\n# On prod server\nexport PROMPTSEC_HOST_LABEL=\"prod-01\"\nexport PROMPTSEC_DM_TO=\"@oncall\"\n/openclaw-audit-watchdog"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: openclaw-audit-watchdog\nversion: 0.1.1\ndescription: Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports.\nhomepage: https://clawsec.prompt.security\nmetadata: {\"openclaw\":{\"emoji\":\"🔭\",\"category\":\"security\"}}\nclawdis:\n  emoji: \"🔭\"\n  requires:\n    bins: [bash, curl]\n---\n\n# Prompt Security Audit (openclaw)\n\n## Installation Options\n\nYou can get openclaw-audit-watchdog in two ways:\n\n### Option A: Bundled with ClawSec Suite (Recommended)\n\n**If you've installed clawsec-suite, you may already have this!**\n\nOpenclaw-audit-watchdog is bundled alongside ClawSec Suite to provide crucial automated security audit capabilities. When you install the suite, if you don't already have the audit watchdog installed, it will be deployed from the bundled copy.\n\n**Advantages:**\n- Convenient - no separate download needed\n- Standard location - installed to `~/.openclaw/skills/openclaw-audit-watchdog/`\n- Preserved - if you already have audit watchdog installed, it won't be overwritten\n- Single verification - integrity checked as part of suite package\n\n### Option B: Standalone Installation (This Page)\n\nInstall openclaw-audit-watchdog independently without the full suite.\n\n**When to use standalone:**\n- You only need the audit watchdog (not other suite components)\n- You want to install before installing the suite\n- You prefer explicit control over audit watchdog installation\n\n**Advantages:**\n- Lighter weight installation\n- Independent from suite\n- Direct control over installation process\n\nContinue below for standalone installation instructions.\n\n---\n\n## Goal\n\nCreate (or update) a daily cron job that:\n\n1) Runs:\n- `openclaw security audit --json`\n- `openclaw security audit --deep --json`\n\n2) Summarizes findings (critical/warn/info + top findings)\n\n3) Sends the report to:\n- a user-selected DM target (channel + recipient id/handle)\n\nDefault schedule: **daily at 23:00 (11pm)** in the chosen timezone.\n\nDelivery:\n- DM to last active session\n\n## Usage Examples\n\n### Example 1: Quick Start (Environment Variables)\n\nFor automated/MDM deployments, set environment variables before invoking:\n\n```bash\nexport PROMPTSEC_DM_CHANNEL=\"telegram\"\nexport PROMPTSEC_DM_TO=\"@yourhandle\"\nexport PROMPTSEC_TZ=\"America/New_York\"\nexport PROMPTSEC_HOST_LABEL=\"prod-server-01\"\n\n# Then invoke the skill\n/openclaw-audit-watchdog\n```\n\nThe skill will automatically configure and create the cron job without prompts.\n\n### Example 2: Interactive Setup\n\nIf environment variables aren't set, the skill will prompt minimally:\n\n```\nUser: /openclaw-audit-watchdog\n\nAgent: Setting up daily security audit watchdog...\n       What channel should I use for delivery? (e.g., telegram, slack)\nUser: telegram\n\nAgent: What's the recipient ID or handle?\nUser: @myhandle\n\nAgent: Which timezone for the 23:00 daily run? (default: UTC)\nUser: America/Los_Angeles\n\nAgent: ✓ Created cron job \"Daily security audit (Prompt Security)\"\n       Schedule: Daily at 23:00 America/"},{"path":"examples/README.md","content":"# Security Audit Configuration Examples\n\n## Overview\n\nThis directory contains example configuration files for the OpenClaw security audit suppression mechanism.\n\n## Configuration File Format\n\nThe suppression configuration file must be valid JSON with the following structure:\n\n```json\n{\n  \"suppressions\": [\n    {\n      \"checkId\": \"skills.code_safety\",\n      \"skill\": \"clawsec-suite\",\n      \"reason\": \"First-party security tooling, reviewed 2026-02-13\",\n      \"suppressedAt\": \"2026-02-13\"\n    }\n  ]\n}\n```\n\n### Required Fields\n\nEach suppression entry must include:\n\n- **`checkId`** (string, required): The security check identifier that flagged the finding\n  - Example: `\"skills.code_safety\"`, `\"skills.permissions\"`, `\"skills.network\"`\n\n- **`skill`** (string, required): The exact skill name being suppressed\n  - Example: `\"clawsec-suite\"`, `\"openclaw-audit-watchdog\"`\n\n- **`reason`** (string, required): Justification for the suppression (audit trail)\n  - Example: `\"First-party security tooling, reviewed 2026-02-13\"`\n  - Example: `\"False positive - validated by security team on 2026-02-10\"`\n\n- **`suppressedAt`** (string, required): ISO 8601 date when suppression was added\n  - Format: `YYYY-MM-DD`\n  - Example: `\"2026-02-13\"`\n\n### Configuration File Locations\n\nThe suppression config is loaded from these locations (in priority order):\n\n1. **Custom path**: Specified via `--config` flag\n2. **Environment variable**: `OPENCLAW_AUDIT_CONFIG` env var\n3. **Primary default**: `~/.openclaw/security-audit.json`\n4. **Fallback**: `.clawsec/allowlist.json`\n\nIf no config file is found, the audit runs normally without suppressions (backward compatible).\n\n## Usage Examples\n\n### Basic Setup\n\n1. Copy the example config:\n```bash\nmkdir -p ~/.openclaw\ncp security-audit-config.example.json ~/.openclaw/security-audit.json\n```\n\n2. Customize the suppressions for your needs\n\n3. Run the audit:\n```bash\nopenclaw security audit --deep\n```\n\n### Using Custom Config Path\n\n```bash\nopenclaw security audit --deep --config /path/to/custom-config.json\n```\n\n### Managing False Positives\n\nWhen you encounter a false positive:\n\n1. Identify the `checkId` and `skill` name from the audit report\n2. Add a suppression entry with a clear reason\n3. Include the current date in ISO format\n4. Re-run the audit to verify the suppression works\n\nExample suppression entry:\n```json\n{\n  \"checkId\": \"skills.permissions\",\n  \"skill\": \"my-internal-tool\",\n  \"reason\": \"Broad permissions required for legitimate functionality, approved by security team\",\n  \"suppressedAt\": \"2026-02-16\"\n}\n```\n\n## Important Notes\n\n- **Transparency**: Suppressed findings remain visible in the audit report under \"INFO - SUPPRESSED\"\n- **Matching**: Suppressions require BOTH `checkId` AND `skill` to match (prevents over-suppression)\n- **Audit Trail**: Always document the reason and date for compliance\n- **Validation**: The config is validated on load - malformed JSON will produce a clear error\n\n## Example Use Case: First-Party Tools\n\nThe example config de"},{"path":"README.md","content":"# OpenClaw Audit Watchdog 🔭\n\nAutomated daily security audits for OpenClaw/Clawdbot agents with email reporting.\n\n## Overview\n\nThe Audit Watchdog provides automated security monitoring for your OpenClaw agent deployments:\n\n- **Daily Security Scans** - Scheduled via cron for continuous monitoring\n- **Deep Audit Mode** - Comprehensive analysis of agent configurations and behavior\n- **Email Reporting** - Formatted reports delivered to your security team\n- **Git Integration** - Optionally syncs latest configurations before audit\n\n## Quick Start\n\n```bash\n# Install skill\nmkdir -p ~/.openclaw/skills/openclaw-audit-watchdog\ncd ~/.openclaw/skills/openclaw-audit-watchdog\n\n# Download and extract\ncurl -sSL \"https://github.com/prompt-security/clawsec/releases/download/$VERSION_TAG/openclaw-audit-watchdog.skill\" -o watchdog.skill\nunzip watchdog.skill\n\n# Configure\nexport PROMPTSEC_EMAIL_TO=\"security@yourcompany.com\"\nexport PROMPTSEC_HOST_LABEL=\"prod-agent-1\"\n\n# Run\n./scripts/runner.sh\n```\n\n## Configuration\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| `PROMPTSEC_EMAIL_TO` | Email recipient for reports | `target@example.com` |\n| `PROMPTSEC_HOST_LABEL` | Host identifier in reports | hostname |\n| `PROMPTSEC_GIT_PULL` | Pull latest before audit (0/1) | `0` |\n| `OPENCLAW_AUDIT_CONFIG` | Path to suppression config file | Auto-detected |\n\n### Path Expansion and Quoting\n\n- `PROMPTSEC_INSTALL_DIR` and `OPENCLAW_AUDIT_CONFIG` support `~`, `$HOME`, `${HOME}`, `%USERPROFILE%`, and `$env:USERPROFILE`.\n- In `bash`/`zsh`, use double quotes for expandable paths:\n  - `export PROMPTSEC_INSTALL_DIR=\"$HOME/.config/security-checkup\"`\n- Avoid single-quoted literals such as `'$HOME/.config/security-checkup'`.\n- In PowerShell:\n  - `$env:PROMPTSEC_INSTALL_DIR = Join-Path $HOME \".config/security-checkup\"`\n\n## Suppression / Allowlist\n\nManage false-positive findings with the built-in suppression mechanism. Suppressed findings remain visible in reports but are demoted to informational status and do not count toward critical/warning totals.\n\nSuppression is **opt-in with defense in depth**: the audit pipeline requires BOTH a CLI flag AND a config-file sentinel before any finding is suppressed. This prevents accidental or unauthorized suppression.\n\n### Activation (Two Gates)\n\nBoth of the following must be true for audit suppressions to take effect:\n\n1. **CLI flag:** Pass `--enable-suppressions` when invoking the runner.\n2. **Config sentinel:** The configuration file must contain `\"enabledFor\": [\"audit\"]` (or a list that includes `\"audit\"`).\n\nIf either gate is missing, the suppression list is ignored entirely and all findings are reported normally.\n\n### Config File Resolution\n\nThe audit scanner resolves the suppression config file using this 4-tier priority:\n\n1. `--config <path>` CLI argument (highest priority)\n2. `OPENCLAW_AUDIT_CONFIG` environment variable\n3. `~/.openclaw/security-audit.json`\n4. `.clawsec/allowlist.json` (fallback)\n\n### Example Configuration\n\n`"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"openclaw-audit-watchdog\",\n  \"version\": \"0.1.1\",\n  \"publishedAt\": 1772018831675\n}"},{"path":"CHANGELOG.md","content":"# Changelog\n\nAll notable changes to this project will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.1.1]\n\n### Added\n\n- Contributor credit: portability and path-hardening improvements in this release were contributed by [@aldodelgado](https://github.com/aldodelgado) in PR #62.\n- Cross-shell home-path expansion support in watchdog path inputs (`~`, `$HOME`, `${HOME}`, `%USERPROFILE%`, `$env:HOME`).\n- Regression coverage for suppression-config home-token expansion and escaped-token rejection (`test/suppression_config.test.mjs`).\n\n### Changed\n\n- `scripts/codex_review.sh` now resolves the Codex CLI from `CODEX_BIN`, then `PATH`, then Homebrew fallback for improved portability.\n- `scripts/setup_cron.mjs` now normalizes and validates install-dir/home-derived paths before job creation.\n- `scripts/load_suppression_config.mjs` now resolves/normalizes configured file paths consistently across shell styles.\n\n### Security\n\n- Escaped or unresolved home tokens in suppression config paths now fail fast to avoid silently using unintended literal paths.\n\n## [0.1.0]\n\n### Added\n\n- Suppression/allowlist mechanism with explicit opt-in gating (defense in depth).\n- `--enable-suppressions` CLI flag for `run_audit_and_format.sh`, `render_report.mjs`, and `runner.sh`.\n- `enabledFor` config sentinel -- config must declare `\"enabledFor\": [\"audit\"]` for audit suppression to activate.\n- 4-tier config file resolution: explicit `--config` path > `OPENCLAW_AUDIT_CONFIG` env var > `~/.openclaw/security-audit.json` > `.clawsec/allowlist.json`.\n- `INFO-SUPPRESSED` section in report output showing suppressed findings with metadata.\n- Integration tests for suppression behavior (11 tests in `render_report_suppression.test.mjs`).\n- Unit tests for config loading and opt-in gating (15 tests in `suppression_config.test.mjs`).\n- Test fixtures: `empty-suppressions.json`, `invalid-json.json`, `malformed-config.json`.\n\n### Changed\n\n- `load_suppression_config.mjs` now requires explicit `{ enabled: true }` parameter -- returns empty suppressions by default.\n- `render_report.mjs` passes suppression enabled state to config loader.\n- Summary counts in report output are recalculated after filtering suppressed findings.\n\n### Security\n\n- Suppression is never active by default -- requires BOTH CLI flag AND config sentinel (defense in depth).\n- Environment variables alone cannot activate suppression (prevents ambient attack vector)."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports. Skill: openclaw-audit-watchdog Owner: davida-ps Summary: Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports. Tags: latest:0.1.1 Version history: v0.1.1 | 2026-02-25T11:27:11.675Z | user Release 0.1.1 via CI v0.1.0 | 2026-02-16T16:56:06.117Z | user Release 0.1.0 via CI v0.0.4 | 2026-02-05T22:37:39.793Z | user Release 0.0.4 via CI v0.0.3 | 2026-02-05T2","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1428,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T00:15:13.381Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}