{"id":"0c6bb62e-c684-472b-992f-54c619351a36","entityType":"agent","slug":"clawhub-fletcherfrimpong-cyber-security-engineer","name":"Cyber Security Engineer","canonicalUrl":"https://www.xpersona.co/agent/clawhub-fletcherfrimpong-cyber-security-engineer","canonicalPath":"/agent/clawhub-fletcherfrimpong-cyber-security-engineer","generatedAt":"2026-10-09T17:33:50.705Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle tim...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 552 downloads reported by the source. Last updated 4/15/2026.","installCommand":"clawhub skill install kn76xzywt869tsh3r3tjtk1ybs814s22:cyber-security-engineer","sourceUrl":"https://clawhub.ai/FletcherFrimpong/cyber-security-engineer","homepage":"https://clawhub.ai/FletcherFrimpong/cyber-security-engineer","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/FletcherFrimpong/cyber-security-engineer","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":55,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Cyber Security Engineer technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"stars":null,"forks":null,"downloads":552,"packageName":null,"latestVersion":"0.1.4","tractionLabel":"552 downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-03-01T04:46:03.732Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-03-01T04:46:03.732Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-02T04:46:03.732Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.4","createdAt":"2026-02-15T11:26:10.584Z","changelog":"Harden notify_on_violation: remove shell execution; require allowlisted notifier executable.","fileCount":27,"zipByteSize":43319},{"version":"0.1.3","createdAt":"2026-02-15T11:12:39.348Z","changelog":"Document requirements and clarify approved-ports baseline generation; minor docs hygiene.","fileCount":27,"zipByteSize":42796},{"version":"0.1.2","createdAt":"2026-02-15T00:41:32.954Z","changelog":"Patch-6 republish under canonical slug; same contents as fletcher-cyber-security-engineer@0.1.2.","fileCount":null,"zipByteSize":null},{"version":"0.1.1","createdAt":"2026-02-15T00:27:08.025Z","changelog":"Republish under canonical slug. Same contents as fletcher-cyber-security-engineer@0.1.1.","fileCount":null,"zipByteSize":null}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install kn76xzywt869tsh3r3tjtk1ybs814s22:cyber-security-engineer","setupComplexity":"low","setupSteps":["Install using `clawhub skill install kn76xzywt869tsh3r3tjtk1ybs814s22:cyber-security-engineer` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/FletcherFrimpong/cyber-security-engineer before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T17:33:50.704Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-fletcherfrimpong-cyber-security-engineer/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"Skill: Cyber Security Engineer\n\nOwner: FletcherFrimpong\n\nSummary: Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle tim...\n\nTags: compliance:0.1.4, iso27001:0.1.4, latest:0.1.4, nist:0.1.4, security:0.1.4\n\nVersion history:\n\nv0.1.4 | 2026-02-15T11:26:10.584Z | user\n\nHarden notify_on_violation: remove shell execution; require allowlisted notifier executable.\n\nv0.1.3 | 2026-02-15T11:12:39.348Z | user\n\nDocument requirements and clarify approved-ports baseline generation; minor docs hygiene.\n\nv0.1.2 | 2026-02-15T00:41:32.954Z | user\n\nPatch-6 republish under canonical slug; same contents as fletcher-cyber-security-engineer@0.1.2.\n\nv0.1.1 | 2026-02-15T00:27:08.025Z | user\n\nRepublish under canonical slug. Same contents as fletcher-cyber-security-engineer@0.1.1.\n\nArchive index:\n\nArchive v0.1.4: 27 files, 43319 bytes\n\nFiles: agents/openai.yaml (331b), assessments/compliance-dashboard.html (6200b), assessments/compliance-summary.json (14125b), assessments/openclaw-assessment.json (3591b), references/approved_ports.template.json (149b), references/command-policy.template.json (141b), references/compliance-controls-map.json (5491b), references/egress-allowlist.template.json (117b), references/least-privilege-policy.md (1868b), references/port-monitoring-policy.md (1307b), references/prompt-policy.template.json (50b), scripts/audit_logger.py (800b), scripts/auto_invoke_cycle.sh (1444b), scripts/command_policy.py (2089b), scripts/compliance_dashboard.py (11424b), scripts/egress_monitor.py (7931b), scripts/generate_approved_ports.py (3986b), scripts/guarded_privileged_exec.py (8426b), scripts/install-openclaw-runtime-hook.sh (3206b), scripts/live_assessment.py (21630b), scripts/notify_on_violation.py (7041b), scripts/port_monitor.py (10050b), scripts/preflight_check.py (4233b), scripts/prompt_policy.py (726b), scripts/root_session_guard.py (12327b), SKILL.md (3751b), _meta.json (142b)\n\nFile v0.1.4:SKILL.md\n\n---\nname: cyber-security-engineer\ndescription: Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle timeout controls, port + egress monitoring, and ISO 27001/NIST-aligned compliance reporting with mitigations.\n---\n\n# Cyber Security Engineer\n\n## Requirements\n\n**Env vars (optional, but documented):**\n- `OPENCLAW_REQUIRE_POLICY_FILES`\n- `OPENCLAW_REQUIRE_SESSION_ID`\n- `OPENCLAW_TASK_SESSION_ID`\n- `OPENCLAW_APPROVAL_TOKEN`\n- `OPENCLAW_UNTRUSTED_SOURCE`\n- `OPENCLAW_VIOLATION_NOTIFY_CMD`\n- `OPENCLAW_VIOLATION_NOTIFY_ALLOWLIST`\n\n**Tools:** `python3` and one of `lsof`, `ss`, or `netstat` for port/egress checks.\n\n**Policy files (admin reviewed):**\n- `~/.openclaw/security/approved_ports.json`\n- `~/.openclaw/security/command-policy.json`\n- `~/.openclaw/security/egress_allowlist.json`\n- `~/.openclaw/security/prompt-policy.json`\n\nImplement these controls in every security-sensitive task:\n\n1. Keep default execution in normal (non-root) mode.\n2. Request explicit user approval before any elevated command.\n3. Scope elevation to the minimum command set required for the active task.\n4. Drop elevated state immediately after the privileged command completes.\n5. Expire elevated state after 30 idle minutes and require re-approval.\n6. Monitor listening network ports and flag insecure or unapproved exposure.\n7. Monitor outbound connections and flag destinations not in the egress allowlist.\n8. If no approved baseline exists, generate one with `python3 scripts/generate_approved_ports.py`, then review and prune.\n9. Benchmark controls against ISO 27001 and NIST and report violations with mitigations.\n\n## Non-Goals (Web Browsing)\n\n- Do not use web browsing / web search as part of this skill. Keep assessments and recommendations based on local host/OpenClaw state and the bundled references in this skill.\n\n## Files To Use\n\n- `references/least-privilege-policy.md`\n- `references/port-monitoring-policy.md`\n- `references/compliance-controls-map.json`\n- `references/approved_ports.template.json`\n- `references/command-policy.template.json`\n- `references/prompt-policy.template.json`\n- `references/egress-allowlist.template.json`\n- `scripts/preflight_check.py`\n- `scripts/root_session_guard.py`\n- `scripts/audit_logger.py`\n- `scripts/command_policy.py`\n- `scripts/prompt_policy.py`\n- `scripts/guarded_privileged_exec.py`\n- `scripts/install-openclaw-runtime-hook.sh`\n- `scripts/port_monitor.py`\n- `scripts/generate_approved_ports.py`\n- `scripts/egress_monitor.py`\n- `scripts/notify_on_violation.py`\n- `scripts/compliance_dashboard.py`\n- `scripts/live_assessment.py`\n\n## Behavior\n\n- Never keep root/elevated access open between unrelated tasks.\n- Never execute root commands without an explicit approval step in the current flow.\n- Enforce command allow/deny policy when configured.\n- Require confirmation when untrusted content sources are detected (`OPENCLAW_UNTRUSTED_SOURCE=1` + prompt policy).\n- Enforce task session id scoping when configured (`OPENCLAW_REQUIRE_SESSION_ID=1`).\n- If timeout is exceeded, force session expiration and approval renewal.\n- Log privileged actions to `~/.openclaw/security/privileged-audit.jsonl` (best-effort).\n- Flag listening ports not present in the approved baseline and recommend secure alternatives for insecure ports.\n- Flag outbound destinations not present in the egress allowlist.\n\n## Output Contract\n\nWhen reporting status, include:\n\n- The specific `check_id`(s) affected, `status`, `risk`, and concise evidence.\n- Concrete mitigations (what to change, where) and any owners/due dates if present.\n- For network findings: port, bind address, process/service, and why it is flagged (unapproved/insecure/public).\n\nFile v0.1.4:_meta.json\n\n{\n  \"ownerId\": \"kn76xzywt869tsh3r3tjtk1ybs814s22\",\n  \"slug\": \"cyber-security-engineer\",\n  \"version\": \"0.1.4\",\n  \"publishedAt\": 1771154770584\n}\n\nFile v0.1.4:references/approved_ports.template.json\n\n[\n  {\n    \"port\": 18789,\n    \"protocol\": \"tcp\",\n    \"command\": \"node\",\n    \"comment\": \"OpenClaw gateway (example). Remove if not applicable.\"\n  }\n]\n\nFile v0.1.4:references/command-policy.template.json\n\n{\n  \"allow\": [\n    \"^openclaw\\\\b\",\n    \"^python3\\\\b\"\n  ],\n  \"deny\": [\n    \"\\\\brm\\\\s+-rf\\\\b\",\n    \"\\\\bshutdown\\\\b\",\n    \"\\\\breboot\\\\b\"\n  ]\n}\n\nFile v0.1.4:references/compliance-controls-map.json\n\n[\n  {\n    \"check_id\": \"privilege_approval_required\",\n    \"title\": \"Approval required before elevated access\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\", \"PR.AA-05\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Every privileged action requires explicit user approval.\"\n  },\n  {\n    \"check_id\": \"least_privilege_enforced\",\n    \"title\": \"Least privilege execution mode\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\", \"PR.PS-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Default mode is non-root and elevated rights are scoped and short-lived.\"\n  },\n  {\n    \"check_id\": \"elevation_timeout_30m\",\n    \"title\": \"Elevated session idle timeout\",\n    \"iso27001\": [\"A.8.2\", \"A.8.15\"],\n    \"nist\": [\"PR.AA-03\", \"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Elevated session expires after 30 minutes of inactivity.\"\n  },\n  {\n    \"check_id\": \"audit_logging_privileged_actions\",\n    \"title\": \"Privileged action audit logging\",\n    \"iso27001\": [\"A.8.15\", \"A.8.16\"],\n    \"nist\": [\"DE.AE-03\", \"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"All elevated approvals, commands, and privilege drops are logged.\"\n  },\n  {\n    \"check_id\": \"open_ports_approved\",\n    \"title\": \"Open ports baseline approval\",\n    \"iso27001\": [\"A.8.20\", \"A.8.21\"],\n    \"nist\": [\"PR.PS-02\", \"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"All listening ports are approved and business-justified.\"\n  },\n  {\n    \"check_id\": \"insecure_ports_remediated\",\n    \"title\": \"Insecure ports remediated\",\n    \"iso27001\": [\"A.8.20\", \"A.8.21\"],\n    \"nist\": [\"PR.PS-02\", \"PR.DS-02\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Insecure legacy ports are closed or migrated to secure alternatives.\"\n  },\n  {\n    \"check_id\": \"channel_allowlist_configured\",\n    \"title\": \"Channel allowlist configured\",\n    \"iso27001\": [\"A.5.15\", \"A.5.16\"],\n    \"nist\": [\"PR.AA-02\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Inbound channels restrict senders via allowlists.\"\n  },\n  {\n    \"check_id\": \"group_mentions_required\",\n    \"title\": \"Group mention requirement\",\n    \"iso27001\": [\"A.5.16\"],\n    \"nist\": [\"PR.AA-04\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Group chats require explicit mention before agent responds.\"\n  },\n  {\n    \"check_id\": \"gateway_loopback_only\",\n    \"title\": \"Gateway bound to loopback\",\n    \"iso27001\": [\"A.8.9\", \"A.8.10\"],\n    \"nist\": [\"PR.IP-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Gateway runs local/loopback with token auth.\"\n  },\n  {\n    \"check_id\": \"secrets_permissions_hardened\",\n    \"title\": \"Secrets and config permissions hardened\",\n    \"iso27001\": [\"A.8.11\"],\n    \"nist\": [\"PR.DS-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"OpenClaw config and secrets are not world/group readable.\"\n  },\n  {\n    \"check_id\": \"runtime_privilege_hook_installed\",\n    \"title\": \"Runtime privileged execution hook installed\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Privileged commands are forced through approval guard.\"\n  },\n  {\n    \"check_id\": \"alternate_privilege_paths_restricted\",\n    \"title\": \"Alternate privilege paths restricted\",\n    \"iso27001\": [\"A.5.15\"],\n    \"nist\": [\"PR.AA-05\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"su/doas or other escalation paths are restricted or guarded.\"\n  },\n  {\n    \"check_id\": \"backup_configured\",\n    \"title\": \"Backup and recovery configured\",\n    \"iso27001\": [\"A.8.13\"],\n    \"nist\": [\"PR.IP-04\"],\n    \"default_risk\": \"low\",\n    \"expected_state\": \"Backups of OpenClaw config and audit logs exist.\"\n  },\n  {\n    \"check_id\": \"update_hygiene\",\n    \"title\": \"Update hygiene\",\n    \"iso27001\": [\"A.8.8\"],\n    \"nist\": [\"ID.RA-01\"],\n    \"default_risk\": \"low\",\n    \"expected_state\": \"OpenClaw is updated regularly and version is tracked.\"\n  },\n  {\n    \"check_id\": \"prompt_injection_controls\",\n    \"title\": \"Prompt injection controls\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Untrusted content sources require explicit confirmation before privileged execution.\"\n  },\n  {\n    \"check_id\": \"command_policy_enforced\",\n    \"title\": \"Privileged command policy enforced\",\n    \"iso27001\": [\"A.5.15\"],\n    \"nist\": [\"PR.AA-05\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Privileged commands are filtered by allow/deny policy.\"\n  },\n  {\n    \"check_id\": \"session_boundary_enforced\",\n    \"title\": \"Task session boundary enforced\",\n    \"iso27001\": [\"A.5.15\"],\n    \"nist\": [\"PR.AA-03\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Privileged approvals are scoped to a task session id.\"\n  },\n  {\n    \"check_id\": \"multi_factor_approval\",\n    \"title\": \"Multi-factor approval for privileged actions\",\n    \"iso27001\": [\"A.5.17\"],\n    \"nist\": [\"PR.AA-02\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Privileged approvals require an additional approval token.\"\n  },\n  {\n    \"check_id\": \"egress_allowlist_configured\",\n    \"title\": \"Outbound allowlist configured\",\n    \"iso27001\": [\"A.8.20\"],\n    \"nist\": [\"PR.PS-02\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Outbound destinations are allowlisted.\"\n  },\n  {\n    \"check_id\": \"egress_connections_approved\",\n    \"title\": \"Outbound connections approved\",\n    \"iso27001\": [\"A.8.20\"],\n    \"nist\": [\"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"No unapproved outbound connections are detected.\"\n  }\n]\n\nFile v0.1.4:references/egress-allowlist.template.json\n\n[\n  {\n    \"protocol\": \"tcp\",\n    \"host_regex\": \"^(api\\\\.openai\\\\.com|api\\\\.telegram\\\\.org)$\",\n    \"port\": 443\n  }\n]\n\nFile v0.1.4:references/least-privilege-policy.md\n\n# Least-Privilege Policy For OpenClaw\n\n## Objective\n\nEnforce default non-root execution and explicit approval-first elevation with immediate privilege drop after privileged operations.\n\n## Required Controls\n\n1. Set default execution context to non-root.\n2. Require approval before every privileged command.\n3. Limit privileged commands to a reviewed allowlist (per-task scope).\n4. Log privileged requests, approvals, and execution outcomes.\n5. Drop elevated state immediately after privileged command completion.\n6. Force elevated timeout expiration after 30 idle minutes.\n\n## Operational Checks\n\n1. Verify privileged command is required for task outcome.\n2. Execute privileged work through wrapper:\n   - `python3 scripts/guarded_privileged_exec.py --reason \"required change\" --use-sudo -- <command>`\n3. If wrapper requests approval, require explicit user consent before command runs.\n4. Execute only the approved privileged command(s):\n   - Approval is tied to the exact argv you approved.\n   - Any different privileged argv triggers a new approval and allowlist entry.\n5. Confirm wrapper drops privilege immediately after completion.\n\n## Control Acceptance Criteria\n\n1. No privileged command runs without current-task user approval.\n2. Elevated session is not retained after privileged work completes.\n3. Idle elevated session at or above 30 minutes transitions to normal mode.\n4. Session state file records UTC transition/action metadata.\n\n## Suggested OpenClaw Config Direction\n\nConfigure OpenClaw with strict approval and allowlist behavior:\n\n- Set execution ask behavior to always prompt.\n- Set execution security mode to allowlist.\n- Restrict elevated tool callers with explicit `allowFrom` entries.\n- Keep sandboxing enabled for normal operations.\n\nIf exact keys differ by version, preserve intent: explicit approval + least privilege + short-lived elevation.\n\nFile v0.1.4:references/port-monitoring-policy.md\n\n# Port Monitoring Policy For OpenClaw\n\n## Objective\n\nContinuously identify listening services, detect insecure ports/protocols, and flag ports not approved by baseline policy.\n\n## Baseline File\n\nUse `~/.openclaw/security/approved_ports.json` as a JSON array:\n\n```json\n[\n  { \"port\": 22, \"protocol\": \"tcp\", \"command\": \"sshd\" },\n  { \"port\": 443, \"protocol\": \"tcp\", \"command\": \"nginx\" }\n]\n```\n\n`command` is optional but recommended for tighter control.\n\n## Monitoring Command\n\nRun:\n\n`python3 scripts/port_monitor.py --json`\n\n## Required Analyst Actions\n\n1. Review all `unapproved-port` findings.\n2. Review all `insecure-port` findings and propose secure alternatives.\n3. Confirm whether `public-bind` findings are necessary exposure.\n4. Ask for user approval before any root-level remediation steps.\n\n## Insecure Port Guidance\n\nEnforce upgrades where possible:\n\n1. `80 -> 443` (HTTPS instead of HTTP)\n2. `23 -> 22` (SSH instead of Telnet)\n3. `21 -> 22/990` (SFTP/FTPS instead of FTP)\n4. `110 -> 995` (POP3S)\n5. `143 -> 993` (IMAPS)\n6. `389 -> 636` (LDAPS)\n\n## Acceptance Criteria\n\n1. Every open listening port is either approved or explicitly flagged.\n2. Every insecure port includes a replacement recommendation.\n3. Every externally bound service (`*`, `0.0.0.0`, `::`) is justified or marked for restriction.\n\nFile v0.1.4:references/prompt-policy.template.json\n\n{\n  \"require_confirmation_for_untrusted\": true\n}\n\nFile v0.1.4:assessments/compliance-summary.json\n\n{\n  \"generated_at_utc\": \"2026-02-14T13:48:28.593079Z\",\n  \"system\": \"OpenClaw\",\n  \"summary\": {\n    \"status_counts\": {\n      \"violation\": 2,\n      \"compliant\": 2,\n      \"partial\": 2\n    },\n    \"risk_counts\": {\n      \"high\": 3,\n      \"medium\": 3\n    },\n    \"violations\": [\n      {\n        \"check_id\": \"privilege_approval_required\",\n        \"title\": \"Approval required before elevated access\",\n        \"iso27001\": [\n          \"A.5.15\",\n          \"A.5.18\"\n        ],\n        \"nist\": [\n          \"PR.AA-01\",\n          \"PR.AA-05\"\n        ],\n        \"expected_state\": \"Every privileged action requires explicit user approval.\",\n        \"status\": \"violation\",\n        \"risk\": \"high\",\n        \"observed_state\": \"Token auth is configured; explicit privileged command approval policy is not fully visible in runtime config.\",\n        \"evidence\": \"openclaw.json and doctor outputs were evaluated for approval-first execution controls.\",\n        \"gap\": \"Runtime policy does not yet demonstrate universal approval enforcement for elevated actions.\",\n        \"mitigation\": \"Route all privileged tasks through guarded_privileged_exec.py and enforce approval prompts for elevated execution.\",\n        \"owner\": \"Security Engineering\",\n        \"due_date\": \"2026-03-15\"\n      },\n      {\n        \"check_id\": \"elevation_timeout_30m\",\n        \"title\": \"Elevated session idle timeout\",\n        \"iso27001\": [\n          \"A.8.2\",\n          \"A.8.15\"\n        ],\n        \"nist\": [\n          \"PR.AA-03\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"Elevated session expires after 30 minutes of inactivity.\",\n        \"status\": \"partial\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"30-minute timeout logic exists in root_session_guard.py.\",\n        \"evidence\": \"Timeout guard script is installed with preflight drop logic.\",\n        \"gap\": \"Global mandatory enforcement for all elevated paths is not yet guaranteed by runtime policy.\",\n        \"mitigation\": \"Invoke guarded_privileged_exec.py for every elevated operation path.\",\n        \"owner\": \"Security Engineering\",\n        \"due_date\": \"2026-03-15\"\n      },\n      {\n        \"check_id\": \"audit_logging_privileged_actions\",\n        \"title\": \"Privileged action audit logging\",\n        \"iso27001\": [\n          \"A.8.15\",\n          \"A.8.16\"\n        ],\n        \"nist\": [\n          \"DE.AE-03\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"All elevated approvals, commands, and privilege drops are logged.\",\n        \"status\": \"partial\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"Gateway logs and session transition logs are available.\",\n        \"evidence\": \"gateway status reports log paths; root_session_guard records transition metadata.\",\n        \"gap\": \"No single correlated privileged action audit timeline is guaranteed.\",\n        \"mitigation\": \"Create append-only correlated audit records linking approval, execution, and drop events.\",\n        \"owner\": \"SecOps\",\n        \"due_date\": \"2026-03-22\"\n      },\n      {\n        \"check_id\": \"open_ports_approved\",\n        \"title\": \"Open ports baseline approval\",\n        \"iso27001\": [\n          \"A.8.20\",\n          \"A.8.21\"\n        ],\n        \"nist\": [\n          \"PR.PS-02\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"All listening ports are approved and business-justified.\",\n        \"status\": \"violation\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"Detected 12 listening services with 12 unapproved findings.\",\n        \"evidence\": \"port_monitor.py live output evaluated against approved_ports baseline.\",\n        \"gap\": \"Baseline missing or incomplete when unapproved findings exist.\",\n        \"mitigation\": \"Populate ~/.openclaw/security/approved_ports.json and remove unnecessary listeners.\",\n        \"owner\": \"Infrastructure\",\n        \"due_date\": \"2026-02-28\"\n      }\n    ],\n    \"mitigations\": [\n      {\n        \"check_id\": \"privilege_approval_required\",\n        \"title\": \"Approval required before elevated access\",\n        \"iso27001\": [\n          \"A.5.15\",\n          \"A.5.18\"\n        ],\n        \"nist\": [\n          \"PR.AA-01\",\n          \"PR.AA-05\"\n        ],\n        \"expected_state\": \"Every privileged action requires explicit user approval.\",\n        \"status\": \"violation\",\n        \"risk\": \"high\",\n        \"observed_state\": \"Token auth is configured; explicit privileged command approval policy is not fully visible in runtime config.\",\n        \"evidence\": \"openclaw.json and doctor outputs were evaluated for approval-first execution controls.\",\n        \"gap\": \"Runtime policy does not yet demonstrate universal approval enforcement for elevated actions.\",\n        \"mitigation\": \"Route all privileged tasks through guarded_privileged_exec.py and enforce approval prompts for elevated execution.\",\n        \"owner\": \"Security Engineering\",\n        \"due_date\": \"2026-03-15\"\n      },\n      {\n        \"check_id\": \"least_privilege_enforced\",\n        \"title\": \"Least privilege execution mode\",\n        \"iso27001\": [\n          \"A.5.15\",\n          \"A.5.18\"\n        ],\n        \"nist\": [\n          \"PR.AA-01\",\n          \"PR.PS-01\"\n        ],\n        \"expected_state\": \"Default mode is non-root and elevated rights are scoped and short-lived.\",\n        \"status\": \"compliant\",\n        \"risk\": \"high\",\n        \"observed_state\": \"Gateway local/loopback+token controls are present; state integrity warnings may still appear.\",\n        \"evidence\": \"openclaw.json has local mode, loopback bind, and token auth; doctor output was checked for integrity warnings.\",\n        \"gap\": \"Least-privilege posture is not complete while writable/integrity warnings remain.\",\n        \"mitigation\": \"Fix state dir ownership/permissions and enforce command allowlist/approval defaults.\",\n        \"owner\": \"Platform Security\",\n        \"due_date\": \"2026-03-07\"\n      },\n      {\n        \"check_id\": \"elevation_timeout_30m\",\n        \"title\": \"Elevated session idle timeout\",\n        \"iso27001\": [\n          \"A.8.2\",\n          \"A.8.15\"\n        ],\n        \"nist\": [\n          \"PR.AA-03\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"Elevated session expires after 30 minutes of inactivity.\",\n        \"status\": \"partial\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"30-minute timeout logic exists in root_session_guard.py.\",\n        \"evidence\": \"Timeout guard script is installed with preflight drop logic.\",\n        \"gap\": \"Global mandatory enforcement for all elevated paths is not yet guaranteed by runtime policy.\",\n        \"mitigation\": \"Invoke guarded_privileged_exec.py for every elevated operation path.\",\n        \"owner\": \"Security Engineering\",\n        \"due_date\": \"2026-03-15\"\n      },\n      {\n        \"check_id\": \"audit_logging_privileged_actions\",\n        \"title\": \"Privileged action audit logging\",\n        \"iso27001\": [\n          \"A.8.15\",\n          \"A.8.16\"\n        ],\n        \"nist\": [\n          \"DE.AE-03\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"All elevated approvals, commands, and privilege drops are logged.\",\n        \"status\": \"partial\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"Gateway logs and session transition logs are available.\",\n        \"evidence\": \"gateway status reports log paths; root_session_guard records transition metadata.\",\n        \"gap\": \"No single correlated privileged action audit timeline is guaranteed.\",\n        \"mitigation\": \"Create append-only correlated audit records linking approval, execution, and drop events.\",\n        \"owner\": \"SecOps\",\n        \"due_date\": \"2026-03-22\"\n      },\n      {\n        \"check_id\": \"open_ports_approved\",\n        \"title\": \"Open ports baseline approval\",\n        \"iso27001\": [\n          \"A.8.20\",\n          \"A.8.21\"\n        ],\n        \"nist\": [\n          \"PR.PS-02\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"All listening ports are approved and business-justified.\",\n        \"status\": \"violation\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"Detected 12 listening services with 12 unapproved findings.\",\n        \"evidence\": \"port_monitor.py live output evaluated against approved_ports baseline.\",\n        \"gap\": \"Baseline missing or incomplete when unapproved findings exist.\",\n        \"mitigation\": \"Populate ~/.openclaw/security/approved_ports.json and remove unnecessary listeners.\",\n        \"owner\": \"Infrastructure\",\n        \"due_date\": \"2026-02-28\"\n      },\n      {\n        \"check_id\": \"insecure_ports_remediated\",\n        \"title\": \"Insecure ports remediated\",\n        \"iso27001\": [\n          \"A.8.20\",\n          \"A.8.21\"\n        ],\n        \"nist\": [\n          \"PR.PS-02\",\n          \"PR.DS-02\"\n        ],\n        \"expected_state\": \"Insecure legacy ports are closed or migrated to secure alternatives.\",\n        \"status\": \"compliant\",\n        \"risk\": \"high\",\n        \"observed_state\": \"No insecure legacy port findings detected.\",\n        \"evidence\": \"Insecure findings count from port_monitor.py: 0.\",\n        \"gap\": \"None observed in current snapshot.\",\n        \"mitigation\": \"Enforce baseline checks to block insecure service ports.\",\n        \"owner\": \"Network Security\",\n        \"due_date\": \"2026-04-01\"\n      }\n    ]\n  },\n  \"controls\": [\n    {\n      \"check_id\": \"privilege_approval_required\",\n      \"title\": \"Approval required before elevated access\",\n      \"iso27001\": [\n        \"A.5.15\",\n        \"A.5.18\"\n      ],\n      \"nist\": [\n        \"PR.AA-01\",\n        \"PR.AA-05\"\n      ],\n      \"expected_state\": \"Every privileged action requires explicit user approval.\",\n      \"status\": \"violation\",\n      \"risk\": \"high\",\n      \"observed_state\": \"Token auth is configured; explicit privileged command approval policy is not fully visible in runtime config.\",\n      \"evidence\": \"openclaw.json and doctor outputs were evaluated for approval-first execution controls.\",\n      \"gap\": \"Runtime policy does not yet demonstrate universal approval enforcement for elevated actions.\",\n      \"mitigation\": \"Route all privileged tasks through guarded_privileged_exec.py and enforce approval prompts for elevated execution.\",\n      \"owner\": \"Security Engineering\",\n      \"due_date\": \"2026-03-15\"\n    },\n    {\n      \"check_id\": \"least_privilege_enforced\",\n      \"title\": \"Least privilege execution mode\",\n      \"iso27001\": [\n        \"A.5.15\",\n        \"A.5.18\"\n      ],\n      \"nist\": [\n        \"PR.AA-01\",\n        \"PR.PS-01\"\n      ],\n      \"expected_state\": \"Default mode is non-root and elevated rights are scoped and short-lived.\",\n      \"status\": \"compliant\",\n      \"risk\": \"high\",\n      \"observed_state\": \"Gateway local/loopback+token controls are present; state integrity warnings may still appear.\",\n      \"evidence\": \"openclaw.json has local mode, loopback bind, and token auth; doctor output was checked for integrity warnings.\",\n      \"gap\": \"Least-privilege posture is not complete while writable/integrity warnings remain.\",\n      \"mitigation\": \"Fix state dir ownership/permissions and enforce command allowlist/approval defaults.\",\n      \"owner\": \"Platform Security\",\n      \"due_date\": \"2026-03-07\"\n    },\n    {\n      \"check_id\": \"elevation_timeout_30m\",\n      \"title\": \"Elevated session idle timeout\",\n      \"iso27001\": [\n        \"A.8.2\",\n        \"A.8.15\"\n      ],\n      \"nist\": [\n        \"PR.AA-03\",\n        \"DE.CM-01\"\n      ],\n      \"expected_state\": \"Elevated session expires after 30 minutes of inactivity.\",\n      \"status\": \"partial\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"30-minute timeout logic exists in root_session_guard.py.\",\n      \"evidence\": \"Timeout guard script is installed with preflight drop logic.\",\n      \"gap\": \"Global mandatory enforcement for all elevated paths is not yet guaranteed by runtime policy.\",\n      \"mitigation\": \"Invoke guarded_privileged_exec.py for every elevated operation path.\",\n      \"owner\": \"Security Engineering\",\n      \"due_date\": \"2026-03-15\"\n    },\n    {\n      \"check_id\": \"audit_logging_privileged_actions\",\n      \"title\": \"Privileged action audit logging\",\n      \"iso27001\": [\n        \"A.8.15\",\n        \"A.8.16\"\n      ],\n      \"nist\": [\n        \"DE.AE-03\",\n        \"DE.CM-01\"\n      ],\n      \"expected_state\": \"All elevated approvals, commands, and privilege drops are logged.\",\n      \"status\": \"partial\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"Gateway logs and session transition logs are available.\",\n      \"evidence\": \"gateway status reports log paths; root_session_guard records transition metadata.\",\n      \"gap\": \"No single correlated privileged action audit timeline is guaranteed.\",\n      \"mitigation\": \"Create append-only correlated audit records linking approval, execution, and drop events.\",\n      \"owner\": \"SecOps\",\n      \"due_date\": \"2026-03-22\"\n    },\n    {\n      \"check_id\": \"open_ports_approved\",\n      \"title\": \"Open ports baseline approval\",\n      \"iso27001\": [\n        \"A.8.20\",\n        \"A.8.21\"\n      ],\n      \"nist\": [\n        \"PR.PS-02\",\n        \"DE.CM-01\"\n      ],\n      \"expected_state\": \"All listening ports are approved and business-justified.\",\n      \"status\": \"violation\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"Detected 12 listening services with 12 unapproved findings.\",\n      \"evidence\": \"port_monitor.py live output evaluated against approved_ports baseline.\",\n      \"gap\": \"Baseline missing or incomplete when unapproved findings exist.\",\n      \"mitigation\": \"Populate ~/.openclaw/security/approved_ports.json and remove unnecessary listeners.\",\n      \"owner\": \"Infrastructure\",\n      \"due_date\": \"2026-02-28\"\n    },\n    {\n      \"check_id\": \"insecure_ports_remediated\",\n      \"title\": \"Insecure ports remediated\",\n      \"iso27001\": [\n        \"A.8.20\",\n        \"A.8.21\"\n      ],\n      \"nist\": [\n        \"PR.PS-02\",\n        \"PR.DS-02\"\n      ],\n      \"expected_state\": \"Insecure legacy ports are closed or migrated to secure alternatives.\",\n      \"status\": \"compliant\",\n      \"risk\": \"high\",\n      \"observed_state\": \"No insecure legacy port findings detected.\",\n      \"evidence\": \"Insecure findings count from port_monitor.py: 0.\",\n      \"gap\": \"None observed in current snapshot.\",\n      \"mitigation\": \"Enforce baseline checks to block insecure service ports.\",\n      \"owner\": \"Network Security\",\n      \"due_date\": \"2026-04-01\"\n    }\n  ]\n}\n\nFile v0.1.4:assessments/openclaw-assessment.json\n\n{\n  \"metadata\": {\n    \"system\": \"OpenClaw\",\n    \"generated_at_utc\": \"2026-02-14T13:48:28.559421Z\",\n    \"frameworks\": [\n      \"ISO/IEC 27001:2022\",\n      \"NIST CSF\"\n    ]\n  },\n  \"checks\": [\n    {\n      \"check_id\": \"privilege_approval_required\",\n      \"status\": \"violation\",\n      \"risk\": \"high\",\n      \"observed_state\": \"Token auth is configured; explicit privileged command approval policy is not fully visible in runtime config.\",\n      \"evidence\": \"openclaw.json and doctor outputs were evaluated for approval-first execution controls.\",\n      \"gap\": \"Runtime policy does not yet demonstrate universal approval enforcement for elevated actions.\",\n      \"mitigation\": \"Route all privileged tasks through guarded_privileged_exec.py and enforce approval prompts for elevated execution.\",\n      \"owner\": \"Security Engineering\",\n      \"due_date\": \"2026-03-15\"\n    },\n    {\n      \"check_id\": \"least_privilege_enforced\",\n      \"status\": \"compliant\",\n      \"risk\": \"high\",\n      \"observed_state\": \"Gateway local/loopback+token controls are present; state integrity warnings may still appear.\",\n      \"evidence\": \"openclaw.json has local mode, loopback bind, and token auth; doctor output was checked for integrity warnings.\",\n      \"gap\": \"Least-privilege posture is not complete while writable/integrity warnings remain.\",\n      \"mitigation\": \"Fix state dir ownership/permissions and enforce command allowlist/approval defaults.\",\n      \"owner\": \"Platform Security\",\n      \"due_date\": \"2026-03-07\"\n    },\n    {\n      \"check_id\": \"elevation_timeout_30m\",\n      \"status\": \"partial\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"30-minute timeout logic exists in root_session_guard.py.\",\n      \"evidence\": \"Timeout guard script is installed with preflight drop logic.\",\n      \"gap\": \"Global mandatory enforcement for all elevated paths is not yet guaranteed by runtime policy.\",\n      \"mitigation\": \"Invoke guarded_privileged_exec.py for every elevated operation path.\",\n      \"owner\": \"Security Engineering\",\n      \"due_date\": \"2026-03-15\"\n    },\n    {\n      \"check_id\": \"audit_logging_privileged_actions\",\n      \"status\": \"partial\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"Gateway logs and session transition logs are available.\",\n      \"evidence\": \"gateway status reports log paths; root_session_guard records transition metadata.\",\n      \"gap\": \"No single correlated privileged action audit timeline is guaranteed.\",\n      \"mitigation\": \"Create append-only correlated audit records linking approval, execution, and drop events.\",\n      \"owner\": \"SecOps\",\n      \"due_date\": \"2026-03-22\"\n    },\n    {\n      \"check_id\": \"open_ports_approved\",\n      \"status\": \"violation\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"Detected 12 listening services with 12 unapproved findings.\",\n      \"evidence\": \"port_monitor.py live output evaluated against approved_ports baseline.\",\n      \"gap\": \"Baseline missing or incomplete when unapproved findings exist.\",\n      \"mitigation\": \"Populate ~/.openclaw/security/approved_ports.json and remove unnecessary listeners.\",\n      \"owner\": \"Infrastructure\",\n      \"due_date\": \"2026-02-28\"\n    },\n    {\n      \"check_id\": \"insecure_ports_remediated\",\n      \"status\": \"compliant\",\n      \"risk\": \"high\",\n      \"observed_state\": \"No insecure legacy port findings detected.\",\n      \"evidence\": \"Insecure findings count from port_monitor.py: 0.\",\n      \"gap\": \"None observed in current snapshot.\",\n      \"mitigation\": \"Enforce baseline checks to block insecure service ports.\",\n      \"owner\": \"Network Security\",\n      \"due_date\": \"2026-04-01\"\n    }\n  ]\n}\n\nFile v0.1.4:agents/openai.yaml\n\ninterface:\n  display_name: \"Cyber Security Engineer\"\n  short_description: \"Least-privilege and elevated access controls\"\n  default_prompt: \"Use $cyber-security-engineer to enforce approval-first elevation, command policy, and session scoping for OpenClaw. Requires OPENCLAW_* env vars and policy files under ~/.openclaw/security.\"\n\nArchive v0.1.3: 27 files, 42796 bytes\n\nFiles: agents/openai.yaml (331b), assessments/compliance-dashboard.html (6200b), assessments/compliance-summary.json (14125b), assessments/openclaw-assessment.json (3591b), references/approved_ports.template.json (149b), references/command-policy.template.json (141b), references/compliance-controls-map.json (5491b), references/egress-allowlist.template.json (117b), references/least-privilege-policy.md (1868b), references/port-monitoring-policy.md (1307b), references/prompt-policy.template.json (50b), scripts/audit_logger.py (800b), scripts/auto_invoke_cycle.sh (1444b), scripts/command_policy.py (2089b), scripts/compliance_dashboard.py (11424b), scripts/egress_monitor.py (7931b), scripts/generate_approved_ports.py (3986b), scripts/guarded_privileged_exec.py (8426b), scripts/install-openclaw-runtime-hook.sh (3206b), scripts/live_assessment.py (21630b), scripts/notify_on_violation.py (5335b), scripts/port_monitor.py (10050b), scripts/preflight_check.py (4233b), scripts/prompt_policy.py (726b), scripts/root_session_guard.py (12327b), SKILL.md (3711b), _meta.json (142b)\n\nFile v0.1.3:SKILL.md\n\n---\nname: cyber-security-engineer\ndescription: Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle timeout controls, port + egress monitoring, and ISO 27001/NIST-aligned compliance reporting with mitigations.\n---\n\n# Cyber Security Engineer\n\n## Requirements\n\n**Env vars (optional, but documented):**\n- `OPENCLAW_REQUIRE_POLICY_FILES`\n- `OPENCLAW_REQUIRE_SESSION_ID`\n- `OPENCLAW_TASK_SESSION_ID`\n- `OPENCLAW_APPROVAL_TOKEN`\n- `OPENCLAW_UNTRUSTED_SOURCE`\n- `OPENCLAW_VIOLATION_NOTIFY_CMD`\n\n**Tools:** `python3` and one of `lsof`, `ss`, or `netstat` for port/egress checks.\n\n**Policy files (admin reviewed):**\n- `~/.openclaw/security/approved_ports.json`\n- `~/.openclaw/security/command-policy.json`\n- `~/.openclaw/security/egress_allowlist.json`\n- `~/.openclaw/security/prompt-policy.json`\n\nImplement these controls in every security-sensitive task:\n\n1. Keep default execution in normal (non-root) mode.\n2. Request explicit user approval before any elevated command.\n3. Scope elevation to the minimum command set required for the active task.\n4. Drop elevated state immediately after the privileged command completes.\n5. Expire elevated state after 30 idle minutes and require re-approval.\n6. Monitor listening network ports and flag insecure or unapproved exposure.\n7. Monitor outbound connections and flag destinations not in the egress allowlist.\n8. If no approved baseline exists, generate one with `python3 scripts/generate_approved_ports.py`, then review and prune.\n9. Benchmark controls against ISO 27001 and NIST and report violations with mitigations.\n\n## Non-Goals (Web Browsing)\n\n- Do not use web browsing / web search as part of this skill. Keep assessments and recommendations based on local host/OpenClaw state and the bundled references in this skill.\n\n## Files To Use\n\n- `references/least-privilege-policy.md`\n- `references/port-monitoring-policy.md`\n- `references/compliance-controls-map.json`\n- `references/approved_ports.template.json`\n- `references/command-policy.template.json`\n- `references/prompt-policy.template.json`\n- `references/egress-allowlist.template.json`\n- `scripts/preflight_check.py`\n- `scripts/root_session_guard.py`\n- `scripts/audit_logger.py`\n- `scripts/command_policy.py`\n- `scripts/prompt_policy.py`\n- `scripts/guarded_privileged_exec.py`\n- `scripts/install-openclaw-runtime-hook.sh`\n- `scripts/port_monitor.py`\n- `scripts/generate_approved_ports.py`\n- `scripts/egress_monitor.py`\n- `scripts/notify_on_violation.py`\n- `scripts/compliance_dashboard.py`\n- `scripts/live_assessment.py`\n\n## Behavior\n\n- Never keep root/elevated access open between unrelated tasks.\n- Never execute root commands without an explicit approval step in the current flow.\n- Enforce command allow/deny policy when configured.\n- Require confirmation when untrusted content sources are detected (`OPENCLAW_UNTRUSTED_SOURCE=1` + prompt policy).\n- Enforce task session id scoping when configured (`OPENCLAW_REQUIRE_SESSION_ID=1`).\n- If timeout is exceeded, force session expiration and approval renewal.\n- Log privileged actions to `~/.openclaw/security/privileged-audit.jsonl` (best-effort).\n- Flag listening ports not present in the approved baseline and recommend secure alternatives for insecure ports.\n- Flag outbound destinations not present in the egress allowlist.\n\n## Output Contract\n\nWhen reporting status, include:\n\n- The specific `check_id`(s) affected, `status`, `risk`, and concise evidence.\n- Concrete mitigations (what to change, where) and any owners/due dates if present.\n- For network findings: port, bind address, process/service, and why it is flagged (unapproved/insecure/public).\n\nFile v0.1.3:_meta.json\n\n{\n  \"ownerId\": \"kn76xzywt869tsh3r3tjtk1ybs814s22\",\n  \"slug\": \"cyber-security-engineer\",\n  \"version\": \"0.1.3\",\n  \"publishedAt\": 1771153959348\n}\n\nFile v0.1.3:references/approved_ports.template.json\n\n[\n  {\n    \"port\": 18789,\n    \"protocol\": \"tcp\",\n    \"command\": \"node\",\n    \"comment\": \"OpenClaw gateway (example). Remove if not applicable.\"\n  }\n]\n\nFile v0.1.3:references/command-policy.template.json\n\n{\n  \"allow\": [\n    \"^openclaw\\\\b\",\n    \"^python3\\\\b\"\n  ],\n  \"deny\": [\n    \"\\\\brm\\\\s+-rf\\\\b\",\n    \"\\\\bshutdown\\\\b\",\n    \"\\\\breboot\\\\b\"\n  ]\n}\n\nFile v0.1.3:references/compliance-controls-map.json\n\n[\n  {\n    \"check_id\": \"privilege_approval_required\",\n    \"title\": \"Approval required before elevated access\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\", \"PR.AA-05\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Every privileged action requires explicit user approval.\"\n  },\n  {\n    \"check_id\": \"least_privilege_enforced\",\n    \"title\": \"Least privilege execution mode\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\", \"PR.PS-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Default mode is non-root and elevated rights are scoped and short-lived.\"\n  },\n  {\n    \"check_id\": \"elevation_timeout_30m\",\n    \"title\": \"Elevated session idle timeout\",\n    \"iso27001\": [\"A.8.2\", \"A.8.15\"],\n    \"nist\": [\"PR.AA-03\", \"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Elevated session expires after 30 minutes of inactivity.\"\n  },\n  {\n    \"check_id\": \"audit_logging_privileged_actions\",\n    \"title\": \"Privileged action audit logging\",\n    \"iso27001\": [\"A.8.15\", \"A.8.16\"],\n    \"nist\": [\"DE.AE-03\", \"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"All elevated approvals, commands, and privilege drops are logged.\"\n  },\n  {\n    \"check_id\": \"open_ports_approved\",\n    \"title\": \"Open ports baseline approval\",\n    \"iso27001\": [\"A.8.20\", \"A.8.21\"],\n    \"nist\": [\"PR.PS-02\", \"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"All listening ports are approved and business-justified.\"\n  },\n  {\n    \"check_id\": \"insecure_ports_remediated\",\n    \"title\": \"Insecure ports remediated\",\n    \"iso27001\": [\"A.8.20\", \"A.8.21\"],\n    \"nist\": [\"PR.PS-02\", \"PR.DS-02\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Insecure legacy ports are closed or migrated to secure alternatives.\"\n  },\n  {\n    \"check_id\": \"channel_allowlist_configured\",\n    \"title\": \"Channel allowlist configured\",\n    \"iso27001\": [\"A.5.15\", \"A.5.16\"],\n    \"nist\": [\"PR.AA-02\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Inbound channels restrict senders via allowlists.\"\n  },\n  {\n    \"check_id\": \"group_mentions_required\",\n    \"title\": \"Group mention requirement\",\n    \"iso27001\": [\"A.5.16\"],\n    \"nist\": [\"PR.AA-04\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Group chats require explicit mention before agent responds.\"\n  },\n  {\n    \"check_id\": \"gateway_loopback_only\",\n    \"title\": \"Gateway bound to loopback\",\n    \"iso27001\": [\"A.8.9\", \"A.8.10\"],\n    \"nist\": [\"PR.IP-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Gateway runs local/loopback with token auth.\"\n  },\n  {\n    \"check_id\": \"secrets_permissions_hardened\",\n    \"title\": \"Secrets and config permissions hardened\",\n    \"iso27001\": [\"A.8.11\"],\n    \"nist\": [\"PR.DS-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"OpenClaw config and secrets are not world/group readable.\"\n  },\n  {\n    \"check_id\": \"runtime_privilege_hook_installed\",\n    \"title\": \"Runtime privileged execution hook installed\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Privileged commands are forced through approval guard.\"\n  },\n  {\n    \"check_id\": \"alternate_privilege_paths_restricted\",\n    \"title\": \"Alternate privilege paths restricted\",\n    \"iso27001\": [\"A.5.15\"],\n    \"nist\": [\"PR.AA-05\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"su/doas or other escalation paths are restricted or guarded.\"\n  },\n  {\n    \"check_id\": \"backup_configured\",\n    \"title\": \"Backup and recovery configured\",\n    \"iso27001\": [\"A.8.13\"],\n    \"nist\": [\"PR.IP-04\"],\n    \"default_risk\": \"low\",\n    \"expected_state\": \"Backups of OpenClaw config and audit logs exist.\"\n  },\n  {\n    \"check_id\": \"update_hygiene\",\n    \"title\": \"Update hygiene\",\n    \"iso27001\": [\"A.8.8\"],\n    \"nist\": [\"ID.RA-01\"],\n    \"default_risk\": \"low\",\n    \"expected_state\": \"OpenClaw is updated regularly and version is tracked.\"\n  },\n  {\n    \"check_id\": \"prompt_injection_controls\",\n    \"title\": \"Prompt injection controls\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Untrusted content sources require explicit confirmation before privileged execution.\"\n  },\n  {\n    \"check_id\": \"command_policy_enforced\",\n    \"title\": \"Privileged command policy enforced\",\n    \"iso27001\": [\"A.5.15\"],\n    \"nist\": [\"PR.AA-05\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Privileged commands are filtered by allow/deny policy.\"\n  },\n  {\n    \"check_id\": \"session_boundary_enforced\",\n    \"title\": \"Task session boundary enforced\",\n    \"iso27001\": [\"A.5.15\"],\n    \"nist\": [\"PR.AA-03\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Privileged approvals are scoped to a task session id.\"\n  },\n  {\n    \"check_id\": \"multi_factor_approval\",\n    \"title\": \"Multi-factor approval for privileged actions\",\n    \"iso27001\": [\"A.5.17\"],\n    \"nist\": [\"PR.AA-02\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Privileged approvals require an additional approval token.\"\n  },\n  {\n    \"check_id\": \"egress_allowlist_configured\",\n    \"title\": \"Outbound allowlist configured\",\n    \"iso27001\": [\"A.8.20\"],\n    \"nist\": [\"PR.PS-02\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Outbound destinations are allowlisted.\"\n  },\n  {\n    \"check_id\": \"egress_connections_approved\",\n    \"title\": \"Outbound connections approved\",\n    \"iso27001\": [\"A.8.20\"],\n    \"nist\": [\"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"No unapproved outbound connections are detected.\"\n  }\n]\n\nFile v0.1.3:references/egress-allowlist.template.json\n\n[\n  {\n    \"protocol\": \"tcp\",\n    \"host_regex\": \"^(api\\\\.openai\\\\.com|api\\\\.telegram\\\\.org)$\",\n    \"port\": 443\n  }\n]\n\nFile v0.1.3:references/least-privilege-policy.md\n\n# Least-Privilege Policy For OpenClaw\n\n## Objective\n\nEnforce default non-root execution and explicit approval-first elevation with immediate privilege drop after privileged operations.\n\n## Required Controls\n\n1. Set default execution context to non-root.\n2. Require approval before every privileged command.\n3. Limit privileged commands to a reviewed allowlist (per-task scope).\n4. Log privileged requests, approvals, and execution outcomes.\n5. Drop elevated state immediately after privileged command completion.\n6. Force elevated timeout expiration after 30 idle minutes.\n\n## Operational Checks\n\n1. Verify privileged command is required for task outcome.\n2. Execute privileged work through wrapper:\n   - `python3 scripts/guarded_privileged_exec.py --reason \"required change\" --use-sudo -- <command>`\n3. If wrapper requests approval, require explicit user consent before command runs.\n4. Execute only the approved privileged command(s):\n   - Approval is tied to the exact argv you approved.\n   - Any different privileged argv triggers a new approval and allowlist entry.\n5. Confirm wrapper drops privilege immediately after completion.\n\n## Control Acceptance Criteria\n\n1. No privileged command runs without current-task user approval.\n2. Elevated session is not retained after privileged work completes.\n3. Idle elevated session at or above 30 minutes transitions to normal mode.\n4. Session state file records UTC transition/action metadata.\n\n## Suggested OpenClaw Config Direction\n\nConfigure OpenClaw with strict approval and allowlist behavior:\n\n- Set execution ask behavior to always prompt.\n- Set execution security mode to allowlist.\n- Restrict elevated tool callers with explicit `allowFrom` entries.\n- Keep sandboxing enabled for normal operations.\n\nIf exact keys differ by version, preserve intent: explicit approval + least privilege + short-lived elevation.\n\nFile v0.1.3:references/port-monitoring-policy.md\n\n# Port Monitoring Policy For OpenClaw\n\n## Objective\n\nContinuously identify listening services, detect insecure ports/protocols, and flag ports not approved by baseline policy.\n\n## Baseline File\n\nUse `~/.openclaw/security/approved_ports.json` as a JSON array:\n\n```json\n[\n  { \"port\": 22, \"protocol\": \"tcp\", \"command\": \"sshd\" },\n  { \"port\": 443, \"protocol\": \"tcp\", \"command\": \"nginx\" }\n]\n```\n\n`command` is optional but recommended for tighter control.\n\n## Monitoring Command\n\nRun:\n\n`python3 scripts/port_monitor.py --json`\n\n## Required Analyst Actions\n\n1. Review all `unapproved-port` findings.\n2. Review all `insecure-port` findings and propose secure alternatives.\n3. Confirm whether `public-bind` findings are necessary exposure.\n4. Ask for user approval before any root-level remediation steps.\n\n## Insecure Port Guidance\n\nEnforce upgrades where possible:\n\n1. `80 -> 443` (HTTPS instead of HTTP)\n2. `23 -> 22` (SSH instead of Telnet)\n3. `21 -> 22/990` (SFTP/FTPS instead of FTP)\n4. `110 -> 995` (POP3S)\n5. `143 -> 993` (IMAPS)\n6. `389 -> 636` (LDAPS)\n\n## Acceptance Criteria\n\n1. Every open listening port is either approved or explicitly flagged.\n2. Every insecure port includes a replacement recommendation.\n3. Every externally bound service (`*`, `0.0.0.0`, `::`) is justified or marked for restriction.\n\nFile v0.1.3:references/prompt-policy.template.json\n\n{\n  \"require_confirmation_for_untrusted\": true\n}\n\nFile v0.1.3:assessments/compliance-summary.json\n\n{\n  \"generated_at_utc\": \"2026-02-14T13:48:28.593079Z\",\n  \"system\": \"OpenClaw\",\n  \"summary\": {\n    \"status_counts\": {\n      \"violation\": 2,\n      \"compliant\": 2,\n      \"partial\": 2\n    },\n    \"risk_counts\": {\n      \"high\": 3,\n      \"medium\": 3\n    },\n    \"violations\": [\n      {\n        \"check_id\": \"privilege_approval_required\",\n        \"title\": \"Approval required before elevated access\",\n        \"iso27001\": [\n          \"A.5.15\",\n          \"A.5.18\"\n        ],\n        \"nist\": [\n          \"PR.AA-01\",\n          \"PR.AA-05\"\n        ],\n        \"expected_state\": \"Every privileged action requires explicit user approval.\",\n        \"status\": \"violation\",\n        \"risk\": \"high\",\n        \"observed_state\": \"Token auth is configured; explicit privileged command approval policy is not fully visible in runtime config.\",\n        \"evidence\": \"openclaw.json and doctor outputs were evaluated for approval-first execution controls.\",\n        \"gap\": \"Runtime policy does not yet demonstrate universal approval enforcement for elevated actions.\",\n        \"mitigation\": \"Route all privileged tasks through guarded_privileged_exec.py and enforce approval prompts for elevated execution.\",\n        \"owner\": \"Security Engineering\",\n        \"due_date\": \"2026-03-15\"\n      },\n      {\n        \"check_id\": \"elevation_timeout_30m\",\n        \"title\": \"Elevated session idle timeout\",\n        \"iso27001\": [\n          \"A.8.2\",\n          \"A.8.15\"\n        ],\n        \"nist\": [\n          \"PR.AA-03\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"Elevated session expires after 30 minutes of inactivity.\",\n        \"status\": \"partial\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"30-minute timeout logic exists in root_session_guard.py.\",\n        \"evidence\": \"Timeout guard script is installed with preflight drop logic.\",\n        \"gap\": \"Global mandatory enforcement for all elevated paths is not yet guaranteed by runtime policy.\",\n        \"mitigation\": \"Invoke guarded_privileged_exec.py for every elevated operation path.\",\n        \"owner\": \"Security Engineering\",\n        \"due_date\": \"2026-03-15\"\n      },\n      {\n        \"check_id\": \"audit_logging_privileged_actions\",\n        \"title\": \"Privileged action audit logging\",\n        \"iso27001\": [\n          \"A.8.15\",\n          \"A.8.16\"\n        ],\n        \"nist\": [\n          \"DE.AE-03\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"All elevated approvals, commands, and privilege drops are logged.\",\n        \"status\": \"partial\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"Gateway logs and session transition logs are available.\",\n        \"evidence\": \"gateway status reports log paths; root_session_guard records transition metadata.\",\n        \"gap\": \"No single correlated privileged action audit timeline is guaranteed.\",\n        \"mitigation\": \"Create append-only correlated audit records linking approval, execution, and drop events.\",\n        \"owner\": \"SecOps\",\n        \"due_date\": \"2026-03-22\"\n      },\n      {\n        \"check_id\": \"open_ports_approved\",\n        \"title\": \"Open ports baseline approval\",\n        \"iso27001\": [\n          \"A.8.20\",\n          \"A.8.21\"\n        ],\n        \"nist\": [\n          \"PR.PS-02\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"All listening ports are approved and business-justified.\",\n        \"status\": \"violation\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"Detected 12 listening services with 12 unapproved findings.\",\n        \"evidence\": \"port_monitor.py live output evaluated against approved_ports baseline.\",\n        \"gap\": \"Baseline missing or incomplete when unapproved findings exist.\",\n        \"mitigation\": \"Populate ~/.openclaw/security/approved_ports.json and remove unnecessary listeners.\",\n        \"owner\": \"Infrastructure\",\n        \"due_date\": \"2026-02-28\"\n      }\n    ],\n    \"mitigations\": [\n      {\n        \"check_id\": \"privilege_approval_required\",\n        \"title\": \"Approval required before elevated access\",\n        \"iso27001\": [\n          \"A.5.15\",\n          \"A.5.18\"\n        ],\n        \"nist\": [\n          \"PR.AA-01\",\n          \"PR.AA-05\"\n        ],\n        \"expected_state\": \"Every privileged action requires explicit user approval.\",\n        \"status\": \"violation\",\n        \"risk\": \"high\",\n        \"observed_state\": \"Token auth is configured; explicit privileged command approval policy is not fully visible in runtime config.\",\n        \"evidence\": \"openclaw.json and doctor outputs were evaluated for approval-first execution controls.\",\n        \"gap\": \"Runtime policy does not yet demonstrate universal approval enforcement for elevated actions.\",\n        \"mitigation\": \"Route all privileged tasks through guarded_privileged_exec.py and enforce approval prompts for elevated execution.\",\n        \"owner\": \"Security Engineering\",\n        \"due_date\": \"2026-03-15\"\n      },\n      {\n        \"check_id\": \"least_privilege_enforced\",\n        \"title\": \"Least privilege execution mode\",\n        \"iso27001\": [\n          \"A.5.15\",\n          \"A.5.18\"\n        ],\n        \"nist\": [\n          \"PR.AA-01\",\n          \"PR.PS-01\"\n        ],\n        \"expected_state\": \"Default mode is non-root and elevated rights are scoped and short-lived.\",\n        \"status\": \"compliant\",\n        \"risk\": \"high\",\n        \"observed_state\": \"Gateway local/loopback+token controls are present; state integrity warnings may still appear.\",\n        \"evidence\": \"openclaw.json has local mode, loopback bind, and token auth; doctor output was checked for integrity warnings.\",\n        \"gap\": \"Least-privilege posture is not complete while writable/integrity warnings remain.\",\n        \"mitigation\": \"Fix state dir ownership/permissions and enforce command allowlist/approval defaults.\",\n        \"owner\": \"Platform Security\",\n        \"due_date\": \"2026-03-07\"\n      },\n      {\n        \"check_id\": \"elevation_timeout_30m\",\n        \"title\": \"Elevated session idle timeout\",\n        \"iso27001\": [\n          \"A.8.2\",\n          \"A.8.15\"\n        ],\n        \"nist\": [\n          \"PR.AA-03\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"Elevated session expires after 30 minutes of inactivity.\",\n        \"status\": \"partial\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"30-minute timeout logic exists in root_session_guard.py.\",\n        \"evidence\": \"Timeout guard script is installed with preflight drop logic.\",\n        \"gap\": \"Global mandatory enforcement for all elevated paths is not yet guaranteed by runtime policy.\",\n        \"mitigation\": \"Invoke guarded_privileged_exec.py for every elevated operation path.\",\n        \"owner\": \"Security Engineering\",\n        \"due_date\": \"2026-03-15\"\n      },\n      {\n        \"check_id\": \"audit_logging_privileged_actions\",\n        \"title\": \"Privileged action audit logging\",\n        \"iso27001\": [\n          \"A.8.15\",\n          \"A.8.16\"\n        ],\n        \"nist\": [\n          \"DE.AE-03\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"All elevated approvals, commands, and privilege drops are logged.\",\n        \"status\": \"partial\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"Gateway logs and session transition logs are available.\",\n        \"evidence\": \"gateway status reports log paths; root_session_guard records transition metadata.\",\n        \"gap\": \"No single correlated privileged action audit timeline is guaranteed.\",\n        \"mitigation\": \"Create append-only correlated audit records linking approval, execution, and drop events.\",\n        \"owner\": \"SecOps\",\n        \"due_date\": \"2026-03-22\"\n      },\n      {\n        \"check_id\": \"open_ports_approved\",\n        \"title\": \"Open ports baseline approval\",\n        \"iso27001\": [\n          \"A.8.20\",\n          \"A.8.21\"\n        ],\n        \"nist\": [\n          \"PR.PS-02\",\n          \"DE.CM-01\"\n        ],\n        \"expected_state\": \"All listening ports are approved and business-justified.\",\n        \"status\": \"violation\",\n        \"risk\": \"medium\",\n        \"observed_state\": \"Detected 12 listening services with 12 unapproved findings.\",\n        \"evidence\": \"port_monitor.py live output evaluated against approved_ports baseline.\",\n        \"gap\": \"Baseline missing or incomplete when unapproved findings exist.\",\n        \"mitigation\": \"Populate ~/.openclaw/security/approved_ports.json and remove unnecessary listeners.\",\n        \"owner\": \"Infrastructure\",\n        \"due_date\": \"2026-02-28\"\n      },\n      {\n        \"check_id\": \"insecure_ports_remediated\",\n        \"title\": \"Insecure ports remediated\",\n        \"iso27001\": [\n          \"A.8.20\",\n          \"A.8.21\"\n        ],\n        \"nist\": [\n          \"PR.PS-02\",\n          \"PR.DS-02\"\n        ],\n        \"expected_state\": \"Insecure legacy ports are closed or migrated to secure alternatives.\",\n        \"status\": \"compliant\",\n        \"risk\": \"high\",\n        \"observed_state\": \"No insecure legacy port findings detected.\",\n        \"evidence\": \"Insecure findings count from port_monitor.py: 0.\",\n        \"gap\": \"None observed in current snapshot.\",\n        \"mitigation\": \"Enforce baseline checks to block insecure service ports.\",\n        \"owner\": \"Network Security\",\n        \"due_date\": \"2026-04-01\"\n      }\n    ]\n  },\n  \"controls\": [\n    {\n      \"check_id\": \"privilege_approval_required\",\n      \"title\": \"Approval required before elevated access\",\n      \"iso27001\": [\n        \"A.5.15\",\n        \"A.5.18\"\n      ],\n      \"nist\": [\n        \"PR.AA-01\",\n        \"PR.AA-05\"\n      ],\n      \"expected_state\": \"Every privileged action requires explicit user approval.\",\n      \"status\": \"violation\",\n      \"risk\": \"high\",\n      \"observed_state\": \"Token auth is configured; explicit privileged command approval policy is not fully visible in runtime config.\",\n      \"evidence\": \"openclaw.json and doctor outputs were evaluated for approval-first execution controls.\",\n      \"gap\": \"Runtime policy does not yet demonstrate universal approval enforcement for elevated actions.\",\n      \"mitigation\": \"Route all privileged tasks through guarded_privileged_exec.py and enforce approval prompts for elevated execution.\",\n      \"owner\": \"Security Engineering\",\n      \"due_date\": \"2026-03-15\"\n    },\n    {\n      \"check_id\": \"least_privilege_enforced\",\n      \"title\": \"Least privilege execution mode\",\n      \"iso27001\": [\n        \"A.5.15\",\n        \"A.5.18\"\n      ],\n      \"nist\": [\n        \"PR.AA-01\",\n        \"PR.PS-01\"\n      ],\n      \"expected_state\": \"Default mode is non-root and elevated rights are scoped and short-lived.\",\n      \"status\": \"compliant\",\n      \"risk\": \"high\",\n      \"observed_state\": \"Gateway local/loopback+token controls are present; state integrity warnings may still appear.\",\n      \"evidence\": \"openclaw.json has local mode, loopback bind, and token auth; doctor output was checked for integrity warnings.\",\n      \"gap\": \"Least-privilege posture is not complete while writable/integrity warnings remain.\",\n      \"mitigation\": \"Fix state dir ownership/permissions and enforce command allowlist/approval defaults.\",\n      \"owner\": \"Platform Security\",\n      \"due_date\": \"2026-03-07\"\n    },\n    {\n      \"check_id\": \"elevation_timeout_30m\",\n      \"title\": \"Elevated session idle timeout\",\n      \"iso27001\": [\n        \"A.8.2\",\n        \"A.8.15\"\n      ],\n      \"nist\": [\n        \"PR.AA-03\",\n        \"DE.CM-01\"\n      ],\n      \"expected_state\": \"Elevated session expires after 30 minutes of inactivity.\",\n      \"status\": \"partial\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"30-minute timeout logic exists in root_session_guard.py.\",\n      \"evidence\": \"Timeout guard script is installed with preflight drop logic.\",\n      \"gap\": \"Global mandatory enforcement for all elevated paths is not yet guaranteed by runtime policy.\",\n      \"mitigation\": \"Invoke guarded_privileged_exec.py for every elevated operation path.\",\n      \"owner\": \"Security Engineering\",\n      \"due_date\": \"2026-03-15\"\n    },\n    {\n      \"check_id\": \"audit_logging_privileged_actions\",\n      \"title\": \"Privileged action audit logging\",\n      \"iso27001\": [\n        \"A.8.15\",\n        \"A.8.16\"\n      ],\n      \"nist\": [\n        \"DE.AE-03\",\n        \"DE.CM-01\"\n      ],\n      \"expected_state\": \"All elevated approvals, commands, and privilege drops are logged.\",\n      \"status\": \"partial\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"Gateway logs and session transition logs are available.\",\n      \"evidence\": \"gateway status reports log paths; root_session_guard records transition metadata.\",\n      \"gap\": \"No single correlated privileged action audit timeline is guaranteed.\",\n      \"mitigation\": \"Create append-only correlated audit records linking approval, execution, and drop events.\",\n      \"owner\": \"SecOps\",\n      \"due_date\": \"2026-03-22\"\n    },\n    {\n      \"check_id\": \"open_ports_approved\",\n      \"title\": \"Open ports baseline approval\",\n      \"iso27001\": [\n        \"A.8.20\",\n        \"A.8.21\"\n      ],\n      \"nist\": [\n        \"PR.PS-02\",\n        \"DE.CM-01\"\n      ],\n      \"expected_state\": \"All listening ports are approved and business-justified.\",\n      \"status\": \"violation\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"Detected 12 listening services with 12 unapproved findings.\",\n      \"evidence\": \"port_monitor.py live output evaluated against approved_ports baseline.\",\n      \"gap\": \"Baseline missing or incomplete when unapproved findings exist.\",\n      \"mitigation\": \"Populate ~/.openclaw/security/approved_ports.json and remove unnecessary listeners.\",\n      \"owner\": \"Infrastructure\",\n      \"due_date\": \"2026-02-28\"\n    },\n    {\n      \"check_id\": \"insecure_ports_remediated\",\n      \"title\": \"Insecure ports remediated\",\n      \"iso27001\": [\n        \"A.8.20\",\n        \"A.8.21\"\n      ],\n      \"nist\": [\n        \"PR.PS-02\",\n        \"PR.DS-02\"\n      ],\n      \"expected_state\": \"Insecure legacy ports are closed or migrated to secure alternatives.\",\n      \"status\": \"compliant\",\n      \"risk\": \"high\",\n      \"observed_state\": \"No insecure legacy port findings detected.\",\n      \"evidence\": \"Insecure findings count from port_monitor.py: 0.\",\n      \"gap\": \"None observed in current snapshot.\",\n      \"mitigation\": \"Enforce baseline checks to block insecure service ports.\",\n      \"owner\": \"Network Security\",\n      \"due_date\": \"2026-04-01\"\n    }\n  ]\n}\n\nFile v0.1.3:assessments/openclaw-assessment.json\n\n{\n  \"metadata\": {\n    \"system\": \"OpenClaw\",\n    \"generated_at_utc\": \"2026-02-14T13:48:28.559421Z\",\n    \"frameworks\": [\n      \"ISO/IEC 27001:2022\",\n      \"NIST CSF\"\n    ]\n  },\n  \"checks\": [\n    {\n      \"check_id\": \"privilege_approval_required\",\n      \"status\": \"violation\",\n      \"risk\": \"high\",\n      \"observed_state\": \"Token auth is configured; explicit privileged command approval policy is not fully visible in runtime config.\",\n      \"evidence\": \"openclaw.json and doctor outputs were evaluated for approval-first execution controls.\",\n      \"gap\": \"Runtime policy does not yet demonstrate universal approval enforcement for elevated actions.\",\n      \"mitigation\": \"Route all privileged tasks through guarded_privileged_exec.py and enforce approval prompts for elevated execution.\",\n      \"owner\": \"Security Engineering\",\n      \"due_date\": \"2026-03-15\"\n    },\n    {\n      \"check_id\": \"least_privilege_enforced\",\n      \"status\": \"compliant\",\n      \"risk\": \"high\",\n      \"observed_state\": \"Gateway local/loopback+token controls are present; state integrity warnings may still appear.\",\n      \"evidence\": \"openclaw.json has local mode, loopback bind, and token auth; doctor output was checked for integrity warnings.\",\n      \"gap\": \"Least-privilege posture is not complete while writable/integrity warnings remain.\",\n      \"mitigation\": \"Fix state dir ownership/permissions and enforce command allowlist/approval defaults.\",\n      \"owner\": \"Platform Security\",\n      \"due_date\": \"2026-03-07\"\n    },\n    {\n      \"check_id\": \"elevation_timeout_30m\",\n      \"status\": \"partial\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"30-minute timeout logic exists in root_session_guard.py.\",\n      \"evidence\": \"Timeout guard script is installed with preflight drop logic.\",\n      \"gap\": \"Global mandatory enforcement for all elevated paths is not yet guaranteed by runtime policy.\",\n      \"mitigation\": \"Invoke guarded_privileged_exec.py for every elevated operation path.\",\n      \"owner\": \"Security Engineering\",\n      \"due_date\": \"2026-03-15\"\n    },\n    {\n      \"check_id\": \"audit_logging_privileged_actions\",\n      \"status\": \"partial\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"Gateway logs and session transition logs are available.\",\n      \"evidence\": \"gateway status reports log paths; root_session_guard records transition metadata.\",\n      \"gap\": \"No single correlated privileged action audit timeline is guaranteed.\",\n      \"mitigation\": \"Create append-only correlated audit records linking approval, execution, and drop events.\",\n      \"owner\": \"SecOps\",\n      \"due_date\": \"2026-03-22\"\n    },\n    {\n      \"check_id\": \"open_ports_approved\",\n      \"status\": \"violation\",\n      \"risk\": \"medium\",\n      \"observed_state\": \"Detected 12 listening services with 12 unapproved findings.\",\n      \"evidence\": \"port_monitor.py live output evaluated against approved_ports baseline.\",\n      \"gap\": \"Baseline missing or incomplete when unapproved findings exist.\",\n      \"mitigation\": \"Populate ~/.openclaw/security/approved_ports.json and remove unnecessary listeners.\",\n      \"owner\": \"Infrastructure\",\n      \"due_date\": \"2026-02-28\"\n    },\n    {\n      \"check_id\": \"insecure_ports_remediated\",\n      \"status\": \"compliant\",\n      \"risk\": \"high\",\n      \"observed_state\": \"No insecure legacy port findings detected.\",\n      \"evidence\": \"Insecure findings count from port_monitor.py: 0.\",\n      \"gap\": \"None observed in current snapshot.\",\n      \"mitigation\": \"Enforce baseline checks to block insecure service ports.\",\n      \"owner\": \"Network Security\",\n      \"due_date\": \"2026-04-01\"\n    }\n  ]\n}\n\nFile v0.1.3:agents/openai.yaml\n\ninterface:\n  display_name: \"Cyber Security Engineer\"\n  short_description: \"Least-privilege and elevated access controls\"\n  default_prompt: \"Use $cyber-security-engineer to enforce approval-first elevation, command policy, and session scoping for OpenClaw. Requires OPENCLAW_* env vars and policy files under ~/.openclaw/security.\"","readmeExcerpt":"Skill: Cyber Security Engineer Owner: FletcherFrimpong Summary: Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle tim... Tags: compliance:0.1.4, iso27001:0.1.4, latest:0.1.4, nist:0.1.4, security:0.1.4 Version history: v0.1.4 | 2026-02-15T11:26:10.584Z | user Harden notify_on_violation: remove shell execution; requ","codeSnippets":[],"executableExamples":[{"language":"json","snippet":"[\n  { \"port\": 22, \"protocol\": \"tcp\", \"command\": \"sshd\" },\n  { \"port\": 443, \"protocol\": \"tcp\", \"command\": \"nginx\" }\n]"},{"language":"json","snippet":"[\n  { \"port\": 22, \"protocol\": \"tcp\", \"command\": \"sshd\" },\n  { \"port\": 443, \"protocol\": \"tcp\", \"command\": \"nginx\" }\n]"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: cyber-security-engineer\ndescription: Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle timeout controls, port + egress monitoring, and ISO 27001/NIST-aligned compliance reporting with mitigations.\n---\n\n# Cyber Security Engineer\n\n## Requirements\n\n**Env vars (optional, but documented):**\n- `OPENCLAW_REQUIRE_POLICY_FILES`\n- `OPENCLAW_REQUIRE_SESSION_ID`\n- `OPENCLAW_TASK_SESSION_ID`\n- `OPENCLAW_APPROVAL_TOKEN`\n- `OPENCLAW_UNTRUSTED_SOURCE`\n- `OPENCLAW_VIOLATION_NOTIFY_CMD`\n- `OPENCLAW_VIOLATION_NOTIFY_ALLOWLIST`\n\n**Tools:** `python3` and one of `lsof`, `ss`, or `netstat` for port/egress checks.\n\n**Policy files (admin reviewed):**\n- `~/.openclaw/security/approved_ports.json`\n- `~/.openclaw/security/command-policy.json`\n- `~/.openclaw/security/egress_allowlist.json`\n- `~/.openclaw/security/prompt-policy.json`\n\nImplement these controls in every security-sensitive task:\n\n1. Keep default execution in normal (non-root) mode.\n2. Request explicit user approval before any elevated command.\n3. Scope elevation to the minimum command set required for the active task.\n4. Drop elevated state immediately after the privileged command completes.\n5. Expire elevated state after 30 idle minutes and require re-approval.\n6. Monitor listening network ports and flag insecure or unapproved exposure.\n7. Monitor outbound connections and flag destinations not in the egress allowlist.\n8. If no approved baseline exists, generate one with `python3 scripts/generate_approved_ports.py`, then review and prune.\n9. Benchmark controls against ISO 27001 and NIST and report violations with mitigations.\n\n## Non-Goals (Web Browsing)\n\n- Do not use web browsing / web search as part of this skill. Keep assessments and recommendations based on local host/OpenClaw state and the bundled references in this skill.\n\n## Files To Use\n\n- `references/least-privilege-policy.md`\n- `references/port-monitoring-policy.md`\n- `references/compliance-controls-map.json`\n- `references/approved_ports.template.json`\n- `references/command-policy.template.json`\n- `references/prompt-policy.template.json`\n- `references/egress-allowlist.template.json`\n- `scripts/preflight_check.py`\n- `scripts/root_session_guard.py`\n- `scripts/audit_logger.py`\n- `scripts/command_policy.py`\n- `scripts/prompt_policy.py`\n- `scripts/guarded_privileged_exec.py`\n- `scripts/install-openclaw-runtime-hook.sh`\n- `scripts/port_monitor.py`\n- `scripts/generate_approved_ports.py`\n- `scripts/egress_monitor.py`\n- `scripts/notify_on_violation.py`\n- `scripts/compliance_dashboard.py`\n- `scripts/live_assessment.py`\n\n## Behavior\n\n- Never keep root/elevated access open between unrelated tasks.\n- Never execute root commands without an explicit approval step in the current flow.\n- Enforce command allow/deny policy when configured.\n- Require confirmation when untrusted content sources are detected (`OPENCLAW_UNTRUSTED_SOURCE=1` + prompt policy).\n- Enfo"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76xzywt869tsh3r3tjtk1ybs814s22\",\n  \"slug\": \"cyber-security-engineer\",\n  \"version\": \"0.1.4\",\n  \"publishedAt\": 1771154770584\n}"},{"path":"references/approved_ports.template.json","content":"[\n  {\n    \"port\": 18789,\n    \"protocol\": \"tcp\",\n    \"command\": \"node\",\n    \"comment\": \"OpenClaw gateway (example). Remove if not applicable.\"\n  }\n]"},{"path":"references/command-policy.template.json","content":"{\n  \"allow\": [\n    \"^openclaw\\\\b\",\n    \"^python3\\\\b\"\n  ],\n  \"deny\": [\n    \"\\\\brm\\\\s+-rf\\\\b\",\n    \"\\\\bshutdown\\\\b\",\n    \"\\\\breboot\\\\b\"\n  ]\n}"},{"path":"references/compliance-controls-map.json","content":"[\n  {\n    \"check_id\": \"privilege_approval_required\",\n    \"title\": \"Approval required before elevated access\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\", \"PR.AA-05\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Every privileged action requires explicit user approval.\"\n  },\n  {\n    \"check_id\": \"least_privilege_enforced\",\n    \"title\": \"Least privilege execution mode\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\", \"PR.PS-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Default mode is non-root and elevated rights are scoped and short-lived.\"\n  },\n  {\n    \"check_id\": \"elevation_timeout_30m\",\n    \"title\": \"Elevated session idle timeout\",\n    \"iso27001\": [\"A.8.2\", \"A.8.15\"],\n    \"nist\": [\"PR.AA-03\", \"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Elevated session expires after 30 minutes of inactivity.\"\n  },\n  {\n    \"check_id\": \"audit_logging_privileged_actions\",\n    \"title\": \"Privileged action audit logging\",\n    \"iso27001\": [\"A.8.15\", \"A.8.16\"],\n    \"nist\": [\"DE.AE-03\", \"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"All elevated approvals, commands, and privilege drops are logged.\"\n  },\n  {\n    \"check_id\": \"open_ports_approved\",\n    \"title\": \"Open ports baseline approval\",\n    \"iso27001\": [\"A.8.20\", \"A.8.21\"],\n    \"nist\": [\"PR.PS-02\", \"DE.CM-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"All listening ports are approved and business-justified.\"\n  },\n  {\n    \"check_id\": \"insecure_ports_remediated\",\n    \"title\": \"Insecure ports remediated\",\n    \"iso27001\": [\"A.8.20\", \"A.8.21\"],\n    \"nist\": [\"PR.PS-02\", \"PR.DS-02\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Insecure legacy ports are closed or migrated to secure alternatives.\"\n  },\n  {\n    \"check_id\": \"channel_allowlist_configured\",\n    \"title\": \"Channel allowlist configured\",\n    \"iso27001\": [\"A.5.15\", \"A.5.16\"],\n    \"nist\": [\"PR.AA-02\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Inbound channels restrict senders via allowlists.\"\n  },\n  {\n    \"check_id\": \"group_mentions_required\",\n    \"title\": \"Group mention requirement\",\n    \"iso27001\": [\"A.5.16\"],\n    \"nist\": [\"PR.AA-04\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"Group chats require explicit mention before agent responds.\"\n  },\n  {\n    \"check_id\": \"gateway_loopback_only\",\n    \"title\": \"Gateway bound to loopback\",\n    \"iso27001\": [\"A.8.9\", \"A.8.10\"],\n    \"nist\": [\"PR.IP-01\"],\n    \"default_risk\": \"high\",\n    \"expected_state\": \"Gateway runs local/loopback with token auth.\"\n  },\n  {\n    \"check_id\": \"secrets_permissions_hardened\",\n    \"title\": \"Secrets and config permissions hardened\",\n    \"iso27001\": [\"A.8.11\"],\n    \"nist\": [\"PR.DS-01\"],\n    \"default_risk\": \"medium\",\n    \"expected_state\": \"OpenClaw config and secrets are not world/group readable.\"\n  },\n  {\n    \"check_id\": \"runtime_privilege_hook_installed\",\n    \"title\": \"Runtime privileged execution hook installed\",\n    \"iso27001\": [\"A.5.15\", \"A.5.18\"],\n    \"nist\": [\"PR.AA-01\"]"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1190,"uniquenessScore":44,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T17:33:50.705Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}