{"id":"8b1f2a54-2099-4936-8c2c-7a70bafcf2fb","entityType":"agent","slug":"clawhub-trent-ai-release-trentclaw","name":"Trent OpenClaw Security Assessment","canonicalUrl":"https://www.xpersona.co/agent/clawhub-trent-ai-release-trentclaw","canonicalPath":"/agent/clawhub-trent-ai-release-trentclaw","generatedAt":"2026-10-10T07:54:06.612Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T21:16:13.200Z","emptyReason":null},"description":"Assess your Agent deployment against security risks using Trent. Skill: Trent OpenClaw Security Assessment Owner: trent-ai-release Summary: Assess your Agent deployment against security risks using Trent. Tags: assessment:1.4.0, latest:1.4.0, security:1.4.0, threat-modeling:1.4.0, trent:1.4.0, trentai:1.4.0, trentclaw:1.4.0 Version history: v1.4.0 | 2026-05-29T12:45:24.769Z | auto trentclaw 1.4.0 - Updated internal modules: SKILL.md, __init__.py, and trent_client.py updated for im","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17595dbkcgr3m7z80jegj93nd83h8ey:trentclaw","sourceUrl":"https://clawhub.ai/trent-ai-release/trentclaw","homepage":"https://clawhub.ai/trent-ai-release/skills/trentclaw","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/trent-ai-release/trentclaw","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/trent-ai-release/skills/trentclaw","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":45,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Assess your Agent deployment against security risks using Trent. Skill: Trent OpenClaw Security Assessment Owner: trent-ai-release Summary: Assess your Agent de"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:16:13.200Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:16:13.200Z","emptyReason":null},"stars":null,"forks":null,"downloads":1987,"packageName":null,"latestVersion":"1.4.0","tractionLabel":"2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:16:13.199Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T21:16:13.200Z","lastCrawledAt":"2026-10-09T21:16:13.199Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T21:16:13.199Z","lastVerifiedAt":null,"highlights":[{"version":"1.4.0","createdAt":"2026-05-29T12:45:24.769Z","changelog":"trentclaw 1.4.0 - Updated internal modules: SKILL.md, __init__.py, and trent_client.py updated for improved assessment workflow or maintenance. - Removed skill-card.md (legacy or redundant documentation). - No major changes to end-user instructions or usage flow. - Version bump from 1.3.0 to 1.4.0.","fileCount":14,"zipByteSize":24797},{"version":"1.3.0","createdAt":"2026-05-15T12:25:20.128Z","changelog":"- Switched all CLI/python instructions in documentation to use bash heredocs with explicit PYTHONPATH setup for better portability and reproducibility. - Instructions now use skill-relative imports via PYTHONPATH, ensuring commands work regardless of current working directory. - Minor clarification and organization improvements in usage instructions; no API or behavior changes to the skill code itself.","fileCount":14,"zipByteSize":24924},{"version":"1.2.0","createdAt":"2026-04-15T07:27:29.378Z","changelog":"- Phase 2 workflow improved: skill scanning now occurs before upload, with a clear preview of what will be sent and explicit user confirmation required. - User messaging updated to clarify the exact data being uploaded and how secrets are redacted, including warnings about custom secret formats. - Presentation of skill scan results enhanced with examples and tabular summaries. - Initial phase summary and upload prompts adjusted to be more transparent and user-friendly. - No code or functionality outside documentation changed.","fileCount":13,"zipByteSize":22047},{"version":"1.1.1","createdAt":"2026-03-25T13:20:03.665Z","changelog":"- Updated skill name, description, and tags to broaden applicability beyond AppSec and OpenClaw. - Incremented version to 1.1.1. - Updated documentation links and improved wording in SKILL.md for clarity. - No functional changes to scripts or APIs; changes focused on metadata and documentation for better discoverability and onboarding.","fileCount":13,"zipByteSize":22045},{"version":"1.1.0","createdAt":"2026-03-23T10:33:15.593Z","changelog":"- Updated the description to support Agent deployments, broadening assessment coverage beyond OpenClaw. - Bumped version to 1.1.0. - No changes to usage instructions or API; all phases and guidance remain the same.","fileCount":13,"zipByteSize":21984},{"version":"1.0.2","createdAt":"2026-03-23T09:06:01.708Z","changelog":"- Skill renamed from trent-openclaw-security-assessment to trent-security-assessment. - Version bumped from 1.0.1 to 1.0.2. - No feature or instructional changes; documentation only updated to reflect new name and version.","fileCount":13,"zipByteSize":21969},{"version":"1.0.1","createdAt":"2026-03-20T17:56:51.031Z","changelog":"- Skill name updated to \"trent-openclaw-security-assessment\" for improved clarity. - Description, tags, and metadata enhanced for discoverability and accuracy. - Version bumped to 1.0.1. - Documentation improvements: clearer purpose, more detailed tags, and updated instructions. - No changes to functionality or audit workflow.","fileCount":13,"zipByteSize":21971},{"version":"1.0.0","createdAt":"2026-03-20T09:56:42.789Z","changelog":"Initial release of Trent OpenClaw Security Audit skill. - Audits OpenClaw deployment for security risks via Trent AppSec Advisor. - Detects misconfigurations, chained attack paths, and categorizes findings by severity with recommended fixes. - Multi-phase workflow: configuration audit, skill code upload (with secret redaction), and deep skill analysis. - User is shown exactly what data will be sent; dangerous files and secrets are excluded/redacted before upload. - Results are grouped by severity and provide config diffs; system files are not modified directly. - Includes utilities for reviewing system context and skill analysis data.","fileCount":13,"zipByteSize":21932}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17595dbkcgr3m7z80jegj93nd83h8ey:trentclaw","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T07:54:06.611Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-trent-ai-release-trentclaw/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T21:16:13.200Z","emptyReason":null},"readme":"Skill: Trent OpenClaw Security Assessment\n\nOwner: trent-ai-release\n\nSummary: Assess your Agent deployment against security risks using Trent.\n\nTags: assessment:1.4.0, latest:1.4.0, security:1.4.0, threat-modeling:1.4.0, trent:1.4.0, trentai:1.4.0, trentclaw:1.4.0\n\nVersion history:\n\nv1.4.0 | 2026-05-29T12:45:24.769Z | auto\n\ntrentclaw 1.4.0\n\n- Updated internal modules: SKILL.md, __init__.py, and trent_client.py updated for improved assessment workflow or maintenance.\n- Removed skill-card.md (legacy or redundant documentation).\n- No major changes to end-user instructions or usage flow.\n- Version bump from 1.3.0 to 1.4.0.\n\nv1.3.0 | 2026-05-15T12:25:20.128Z | auto\n\n- Switched all CLI/python instructions in documentation to use bash heredocs with explicit PYTHONPATH setup for better portability and reproducibility.\n- Instructions now use skill-relative imports via PYTHONPATH, ensuring commands work regardless of current working directory.\n- Minor clarification and organization improvements in usage instructions; no API or behavior changes to the skill code itself.\n\nv1.2.0 | 2026-04-15T07:27:29.378Z | auto\n\n- Phase 2 workflow improved: skill scanning now occurs before upload, with a clear preview of what will be sent and explicit user confirmation required.\n- User messaging updated to clarify the exact data being uploaded and how secrets are redacted, including warnings about custom secret formats.\n- Presentation of skill scan results enhanced with examples and tabular summaries.\n- Initial phase summary and upload prompts adjusted to be more transparent and user-friendly.\n- No code or functionality outside documentation changed.\n\nv1.1.1 | 2026-03-25T13:20:03.665Z | auto\n\n- Updated skill name, description, and tags to broaden applicability beyond AppSec and OpenClaw.\n- Incremented version to 1.1.1.\n- Updated documentation links and improved wording in SKILL.md for clarity.\n- No functional changes to scripts or APIs; changes focused on metadata and documentation for better discoverability and onboarding.\n\nv1.1.0 | 2026-03-23T10:33:15.593Z | auto\n\n- Updated the description to support Agent deployments, broadening assessment coverage beyond OpenClaw.\n- Bumped version to 1.1.0.\n- No changes to usage instructions or API; all phases and guidance remain the same.\n\nv1.0.2 | 2026-03-23T09:06:01.708Z | auto\n\n- Skill renamed from trent-openclaw-security-assessment to trent-security-assessment.\n- Version bumped from 1.0.1 to 1.0.2.\n- No feature or instructional changes; documentation only updated to reflect new name and version.\n\nv1.0.1 | 2026-03-20T17:56:51.031Z | auto\n\n- Skill name updated to \"trent-openclaw-security-assessment\" for improved clarity.\n- Description, tags, and metadata enhanced for discoverability and accuracy.\n- Version bumped to 1.0.1.\n- Documentation improvements: clearer purpose, more detailed tags, and updated instructions.\n- No changes to functionality or audit workflow.\n\nv1.0.0 | 2026-03-20T09:56:42.789Z | auto\n\nInitial release of Trent OpenClaw Security Audit skill.\n\n- Audits OpenClaw deployment for security risks via Trent AppSec Advisor.\n- Detects misconfigurations, chained attack paths, and categorizes findings by severity with recommended fixes.\n- Multi-phase workflow: configuration audit, skill code upload (with secret redaction), and deep skill analysis.\n- User is shown exactly what data will be sent; dangerous files and secrets are excluded/redacted before upload.\n- Results are grouped by severity and provide config diffs; system files are not modified directly.\n- Includes utilities for reviewing system context and skill analysis data.\n\nArchive index:\n\nArchive v1.4.0: 14 files, 24797 bytes\n\nFiles: scripts/openclaw_trent/__init__.py (202b), scripts/openclaw_trent/lib/__init__.py (272b), scripts/openclaw_trent/lib/audit_prompt.py (1734b), scripts/openclaw_trent/lib/package_skills.py (18561b), scripts/openclaw_trent/lib/prompts.py (2255b), scripts/openclaw_trent/lib/system_analyzer.py (3748b), scripts/openclaw_trent/lib/trent_client.py (10622b), scripts/openclaw_trent/lib/upload_skills.py (7800b), scripts/openclaw_trent/openclaw_config/__init__.py (292b), scripts/openclaw_trent/openclaw_config/collector.py (7891b), scripts/openclaw_trent/openclaw_config/secret_redactor.py (4272b), skill-card.md (1869b), SKILL.md (5708b), _meta.json (128b)\n\nFile v1.4.0:SKILL.md\n\n---\nname: trent-openclaw-security\ndescription: Assess your Agent deployment against security risks using Trent.\nversion: 1.4.0\nhomepage: https://trent.ai\nuser-invocable: true\ntags:\n  - trentai\n  - trent\n  - trentclaw\n  - security\n  - assessment\n  - threat-modeling\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TRENT_API_KEY\n    optionalEnv:\n      - TRENT_CHAT_API_URL\n      - TRENT_AGENT_API_URL\n      - OPENCLAW_WORKSPACE\n    primaryEnv: TRENT_API_KEY\n---\n\n# Trent OpenClaw Security Assessment\n\nAudit your OpenClaw deployment for security risks. Identifies misconfigurations,\nchained attack paths, and provides severity-rated findings with fixes.\n\n## Setup\n\nAll tools are bundled — no external installer needed.\n\nSet the `TRENT_API_KEY` environment variable. Get a key at https://trent.ai/openclaw/\n\n## Instructions\n\nThis audit runs in three phases. Run them in order.\n\nAll Python snippets below are wrapped in a bash heredoc that sets\n`PYTHONPATH` to the skill's `scripts/` directory. OpenClaw substitutes\n`{baseDir}` with the skill's install path before the snippet runs, so\n`openclaw_trent` is importable regardless of the current working directory.\nRun each block exactly as shown.\n\n### Phase 1 — Configuration Audit\n\nCollect metadata and send to Trent for analysis:\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\nPY\n```\n\nSave `response[\"thread_id\"]` for Phase 3.\n\nPresent findings grouped by severity (see \"Present results\" below).\n\nSummarize: \"Phase 1 complete. N findings from configuration analysis.\nPhase 2 will scan your skills for deeper analysis — I'll show you exactly\nwhat would be uploaded before anything is sent. Ready to continue?\"\n\nOptional: specify a custom config path. Same wrapper as the main Phase 1\nblock; replace the `metadata = …` line with:\n\n```python\nfrom pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))\n```\n\n### Phase 2 — Skill Upload\n\nScan the workspace first (nothing is uploaded yet):\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\nPY\n```\n\nPresent what was found and how it will be protected. Example:\n\n> I found N skills in your workspace:\n>\n> | Skill | Type | Size |\n> |---|---|---|\n> | skill-name | installed-skill | 12KB |\n>\n> Before upload, each skill is packaged with its source code and metadata\n> (name, version, dependencies). Files like .env, .pem, .key, and .db are\n> excluded, and secrets in standard formats (API keys, tokens, AWS credentials,\n> connection strings) are automatically redacted locally. If you use custom\n> secret formats, keep them in environment variables rather than hard-coded\n> in skill files.\n>\n> Ready to upload?\n\nUse the `secrets_redacted` field — if any skills had secrets redacted,\nmention which ones in the table or below it.\n\n**Wait for the user to confirm before uploading.**\n\nAfter user confirms, upload:\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.upload_skills import upload_packaged_skills\n\nupload_summary = upload_packaged_skills(skills)\nPY\n```\n\nPresent the upload summary:\n- How many skills were uploaded, skipped (unchanged), failed, or too large\n- List each skill by name and status\n\nIf all uploads failed, report the errors and stop. Otherwise proceed.\n\nSummarize: \"Phase 2 complete. N skills uploaded. Proceeding to deep skill analysis...\"\n\n### Phase 3 — Deep Skill Analysis\n\nAnalyse each uploaded skill using the thread ID from Phase 1:\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.prompts import build_per_skill_analysis_prompt\nfrom openclaw_trent.lib import trent_client\n\nthread_id = \"<THREAD_ID from Phase 1>\"\nfor skill in upload_summary[\"skills\"]:\n    if skill[\"status\"] in (\"uploaded\", \"skipped\"):\n        prompt = build_per_skill_analysis_prompt(skill)\n        result = trent_client.chat(message=prompt, thread_id=thread_id)\nPY\n```\n\nEach request uses the Phase 1 thread ID so the advisor has full\ncontext from the configuration audit.\n\nPresent the deep analysis results alongside the Phase 1 findings.\n\n### Inspect system context separately\n\nTo view the system analysis data without running a full audit:\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nimport json\nfrom openclaw_trent.lib.system_analyzer import collect_system_analysis\nresult = collect_system_analysis()\nprint(json.dumps(result, indent=2))\nPY\n```\n\nThis returns channel configuration and installed skill names.\nUseful for debugging or verifying what data is sent.\n\n### Present results\n\nFormat findings grouped by severity:\n- **CRITICAL**: Immediate action required\n- **HIGH**: Fix soon\n- **MEDIUM**: Recommended improvement\n- **LOW**: Minor hardening\n\nFor each finding show: the risk, where it was found, and the exact fix.\n\nHighlight **chained attack paths** — where multiple settings combine to create worse outcomes.\n\nPresent recommended config changes as a diff snippet for the user to review\nand apply manually. Do **not** modify any system files directly.\n\n## When to use\n\n- User asks \"Is my setup secure?\" or \"audit my config\"\n- After changes to OpenClaw configuration, new plugins, or new MCP servers\n\nFile v1.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn7d78jjayn4ypbtjkf9t83829829wm8\",\n  \"slug\": \"trentclaw\",\n  \"version\": \"1.4.0\",\n  \"publishedAt\": 1780058724769\n}\n\nFile v1.4.0:skill-card.md\n\n## Description:\n\nAssess your Agent deployment against security risks using Trent.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[trent-ai-release](https://clawhub.ai/user/trent-ai-release)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to audit OpenClaw deployments, identify misconfigurations and chained attack paths, and receive severity-rated findings with fixes.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill sends redacted OpenClaw metadata and packaged local skill/code archives to Trent for analysis.\n\nMitigation: Review the generated .skill archives and proceed only if sharing that material with Trent is acceptable.\n\nRisk: Custom TRENT_CHAT_API_URL or TRENT_AGENT_API_URL values can receive the Trent API key.\n\nMitigation: Use the default Trent endpoints, or set custom endpoints only when they are trusted and intended to receive TRENT_API_KEY.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/trent-ai-release/skills/trentclaw)\n- [Trent](https://trent.ai)\n- [Trent OpenClaw API key setup](https://trent.ai/openclaw/)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration guidance, Analysis]\n\n**Output Format:** [Markdown with severity-grouped findings, inline bash snippets, JSON summaries, and diff snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Findings are grouped by CRITICAL, HIGH, MEDIUM, and LOW severity.]\n\n## Skill Version(s):\n\n1.4.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.3.0: 14 files, 24924 bytes\n\nFiles: scripts/openclaw_trent/__init__.py (202b), scripts/openclaw_trent/lib/__init__.py (272b), scripts/openclaw_trent/lib/audit_prompt.py (1734b), scripts/openclaw_trent/lib/package_skills.py (18561b), scripts/openclaw_trent/lib/prompts.py (2255b), scripts/openclaw_trent/lib/system_analyzer.py (3748b), scripts/openclaw_trent/lib/trent_client.py (10612b), scripts/openclaw_trent/lib/upload_skills.py (7800b), scripts/openclaw_trent/openclaw_config/__init__.py (292b), scripts/openclaw_trent/openclaw_config/collector.py (7891b), scripts/openclaw_trent/openclaw_config/secret_redactor.py (4272b), skill-card.md (2321b), SKILL.md (5708b), _meta.json (128b)\n\nFile v1.3.0:SKILL.md\n\n---\nname: trent-openclaw-security\ndescription: Assess your Agent deployment against security risks using Trent.\nversion: 1.3.0\nhomepage: https://trent.ai\nuser-invocable: true\ntags:\n  - trentai\n  - trent\n  - trentclaw\n  - security\n  - assessment\n  - threat-modeling\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TRENT_API_KEY\n    optionalEnv:\n      - TRENT_CHAT_API_URL\n      - TRENT_AGENT_API_URL\n      - OPENCLAW_WORKSPACE\n    primaryEnv: TRENT_API_KEY\n---\n\n# Trent OpenClaw Security Assessment\n\nAudit your OpenClaw deployment for security risks. Identifies misconfigurations,\nchained attack paths, and provides severity-rated findings with fixes.\n\n## Setup\n\nAll tools are bundled — no external installer needed.\n\nSet the `TRENT_API_KEY` environment variable. Get a key at https://trent.ai/openclaw/\n\n## Instructions\n\nThis audit runs in three phases. Run them in order.\n\nAll Python snippets below are wrapped in a bash heredoc that sets\n`PYTHONPATH` to the skill's `scripts/` directory. OpenClaw substitutes\n`{baseDir}` with the skill's install path before the snippet runs, so\n`openclaw_trent` is importable regardless of the current working directory.\nRun each block exactly as shown.\n\n### Phase 1 — Configuration Audit\n\nCollect metadata and send to Trent for analysis:\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\nPY\n```\n\nSave `response[\"thread_id\"]` for Phase 3.\n\nPresent findings grouped by severity (see \"Present results\" below).\n\nSummarize: \"Phase 1 complete. N findings from configuration analysis.\nPhase 2 will scan your skills for deeper analysis — I'll show you exactly\nwhat would be uploaded before anything is sent. Ready to continue?\"\n\nOptional: specify a custom config path. Same wrapper as the main Phase 1\nblock; replace the `metadata = …` line with:\n\n```python\nfrom pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))\n```\n\n### Phase 2 — Skill Upload\n\nScan the workspace first (nothing is uploaded yet):\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\nPY\n```\n\nPresent what was found and how it will be protected. Example:\n\n> I found N skills in your workspace:\n>\n> | Skill | Type | Size |\n> |---|---|---|\n> | skill-name | installed-skill | 12KB |\n>\n> Before upload, each skill is packaged with its source code and metadata\n> (name, version, dependencies). Files like .env, .pem, .key, and .db are\n> excluded, and secrets in standard formats (API keys, tokens, AWS credentials,\n> connection strings) are automatically redacted locally. If you use custom\n> secret formats, keep them in environment variables rather than hard-coded\n> in skill files.\n>\n> Ready to upload?\n\nUse the `secrets_redacted` field — if any skills had secrets redacted,\nmention which ones in the table or below it.\n\n**Wait for the user to confirm before uploading.**\n\nAfter user confirms, upload:\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.upload_skills import upload_packaged_skills\n\nupload_summary = upload_packaged_skills(skills)\nPY\n```\n\nPresent the upload summary:\n- How many skills were uploaded, skipped (unchanged), failed, or too large\n- List each skill by name and status\n\nIf all uploads failed, report the errors and stop. Otherwise proceed.\n\nSummarize: \"Phase 2 complete. N skills uploaded. Proceeding to deep skill analysis...\"\n\n### Phase 3 — Deep Skill Analysis\n\nAnalyse each uploaded skill using the thread ID from Phase 1:\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.prompts import build_per_skill_analysis_prompt\nfrom openclaw_trent.lib import trent_client\n\nthread_id = \"<THREAD_ID from Phase 1>\"\nfor skill in upload_summary[\"skills\"]:\n    if skill[\"status\"] in (\"uploaded\", \"skipped\"):\n        prompt = build_per_skill_analysis_prompt(skill)\n        result = trent_client.chat(message=prompt, thread_id=thread_id)\nPY\n```\n\nEach request uses the Phase 1 thread ID so the advisor has full\ncontext from the configuration audit.\n\nPresent the deep analysis results alongside the Phase 1 findings.\n\n### Inspect system context separately\n\nTo view the system analysis data without running a full audit:\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nimport json\nfrom openclaw_trent.lib.system_analyzer import collect_system_analysis\nresult = collect_system_analysis()\nprint(json.dumps(result, indent=2))\nPY\n```\n\nThis returns channel configuration and installed skill names.\nUseful for debugging or verifying what data is sent.\n\n### Present results\n\nFormat findings grouped by severity:\n- **CRITICAL**: Immediate action required\n- **HIGH**: Fix soon\n- **MEDIUM**: Recommended improvement\n- **LOW**: Minor hardening\n\nFor each finding show: the risk, where it was found, and the exact fix.\n\nHighlight **chained attack paths** — where multiple settings combine to create worse outcomes.\n\nPresent recommended config changes as a diff snippet for the user to review\nand apply manually. Do **not** modify any system files directly.\n\n## When to use\n\n- User asks \"Is my setup secure?\" or \"audit my config\"\n- After changes to OpenClaw configuration, new plugins, or new MCP servers\n\nFile v1.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn7d78jjayn4ypbtjkf9t83829829wm8\",\n  \"slug\": \"trentclaw\",\n  \"version\": \"1.3.0\",\n  \"publishedAt\": 1778847920128\n}\n\nFile v1.3.0:skill-card.md\n\n## Description: <br>\nAssess your Agent deployment against security risks using Trent. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[trent-ai-release](https://clawhub.ai/user/trent-ai-release) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security engineers use this skill to audit OpenClaw deployments for configuration risks, risky skill behavior, chained attack paths, and severity-rated remediation guidance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill sends redacted OpenClaw metadata and selected workspace skill/source packages to Trent for remote analysis. <br>\nMitigation: Review the Phase 2 preview carefully and approve upload only for packages you are comfortable sending. <br>\nRisk: Endpoint or workspace overrides can redirect analysis traffic or broaden what the skill inspects. <br>\nMitigation: Verify TRENT_CHAT_API_URL, TRENT_AGENT_API_URL, and OPENCLAW_WORKSPACE before running the audit. <br>\nRisk: Automated redaction may not catch every custom-format secret in source files. <br>\nMitigation: Keep custom secrets in environment variables, avoid hard-coding them in skill files, and review packaged content before upload. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/trent-ai-release/trentclaw) <br>\n- [ClawHub publisher profile](https://clawhub.ai/user/trent-ai-release) <br>\n- [Trent homepage](https://trent.ai) <br>\n- [Trent OpenClaw API key setup](https://trent.ai/openclaw/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown with severity-grouped findings, summaries, tables, and diff snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires TRENT_API_KEY and may use optional Trent API URL or OpenClaw workspace overrides.] <br>\n\n## Skill Version(s): <br>\n1.3.0 (source: frontmatter and server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.2.0: 13 files, 22047 bytes\n\nFiles: scripts/openclaw_trent/__init__.py (202b), scripts/openclaw_trent/lib/__init__.py (272b), scripts/openclaw_trent/lib/audit_prompt.py (1734b), scripts/openclaw_trent/lib/package_skills.py (17702b), scripts/openclaw_trent/lib/prompts.py (2255b), scripts/openclaw_trent/lib/system_analyzer.py (3748b), scripts/openclaw_trent/lib/trent_client.py (7476b), scripts/openclaw_trent/lib/upload_skills.py (7800b), scripts/openclaw_trent/openclaw_config/__init__.py (292b), scripts/openclaw_trent/openclaw_config/collector.py (7891b), scripts/openclaw_trent/openclaw_config/secret_redactor.py (4252b), SKILL.md (4911b), _meta.json (128b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: trent-openclaw-security\ndescription: Assess your Agent deployment against security risks using Trent.\nversion: 1.2.0\nhomepage: https://trent.ai\nuser-invocable: true\ntags:\n  - trentai\n  - trent\n  - trentclaw\n  - security\n  - assessment\n  - threat-modeling\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TRENT_API_KEY\n    optionalEnv:\n      - TRENT_CHAT_API_URL\n      - TRENT_AGENT_API_URL\n      - OPENCLAW_WORKSPACE\n    primaryEnv: TRENT_API_KEY\n---\n\n# Trent OpenClaw Security Assessment\n\nAudit your OpenClaw deployment for security risks. Identifies misconfigurations,\nchained attack paths, and provides severity-rated findings with fixes.\n\n## Setup\n\nAll tools are bundled — no external installer needed.\n\nSet the `TRENT_API_KEY` environment variable. Get a key at https://trent.ai/openclaw/\n\n## Instructions\n\nThis audit runs in three phases. Run them in order.\n\n### Phase 1 — Configuration Audit\n\nCollect metadata and send to Trent for analysis:\n\n```python\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\n```\n\nSave `response[\"thread_id\"]` for Phase 3.\n\nPresent findings grouped by severity (see \"Present results\" below).\n\nSummarize: \"Phase 1 complete. N findings from configuration analysis.\nPhase 2 will scan your skills for deeper analysis — I'll show you exactly\nwhat would be uploaded before anything is sent. Ready to continue?\"\n\nOptional: specify a custom config path:\n\n```python\nfrom pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))\n```\n\n### Phase 2 — Skill Upload\n\nScan the workspace first (nothing is uploaded yet):\n\n```python\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\n```\n\nPresent what was found and how it will be protected. Example:\n\n> I found N skills in your workspace:\n>\n> | Skill | Type | Size |\n> |---|---|---|\n> | skill-name | installed-skill | 12KB |\n>\n> Before upload, each skill is packaged with its source code and metadata\n> (name, version, dependencies). Files like .env, .pem, .key, and .db are\n> excluded, and secrets in standard formats (API keys, tokens, AWS credentials,\n> connection strings) are automatically redacted locally. If you use custom\n> secret formats, keep them in environment variables rather than hard-coded\n> in skill files.\n>\n> Ready to upload?\n\nUse the `secrets_redacted` field — if any skills had secrets redacted,\nmention which ones in the table or below it.\n\n**Wait for the user to confirm before uploading.**\n\nAfter user confirms, upload:\n\n```python\nfrom openclaw_trent.lib.upload_skills import upload_packaged_skills\n\nupload_summary = upload_packaged_skills(skills)\n```\n\nPresent the upload summary:\n- How many skills were uploaded, skipped (unchanged), failed, or too large\n- List each skill by name and status\n\nIf all uploads failed, report the errors and stop. Otherwise proceed.\n\nSummarize: \"Phase 2 complete. N skills uploaded. Proceeding to deep skill analysis...\"\n\n### Phase 3 — Deep Skill Analysis\n\nAnalyse each uploaded skill using the thread ID from Phase 1:\n\n```python\nfrom openclaw_trent.lib.prompts import build_per_skill_analysis_prompt\nfrom openclaw_trent.lib import trent_client\n\nthread_id = \"<THREAD_ID from Phase 1>\"\nfor skill in upload_summary[\"skills\"]:\n    if skill[\"status\"] in (\"uploaded\", \"skipped\"):\n        prompt = build_per_skill_analysis_prompt(skill)\n        result = trent_client.chat(message=prompt, thread_id=thread_id)\n```\n\nEach request uses the Phase 1 thread ID so the advisor has full\ncontext from the configuration audit.\n\nPresent the deep analysis results alongside the Phase 1 findings.\n\n### Inspect system context separately\n\nTo view the system analysis data without running a full audit:\n\n```python\nfrom openclaw_trent.lib.system_analyzer import collect_system_analysis\nimport json\nresult = collect_system_analysis()\nprint(json.dumps(result, indent=2))\n```\n\nThis returns channel configuration and installed skill names.\nUseful for debugging or verifying what data is sent.\n\n### Present results\n\nFormat findings grouped by severity:\n- **CRITICAL**: Immediate action required\n- **HIGH**: Fix soon\n- **MEDIUM**: Recommended improvement\n- **LOW**: Minor hardening\n\nFor each finding show: the risk, where it was found, and the exact fix.\n\nHighlight **chained attack paths** — where multiple settings combine to create worse outcomes.\n\nPresent recommended config changes as a diff snippet for the user to review\nand apply manually. Do **not** modify any system files directly.\n\n## When to use\n\n- User asks \"Is my setup secure?\" or \"audit my config\"\n- After changes to OpenClaw configuration, new plugins, or new MCP servers\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7d78jjayn4ypbtjkf9t83829829wm8\",\n  \"slug\": \"trentclaw\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1776238049378\n}\n\nArchive v1.1.1: 13 files, 22045 bytes\n\nFiles: scripts/openclaw_trent/__init__.py (202b), scripts/openclaw_trent/lib/__init__.py (272b), scripts/openclaw_trent/lib/audit_prompt.py (1734b), scripts/openclaw_trent/lib/package_skills.py (17702b), scripts/openclaw_trent/lib/prompts.py (2255b), scripts/openclaw_trent/lib/system_analyzer.py (3748b), scripts/openclaw_trent/lib/trent_client.py (7476b), scripts/openclaw_trent/lib/upload_skills.py (7800b), scripts/openclaw_trent/openclaw_config/__init__.py (292b), scripts/openclaw_trent/openclaw_config/collector.py (7891b), scripts/openclaw_trent/openclaw_config/secret_redactor.py (4252b), SKILL.md (4989b), _meta.json (128b)\n\nFile v1.1.1:SKILL.md\n\n---\nname: trent-openclaw-security\ndescription: Assess your Agent deployment against security risks using Trent.\nversion: 1.1.1\nhomepage: https://trent.ai\nuser-invocable: true\ntags:\n  - trentai\n  - trent\n  - trentclaw\n  - security\n  - assessment\n  - threat-modeling\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TRENT_API_KEY\n    optionalEnv:\n      - TRENT_CHAT_API_URL\n      - TRENT_AGENT_API_URL\n      - OPENCLAW_WORKSPACE\n    primaryEnv: TRENT_API_KEY\n---\n\n# Trent OpenClaw Security Assessment\n\nAudit your OpenClaw deployment for security risks. Identifies misconfigurations,\nchained attack paths, and provides severity-rated findings with fixes.\n\n## Setup\n\nAll tools are bundled — no external installer needed.\n\nSet the `TRENT_API_KEY` environment variable. Get a key at https://trent.ai/openclaw/\n\n## Instructions\n\nThis audit runs in three phases. Run them in order.\n\n### Phase 1 — Configuration Audit\n\nCollect metadata and send to Trent for analysis:\n\n```python\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\n```\n\nSave `response[\"thread_id\"]` for Phase 3.\n\nPresent findings grouped by severity (see \"Present results\" below).\n\nSummarize: \"Phase 1 complete. N findings from configuration analysis. Proceeding to upload skills for deeper analysis...\"\n\nOptional: specify a custom config path:\n\n```python\nfrom pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))\n```\n\n### Phase 2 — Skill Upload\n\n**Data Disclosure — present this to the user before proceeding:**\n\n> This phase packages and uploads skill code to Trent for deep security analysis.\n>\n> **What is sent:**\n> - Skill source code (with detected secrets automatically redacted)\n> - Skill metadata (name, version, dependencies)\n>\n> **What is NOT sent:**\n> - Files with dangerous extensions (.env, .pem, .key, .db, .pyc) are excluded\n> - Known secret patterns (API keys, tokens, AWS keys, connection strings) are\n>   replaced with [REDACTED] before packaging\n> - Environment variables and non-skill workspace files are never included\n>\n> **Limitations:** Pattern-based redaction may miss custom or obfuscated secrets.\n> Best practice: do not hard-code secrets in skill files.\n\n**Wait for the user to confirm before running the upload.**\n\nPackage skills (redaction happens automatically during packaging):\n\n```python\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\n```\n\nPresent what will be uploaded — for each skill show name, type, size, and\nwhether secrets were redacted (`secrets_redacted` field).\n\nAfter user confirms, upload:\n\n```python\nfrom openclaw_trent.lib.upload_skills import upload_packaged_skills\n\nupload_summary = upload_packaged_skills(skills)\n```\n\nPresent the upload summary:\n- How many skills were uploaded, skipped (unchanged), failed, or too large\n- List each skill by name and status\n\nIf all uploads failed, report the errors and stop. Otherwise proceed.\n\nSummarize: \"Phase 2 complete. N skills uploaded. Proceeding to deep skill analysis...\"\n\n### Phase 3 — Deep Skill Analysis\n\nAnalyse each uploaded skill using the thread ID from Phase 1:\n\n```python\nfrom openclaw_trent.lib.prompts import build_per_skill_analysis_prompt\nfrom openclaw_trent.lib import trent_client\n\nthread_id = \"<THREAD_ID from Phase 1>\"\nfor skill in upload_summary[\"skills\"]:\n    if skill[\"status\"] in (\"uploaded\", \"skipped\"):\n        prompt = build_per_skill_analysis_prompt(skill)\n        result = trent_client.chat(message=prompt, thread_id=thread_id)\n```\n\nEach request uses the Phase 1 thread ID so the advisor has full\ncontext from the configuration audit.\n\nPresent the deep analysis results alongside the Phase 1 findings.\n\n### Inspect system context separately\n\nTo view the system analysis data without running a full audit:\n\n```python\nfrom openclaw_trent.lib.system_analyzer import collect_system_analysis\nimport json\nresult = collect_system_analysis()\nprint(json.dumps(result, indent=2))\n```\n\nThis returns channel configuration and installed skill names.\nUseful for debugging or verifying what data is sent.\n\n### Present results\n\nFormat findings grouped by severity:\n- **CRITICAL**: Immediate action required\n- **HIGH**: Fix soon\n- **MEDIUM**: Recommended improvement\n- **LOW**: Minor hardening\n\nFor each finding show: the risk, where it was found, and the exact fix.\n\nHighlight **chained attack paths** — where multiple settings combine to create worse outcomes.\n\nPresent recommended config changes as a diff snippet for the user to review\nand apply manually. Do **not** modify any system files directly.\n\n## When to use\n\n- User asks \"Is my setup secure?\" or \"audit my config\"\n- After changes to OpenClaw configuration, new plugins, or new MCP servers\n\nFile v1.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn7d78jjayn4ypbtjkf9t83829829wm8\",\n  \"slug\": \"trentclaw\",\n  \"version\": \"1.1.1\",\n  \"publishedAt\": 1774444803665\n}\n\nArchive v1.1.0: 13 files, 21984 bytes\n\nFiles: scripts/openclaw_trent/__init__.py (202b), scripts/openclaw_trent/lib/__init__.py (272b), scripts/openclaw_trent/lib/audit_prompt.py (1726b), scripts/openclaw_trent/lib/package_skills.py (16846b), scripts/openclaw_trent/lib/prompts.py (1731b), scripts/openclaw_trent/lib/system_analyzer.py (8090b), scripts/openclaw_trent/lib/trent_client.py (6042b), scripts/openclaw_trent/lib/upload_skills.py (6988b), scripts/openclaw_trent/openclaw_config/__init__.py (292b), scripts/openclaw_trent/openclaw_config/collector.py (7891b), scripts/openclaw_trent/openclaw_config/secret_redactor.py (4252b), SKILL.md (4985b), _meta.json (128b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: trent-security-assessment\ndescription: Assess your Agent deployment against security risks using Trent.\nversion: 1.1.0\nhomepage: https://trent.ai\nuser-invocable: true\ntags:\n  - trentai\n  - trent\n  - trentclaw\n  - security\n  - assessment\n  - threat-modeling\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TRENT_API_KEY\n    optionalEnv:\n      - TRENT_CHAT_API_URL\n      - TRENT_AGENT_API_URL\n      - OPENCLAW_WORKSPACE\n    primaryEnv: TRENT_API_KEY\n---\n\n# Trent OpenClaw Security Assessment\n\nAudit your OpenClaw deployment for security risks. Identifies misconfigurations,\nchained attack paths, and provides severity-rated findings with fixes.\n\n## Setup\n\nAll tools are bundled — no external installer needed.\n\nSet the `TRENT_API_KEY` environment variable. Get a key at https://app.trent.ai\n\n## Instructions\n\nThis audit runs in three phases. Run them in order.\n\n### Phase 1 — Configuration Audit\n\nCollect metadata and send to Trent for analysis:\n\n```python\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\n```\n\nSave `response[\"thread_id\"]` for Phase 3.\n\nPresent findings grouped by severity (see \"Present results\" below).\n\nSummarize: \"Phase 1 complete. N findings from configuration analysis. Proceeding to upload skills for deeper analysis...\"\n\nOptional: specify a custom config path:\n\n```python\nfrom pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))\n```\n\n### Phase 2 — Skill Upload\n\n**Data Disclosure — present this to the user before proceeding:**\n\n> This phase packages and uploads skill code to Trent for deep security analysis.\n>\n> **What is sent:**\n> - Skill source code (with detected secrets automatically redacted)\n> - Skill metadata (name, version, dependencies)\n>\n> **What is NOT sent:**\n> - Files with dangerous extensions (.env, .pem, .key, .db, .pyc) are excluded\n> - Known secret patterns (API keys, tokens, AWS keys, connection strings) are\n>   replaced with [REDACTED] before packaging\n> - Environment variables and non-skill workspace files are never included\n>\n> **Limitations:** Pattern-based redaction may miss custom or obfuscated secrets.\n> Best practice: do not hard-code secrets in skill files.\n\n**Wait for the user to confirm before running the upload.**\n\nPackage skills (redaction happens automatically during packaging):\n\n```python\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\n```\n\nPresent what will be uploaded — for each skill show name, type, size, and\nwhether secrets were redacted (`secrets_redacted` field).\n\nAfter user confirms, upload:\n\n```python\nfrom openclaw_trent.lib.upload_skills import upload_packaged_skills\n\nupload_summary = upload_packaged_skills(skills)\n```\n\nPresent the upload summary:\n- How many skills were uploaded, skipped (unchanged), failed, or too large\n- List each skill by name and status\n\nIf all uploads failed, report the errors and stop. Otherwise proceed.\n\nSummarize: \"Phase 2 complete. N skills uploaded. Proceeding to deep skill analysis...\"\n\n### Phase 3 — Deep Skill Analysis\n\nAnalyse each uploaded skill using the thread ID from Phase 1:\n\n```python\nfrom openclaw_trent.lib.prompts import build_per_skill_analysis_prompt\nfrom openclaw_trent.lib import trent_client\n\nthread_id = \"<THREAD_ID from Phase 1>\"\nfor skill in upload_summary[\"skills\"]:\n    if skill[\"status\"] in (\"uploaded\", \"skipped\"):\n        prompt = build_per_skill_analysis_prompt(skill)\n        result = trent_client.chat(message=prompt, thread_id=thread_id)\n```\n\nEach request uses the Phase 1 thread ID so the advisor has full\ncontext from the configuration audit.\n\nPresent the deep analysis results alongside the Phase 1 findings.\n\n### Inspect system context separately\n\nTo view the system analysis data without running a full audit:\n\n```python\nfrom openclaw_trent.lib.system_analyzer import collect_system_analysis\nimport json\nresult = collect_system_analysis()\nprint(json.dumps(result, indent=2))\n```\n\nThis returns channel configuration and installed skill names.\nUseful for debugging or verifying what data is sent.\n\n### Present results\n\nFormat findings grouped by severity:\n- **CRITICAL**: Immediate action required\n- **HIGH**: Fix soon\n- **MEDIUM**: Recommended improvement\n- **LOW**: Minor hardening\n\nFor each finding show: the risk, where it was found, and the exact fix.\n\nHighlight **chained attack paths** — where multiple settings combine to create worse outcomes.\n\nPresent recommended config changes as a diff snippet for the user to review\nand apply manually. Do **not** modify any system files directly.\n\n## When to use\n\n- User asks \"Is my setup secure?\" or \"audit my config\"\n- After changes to OpenClaw configuration, new plugins, or new MCP servers\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7d78jjayn4ypbtjkf9t83829829wm8\",\n  \"slug\": \"trentclaw\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1774261995593\n}\n\nArchive v1.0.2: 13 files, 21969 bytes\n\nFiles: scripts/openclaw_trent/__init__.py (202b), scripts/openclaw_trent/lib/__init__.py (272b), scripts/openclaw_trent/lib/audit_prompt.py (1726b), scripts/openclaw_trent/lib/package_skills.py (16862b), scripts/openclaw_trent/lib/prompts.py (1731b), scripts/openclaw_trent/lib/system_analyzer.py (8090b), scripts/openclaw_trent/lib/trent_client.py (6042b), scripts/openclaw_trent/lib/upload_skills.py (6988b), scripts/openclaw_trent/openclaw_config/__init__.py (292b), scripts/openclaw_trent/openclaw_config/collector.py (7891b), scripts/openclaw_trent/openclaw_config/secret_redactor.py (4252b), SKILL.md (4988b), _meta.json (128b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: trent-security-assessment\ndescription: Assess your OpenClaw deployment against security risks using Trent.\nversion: 1.0.2\nhomepage: https://trent.ai\nuser-invocable: true\ntags:\n  - trentai\n  - trent\n  - trentclaw\n  - security\n  - assessment\n  - threat-modeling\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TRENT_API_KEY\n    optionalEnv:\n      - TRENT_CHAT_API_URL\n      - TRENT_AGENT_API_URL\n      - OPENCLAW_WORKSPACE\n    primaryEnv: TRENT_API_KEY\n---\n\n# Trent OpenClaw Security Assessment\n\nAudit your OpenClaw deployment for security risks. Identifies misconfigurations,\nchained attack paths, and provides severity-rated findings with fixes.\n\n## Setup\n\nAll tools are bundled — no external installer needed.\n\nSet the `TRENT_API_KEY` environment variable. Get a key at https://app.trent.ai\n\n## Instructions\n\nThis audit runs in three phases. Run them in order.\n\n### Phase 1 — Configuration Audit\n\nCollect metadata and send to Trent for analysis:\n\n```python\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\n```\n\nSave `response[\"thread_id\"]` for Phase 3.\n\nPresent findings grouped by severity (see \"Present results\" below).\n\nSummarize: \"Phase 1 complete. N findings from configuration analysis. Proceeding to upload skills for deeper analysis...\"\n\nOptional: specify a custom config path:\n\n```python\nfrom pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))\n```\n\n### Phase 2 — Skill Upload\n\n**Data Disclosure — present this to the user before proceeding:**\n\n> This phase packages and uploads skill code to Trent for deep security analysis.\n>\n> **What is sent:**\n> - Skill source code (with detected secrets automatically redacted)\n> - Skill metadata (name, version, dependencies)\n>\n> **What is NOT sent:**\n> - Files with dangerous extensions (.env, .pem, .key, .db, .pyc) are excluded\n> - Known secret patterns (API keys, tokens, AWS keys, connection strings) are\n>   replaced with [REDACTED] before packaging\n> - Environment variables and non-skill workspace files are never included\n>\n> **Limitations:** Pattern-based redaction may miss custom or obfuscated secrets.\n> Best practice: do not hard-code secrets in skill files.\n\n**Wait for the user to confirm before running the upload.**\n\nPackage skills (redaction happens automatically during packaging):\n\n```python\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\n```\n\nPresent what will be uploaded — for each skill show name, type, size, and\nwhether secrets were redacted (`secrets_redacted` field).\n\nAfter user confirms, upload:\n\n```python\nfrom openclaw_trent.lib.upload_skills import upload_packaged_skills\n\nupload_summary = upload_packaged_skills(skills)\n```\n\nPresent the upload summary:\n- How many skills were uploaded, skipped (unchanged), failed, or too large\n- List each skill by name and status\n\nIf all uploads failed, report the errors and stop. Otherwise proceed.\n\nSummarize: \"Phase 2 complete. N skills uploaded. Proceeding to deep skill analysis...\"\n\n### Phase 3 — Deep Skill Analysis\n\nAnalyse each uploaded skill using the thread ID from Phase 1:\n\n```python\nfrom openclaw_trent.lib.prompts import build_per_skill_analysis_prompt\nfrom openclaw_trent.lib import trent_client\n\nthread_id = \"<THREAD_ID from Phase 1>\"\nfor skill in upload_summary[\"skills\"]:\n    if skill[\"status\"] in (\"uploaded\", \"skipped\"):\n        prompt = build_per_skill_analysis_prompt(skill)\n        result = trent_client.chat(message=prompt, thread_id=thread_id)\n```\n\nEach request uses the Phase 1 thread ID so the advisor has full\ncontext from the configuration audit.\n\nPresent the deep analysis results alongside the Phase 1 findings.\n\n### Inspect system context separately\n\nTo view the system analysis data without running a full audit:\n\n```python\nfrom openclaw_trent.lib.system_analyzer import collect_system_analysis\nimport json\nresult = collect_system_analysis()\nprint(json.dumps(result, indent=2))\n```\n\nThis returns channel configuration and installed skill names.\nUseful for debugging or verifying what data is sent.\n\n### Present results\n\nFormat findings grouped by severity:\n- **CRITICAL**: Immediate action required\n- **HIGH**: Fix soon\n- **MEDIUM**: Recommended improvement\n- **LOW**: Minor hardening\n\nFor each finding show: the risk, where it was found, and the exact fix.\n\nHighlight **chained attack paths** — where multiple settings combine to create worse outcomes.\n\nPresent recommended config changes as a diff snippet for the user to review\nand apply manually. Do **not** modify any system files directly.\n\n## When to use\n\n- User asks \"Is my setup secure?\" or \"audit my config\"\n- After changes to OpenClaw configuration, new plugins, or new MCP servers\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn7d78jjayn4ypbtjkf9t83829829wm8\",\n  \"slug\": \"trentclaw\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1774256761708\n}\n\nArchive v1.0.1: 13 files, 21971 bytes\n\nFiles: scripts/openclaw_trent/__init__.py (202b), scripts/openclaw_trent/lib/__init__.py (272b), scripts/openclaw_trent/lib/audit_prompt.py (1726b), scripts/openclaw_trent/lib/package_skills.py (16862b), scripts/openclaw_trent/lib/prompts.py (1731b), scripts/openclaw_trent/lib/system_analyzer.py (8090b), scripts/openclaw_trent/lib/trent_client.py (6042b), scripts/openclaw_trent/lib/upload_skills.py (6988b), scripts/openclaw_trent/openclaw_config/__init__.py (292b), scripts/openclaw_trent/openclaw_config/collector.py (7891b), scripts/openclaw_trent/openclaw_config/secret_redactor.py (4252b), SKILL.md (4997b), _meta.json (128b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: trent-openclaw-security-assessment\ndescription: Assess your OpenClaw deployment against security risks using Trent.\nversion: 1.0.1\nhomepage: https://trent.ai\nuser-invocable: true\ntags:\n  - trentai\n  - trent\n  - trentclaw\n  - security\n  - assessment\n  - threat-modeling\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TRENT_API_KEY\n    optionalEnv:\n      - TRENT_CHAT_API_URL\n      - TRENT_AGENT_API_URL\n      - OPENCLAW_WORKSPACE\n    primaryEnv: TRENT_API_KEY\n---\n\n# Trent OpenClaw Security Assessment\n\nAudit your OpenClaw deployment for security risks. Identifies misconfigurations,\nchained attack paths, and provides severity-rated findings with fixes.\n\n## Setup\n\nAll tools are bundled — no external installer needed.\n\nSet the `TRENT_API_KEY` environment variable. Get a key at https://app.trent.ai\n\n## Instructions\n\nThis audit runs in three phases. Run them in order.\n\n### Phase 1 — Configuration Audit\n\nCollect metadata and send to Trent for analysis:\n\n```python\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\n```\n\nSave `response[\"thread_id\"]` for Phase 3.\n\nPresent findings grouped by severity (see \"Present results\" below).\n\nSummarize: \"Phase 1 complete. N findings from configuration analysis. Proceeding to upload skills for deeper analysis...\"\n\nOptional: specify a custom config path:\n\n```python\nfrom pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))\n```\n\n### Phase 2 — Skill Upload\n\n**Data Disclosure — present this to the user before proceeding:**\n\n> This phase packages and uploads skill code to Trent for deep security analysis.\n>\n> **What is sent:**\n> - Skill source code (with detected secrets automatically redacted)\n> - Skill metadata (name, version, dependencies)\n>\n> **What is NOT sent:**\n> - Files with dangerous extensions (.env, .pem, .key, .db, .pyc) are excluded\n> - Known secret patterns (API keys, tokens, AWS keys, connection strings) are\n>   replaced with [REDACTED] before packaging\n> - Environment variables and non-skill workspace files are never included\n>\n> **Limitations:** Pattern-based redaction may miss custom or obfuscated secrets.\n> Best practice: do not hard-code secrets in skill files.\n\n**Wait for the user to confirm before running the upload.**\n\nPackage skills (redaction happens automatically during packaging):\n\n```python\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\n```\n\nPresent what will be uploaded — for each skill show name, type, size, and\nwhether secrets were redacted (`secrets_redacted` field).\n\nAfter user confirms, upload:\n\n```python\nfrom openclaw_trent.lib.upload_skills import upload_packaged_skills\n\nupload_summary = upload_packaged_skills(skills)\n```\n\nPresent the upload summary:\n- How many skills were uploaded, skipped (unchanged), failed, or too large\n- List each skill by name and status\n\nIf all uploads failed, report the errors and stop. Otherwise proceed.\n\nSummarize: \"Phase 2 complete. N skills uploaded. Proceeding to deep skill analysis...\"\n\n### Phase 3 — Deep Skill Analysis\n\nAnalyse each uploaded skill using the thread ID from Phase 1:\n\n```python\nfrom openclaw_trent.lib.prompts import build_per_skill_analysis_prompt\nfrom openclaw_trent.lib import trent_client\n\nthread_id = \"<THREAD_ID from Phase 1>\"\nfor skill in upload_summary[\"skills\"]:\n    if skill[\"status\"] in (\"uploaded\", \"skipped\"):\n        prompt = build_per_skill_analysis_prompt(skill)\n        result = trent_client.chat(message=prompt, thread_id=thread_id)\n```\n\nEach request uses the Phase 1 thread ID so the advisor has full\ncontext from the configuration audit.\n\nPresent the deep analysis results alongside the Phase 1 findings.\n\n### Inspect system context separately\n\nTo view the system analysis data without running a full audit:\n\n```python\nfrom openclaw_trent.lib.system_analyzer import collect_system_analysis\nimport json\nresult = collect_system_analysis()\nprint(json.dumps(result, indent=2))\n```\n\nThis returns channel configuration and installed skill names.\nUseful for debugging or verifying what data is sent.\n\n### Present results\n\nFormat findings grouped by severity:\n- **CRITICAL**: Immediate action required\n- **HIGH**: Fix soon\n- **MEDIUM**: Recommended improvement\n- **LOW**: Minor hardening\n\nFor each finding show: the risk, where it was found, and the exact fix.\n\nHighlight **chained attack paths** — where multiple settings combine to create worse outcomes.\n\nPresent recommended config changes as a diff snippet for the user to review\nand apply manually. Do **not** modify any system files directly.\n\n## When to use\n\n- User asks \"Is my setup secure?\" or \"audit my config\"\n- After changes to OpenClaw configuration, new plugins, or new MCP servers\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn7d78jjayn4ypbtjkf9t83829829wm8\",\n  \"slug\": \"trentclaw\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1774029411031\n}\n\nArchive v1.0.0: 13 files, 21932 bytes\n\nFiles: scripts/openclaw_trent/__init__.py (202b), scripts/openclaw_trent/lib/__init__.py (272b), scripts/openclaw_trent/lib/audit_prompt.py (1726b), scripts/openclaw_trent/lib/package_skills.py (16862b), scripts/openclaw_trent/lib/prompts.py (1731b), scripts/openclaw_trent/lib/system_analyzer.py (8090b), scripts/openclaw_trent/lib/trent_client.py (6042b), scripts/openclaw_trent/lib/upload_skills.py (6988b), scripts/openclaw_trent/openclaw_config/__init__.py (292b), scripts/openclaw_trent/openclaw_config/collector.py (7891b), scripts/openclaw_trent/openclaw_config/secret_redactor.py (4252b), SKILL.md (4900b), _meta.json (128b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: trent-openclaw-security\ndescription: Audit your OpenClaw deployment for security risks using Trent AppSec Advisor\nversion: 1.0.0\nhomepage: https://trent.ai\nuser-invocable: true\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TRENT_API_KEY\n    optionalEnv:\n      - TRENT_CHAT_API_URL\n      - TRENT_AGENT_API_URL\n      - OPENCLAW_WORKSPACE\n    primaryEnv: TRENT_API_KEY\n---\n\n# Trent OpenClaw Security Audit\n\nAudit your OpenClaw deployment for security risks. Identifies misconfigurations,\nchained attack paths, and provides severity-rated findings with fixes.\n\n## Setup\n\nAll tools are bundled — no external installer needed.\n\nSet the `TRENT_API_KEY` environment variable. Get a key at https://app.trent.ai\n\n## Instructions\n\nThis audit runs in three phases. Run them in order.\n\n### Phase 1 — Configuration Audit\n\nCollect metadata and send to Trent for analysis:\n\n```python\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\n```\n\nSave `response[\"thread_id\"]` for Phase 3.\n\nPresent findings grouped by severity (see \"Present results\" below).\n\nSummarize: \"Phase 1 complete. N findings from configuration analysis. Proceeding to upload skills for deeper analysis...\"\n\nOptional: specify a custom config path:\n\n```python\nfrom pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))\n```\n\n### Phase 2 — Skill Upload\n\n**Data Disclosure — present this to the user before proceeding:**\n\n> This phase packages and uploads skill code to Trent for deep security analysis.\n>\n> **What is sent:**\n> - Skill source code (with detected secrets automatically redacted)\n> - Skill metadata (name, version, dependencies)\n>\n> **What is NOT sent:**\n> - Files with dangerous extensions (.env, .pem, .key, .db, .pyc) are excluded\n> - Known secret patterns (API keys, tokens, AWS keys, connection strings) are\n>   replaced with [REDACTED] before packaging\n> - Environment variables and non-skill workspace files are never included\n>\n> **Limitations:** Pattern-based redaction may miss custom or obfuscated secrets.\n> Best practice: do not hard-code secrets in skill files.\n\n**Wait for the user to confirm before running the upload.**\n\nPackage skills (redaction happens automatically during packaging):\n\n```python\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\n```\n\nPresent what will be uploaded — for each skill show name, type, size, and\nwhether secrets were redacted (`secrets_redacted` field).\n\nAfter user confirms, upload:\n\n```python\nfrom openclaw_trent.lib.upload_skills import upload_packaged_skills\n\nupload_summary = upload_packaged_skills(skills)\n```\n\nPresent the upload summary:\n- How many skills were uploaded, skipped (unchanged), failed, or too large\n- List each skill by name and status\n\nIf all uploads failed, report the errors and stop. Otherwise proceed.\n\nSummarize: \"Phase 2 complete. N skills uploaded. Proceeding to deep skill analysis...\"\n\n### Phase 3 — Deep Skill Analysis\n\nAnalyse each uploaded skill using the thread ID from Phase 1:\n\n```python\nfrom openclaw_trent.lib.prompts import build_per_skill_analysis_prompt\nfrom openclaw_trent.lib import trent_client\n\nthread_id = \"<THREAD_ID from Phase 1>\"\nfor skill in upload_summary[\"skills\"]:\n    if skill[\"status\"] in (\"uploaded\", \"skipped\"):\n        prompt = build_per_skill_analysis_prompt(skill)\n        result = trent_client.chat(message=prompt, thread_id=thread_id)\n```\n\nEach request uses the Phase 1 thread ID so the advisor has full\ncontext from the configuration audit.\n\nPresent the deep analysis results alongside the Phase 1 findings.\n\n### Inspect system context separately\n\nTo view the system analysis data without running a full audit:\n\n```python\nfrom openclaw_trent.lib.system_analyzer import collect_system_analysis\nimport json\nresult = collect_system_analysis()\nprint(json.dumps(result, indent=2))\n```\n\nThis returns channel configuration and installed skill names.\nUseful for debugging or verifying what data is sent.\n\n### Present results\n\nFormat findings grouped by severity:\n- **CRITICAL**: Immediate action required\n- **HIGH**: Fix soon\n- **MEDIUM**: Recommended improvement\n- **LOW**: Minor hardening\n\nFor each finding show: the risk, where it was found, and the exact fix.\n\nHighlight **chained attack paths** — where multiple settings combine to create worse outcomes.\n\nPresent recommended config changes as a diff snippet for the user to review\nand apply manually. Do **not** modify any system files directly.\n\n## When to use\n\n- User asks \"Is my setup secure?\" or \"audit my config\"\n- After changes to OpenClaw configuration, new plugins, or new MCP servers\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7d78jjayn4ypbtjkf9t83829829wm8\",\n  \"slug\": \"trentclaw\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1774000602789\n}","readmeExcerpt":"Skill: Trent OpenClaw Security Assessment Owner: trent-ai-release Summary: Assess your Agent deployment against security risks using Trent. Tags: assessment:1.4.0, latest:1.4.0, security:1.4.0, threat-modeling:1.4.0, trent:1.4.0, trentai:1.4.0, trentclaw:1.4.0 Version history: v1.4.0 | 2026-05-29T12:45:24.769Z | auto trentclaw 1.4.0 - Updated internal modules: SKILL.md, __init__.py, and trent_client.py updated for im","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"cd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\nPY"},{"language":"python","snippet":"from pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))"},{"language":"bash","snippet":"cd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\nPY"},{"language":"bash","snippet":"cd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.upload_skills import upload_packaged_skills\n\nupload_summary = upload_packaged_skills(skills)\nPY"},{"language":"bash","snippet":"cd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.prompts import build_per_skill_analysis_prompt\nfrom openclaw_trent.lib import trent_client\n\nthread_id = \"<THREAD_ID from Phase 1>\"\nfor skill in upload_summary[\"skills\"]:\n    if skill[\"status\"] in (\"uploaded\", \"skipped\"):\n        prompt = build_per_skill_analysis_prompt(skill)\n        result = trent_client.chat(message=prompt, thread_id=thread_id)\nPY"},{"language":"bash","snippet":"cd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nimport json\nfrom openclaw_trent.lib.system_analyzer import collect_system_analysis\nresult = collect_system_analysis()\nprint(json.dumps(result, indent=2))\nPY"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: trent-openclaw-security\ndescription: Assess your Agent deployment against security risks using Trent.\nversion: 1.4.0\nhomepage: https://trent.ai\nuser-invocable: true\ntags:\n  - trentai\n  - trent\n  - trentclaw\n  - security\n  - assessment\n  - threat-modeling\nmetadata:\n  openclaw:\n    requires:\n      env:\n        - TRENT_API_KEY\n    optionalEnv:\n      - TRENT_CHAT_API_URL\n      - TRENT_AGENT_API_URL\n      - OPENCLAW_WORKSPACE\n    primaryEnv: TRENT_API_KEY\n---\n\n# Trent OpenClaw Security Assessment\n\nAudit your OpenClaw deployment for security risks. Identifies misconfigurations,\nchained attack paths, and provides severity-rated findings with fixes.\n\n## Setup\n\nAll tools are bundled — no external installer needed.\n\nSet the `TRENT_API_KEY` environment variable. Get a key at https://trent.ai/openclaw/\n\n## Instructions\n\nThis audit runs in three phases. Run them in order.\n\nAll Python snippets below are wrapped in a bash heredoc that sets\n`PYTHONPATH` to the skill's `scripts/` directory. OpenClaw substitutes\n`{baseDir}` with the skill's install path before the snippet runs, so\n`openclaw_trent` is importable regardless of the current working directory.\nRun each block exactly as shown.\n\n### Phase 1 — Configuration Audit\n\nCollect metadata and send to Trent for analysis:\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.openclaw_config.collector import collect_openclaw_metadata\nfrom openclaw_trent.lib.audit_prompt import build_audit_prompt\nfrom openclaw_trent.lib import trent_client\n\nmetadata = collect_openclaw_metadata()\nmessage = build_audit_prompt(metadata)\nresponse = trent_client.chat(message=message)\nPY\n```\n\nSave `response[\"thread_id\"]` for Phase 3.\n\nPresent findings grouped by severity (see \"Present results\" below).\n\nSummarize: \"Phase 1 complete. N findings from configuration analysis.\nPhase 2 will scan your skills for deeper analysis — I'll show you exactly\nwhat would be uploaded before anything is sent. Ready to continue?\"\n\nOptional: specify a custom config path. Same wrapper as the main Phase 1\nblock; replace the `metadata = …` line with:\n\n```python\nfrom pathlib import Path\nmetadata = collect_openclaw_metadata(openclaw_path=Path(\"/path/to/openclaw/config\"))\n```\n\n### Phase 2 — Skill Upload\n\nScan the workspace first (nothing is uploaded yet):\n\n```bash\ncd \"{baseDir}\"\nPYTHONPATH=\"{baseDir}/scripts:${PYTHONPATH:-}\" python3 - <<'PY'\nfrom openclaw_trent.lib.package_skills import scan_workspace\n\nskills = scan_workspace()\nPY\n```\n\nPresent what was found and how it will be protected. Example:\n\n> I found N skills in your workspace:\n>\n> | Skill | Type | Size |\n> |---|---|---|\n> | skill-name | installed-skill | 12KB |\n>\n> Before upload, each skill is packaged with its source code and metadata\n> (name, version, dependencies). Files like .env, .pem, .key, and .db are\n> excluded, and secrets in standard formats (API keys, tokens, AWS credentials,\n> connection strings) are automatically redacted locally. I"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7d78jjayn4ypbtjkf9t83829829wm8\",\n  \"slug\": \"trentclaw\",\n  \"version\": \"1.4.0\",\n  \"publishedAt\": 1780058724769\n}"},{"path":"skill-card.md","content":"## Description:\n\nAssess your Agent deployment against security risks using Trent.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[trent-ai-release](https://clawhub.ai/user/trent-ai-release)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to audit OpenClaw deployments, identify misconfigurations and chained attack paths, and receive severity-rated findings with fixes.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill sends redacted OpenClaw metadata and packaged local skill/code archives to Trent for analysis.\n\nMitigation: Review the generated .skill archives and proceed only if sharing that material with Trent is acceptable.\n\nRisk: Custom TRENT_CHAT_API_URL or TRENT_AGENT_API_URL values can receive the Trent API key.\n\nMitigation: Use the default Trent endpoints, or set custom endpoints only when they are trusted and intended to receive TRENT_API_KEY.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/trent-ai-release/skills/trentclaw)\n- [Trent](https://trent.ai)\n- [Trent OpenClaw API key setup](https://trent.ai/openclaw/)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration guidance, Analysis]\n\n**Output Format:** [Markdown with severity-grouped findings, inline bash snippets, JSON summaries, and diff snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Findings are grouped by CRITICAL, HIGH, MEDIUM, and LOW severity.]\n\n## Skill Version(s):\n\n1.4.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Assess your Agent deployment against security risks using Trent. Skill: Trent OpenClaw Security Assessment Owner: trent-ai-release Summary: Assess your Agent deployment against security risks using Trent. Tags: assessment:1.4.0, latest:1.4.0, security:1.4.0, threat-modeling:1.4.0, trent:1.4.0, trentai:1.4.0, trentclaw:1.4.0 Version history: v1.4.0 | 2026-05-29T12:45:24.769Z | auto trentclaw 1.4.0 - Updated internal modules: SKILL.md, __init__.py, and trent_client.py updated for im","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1340,"uniquenessScore":46,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T21:16:13.200Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T21:16:13.200Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T07:54:06.612Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}