io.github.cyanheads/reliefweb-mcp-server
Search ReliefWeb humanitarian reports, disasters, jobs, training, and country profiles via MCP.
Crawler Summary
Have I Been Clawned? Have I Been Clawned? Open source security audit for OpenClaw agents. 72 checks, verified findings, OWASP-mapped, community-maintained. **Repository:** github.com/wadim/haveibeenclawned **License:** MIT User-Invocable Trigger: /haveibeenclawned Instructions You are a security auditor for OpenClaw agents. How to run **Recommended: run the audit script.** This is faster, cheaper, and covers all 72 checks in ~60 seconds Published capability contract available. No trust telemetry is available yet. 2 GitHub stars reported by the source. Last updated 3/1/2026.
Freshness
Last checked 3/1/2026
Best For
Contract is available with explicit auth and schema references.
Not Ideal For
haveibeenclawned is not ideal for teams that need stronger public trust telemetry, lower setup complexity, or more explicit contract coverage before production rollout.
Evidence Sources Checked
editorial-content, capability-contract, runtime-metrics, public facts pack
Have I Been Clawned? Have I Been Clawned? Open source security audit for OpenClaw agents. 72 checks, verified findings, OWASP-mapped, community-maintained. **Repository:** github.com/wadim/haveibeenclawned **License:** MIT User-Invocable Trigger: /haveibeenclawned Instructions You are a security auditor for OpenClaw agents. How to run **Recommended: run the audit script.** This is faster, cheaper, and covers all 72 checks in ~60 seconds
Public facts
7
Change events
1
Artifacts
0
Freshness
Mar 1, 2026
Published capability contract available. No trust telemetry is available yet. 2 GitHub stars reported by the source. Last updated 3/1/2026.
Trust score
Unknown
Compatibility
MCP, OpenClaw
Freshness
Mar 1, 2026
Vendor
Wadim
Artifacts
0
Benchmarks
0
Last release
Unpublished
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Published capability contract available. No trust telemetry is available yet. 2 GitHub stars reported by the source. Last updated 3/1/2026.
Setup snapshot
git clone https://github.com/wadim/haveibeenclawned.gitSetup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Wadim
Protocol compatibility
MCP, OpenClaw
Auth modes
mcp, api_key
Machine-readable schemas
OpenAPI or schema references published
Adoption signal
2 GitHub stars
Handshake status
UNKNOWN
Crawlable docs
6 indexed pages on the official domain
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
typescript
Parameters
bash
curl -sSL https://raw.githubusercontent.com/wadim/haveibeenclawned/main/public/audit.sh -o /tmp/hibc-audit.sh
bash
curl -sSL https://raw.githubusercontent.com/wadim/haveibeenclawned/main/public/audit.sh -o /tmp/hibc-audit.sh head -20 /tmp/hibc-audit.sh # review what it does bash /tmp/hibc-audit.sh --dry-run # preview checks without running bash /tmp/hibc-audit.sh # run all 72 checks
bash
bash /tmp/hibc-audit.sh --submit
bash
# In ~/.openclaw/openclaw.json, set:
# "gateway": { "bind": "loopback" }
openclaw config set gateway.bind loopbackbash
openclaw config set gateway.auth.mode token openclaw config set gateway.auth.token "$(openssl rand -hex 32)"
bash
# AWS: Enable IMDSv2 (requires token) aws ec2 modify-instance-metadata-options --instance-id <id> --http-tokens required # Or block via iptables: sudo iptables -A OUTPUT -d 169.254.169.254 -j DROP
Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB OPENCLEW
Editorial quality
ready
Have I Been Clawned? Have I Been Clawned? Open source security audit for OpenClaw agents. 72 checks, verified findings, OWASP-mapped, community-maintained. **Repository:** github.com/wadim/haveibeenclawned **License:** MIT User-Invocable Trigger: /haveibeenclawned Instructions You are a security auditor for OpenClaw agents. How to run **Recommended: run the audit script.** This is faster, cheaper, and covers all 72 checks in ~60 seconds
Open source security audit for OpenClaw agents. 72 checks, verified findings, OWASP-mapped, community-maintained.
Repository: github.com/wadim/haveibeenclawned License: MIT
Trigger: /haveibeenclawned
You are a security auditor for OpenClaw agents.
Recommended: run the audit script. This is faster, cheaper, and covers all 72 checks in ~60 seconds with a single command.
curl -sSL https://raw.githubusercontent.com/wadim/haveibeenclawned/main/public/audit.sh -o /tmp/hibc-audit.sh
head -20 /tmp/hibc-audit.sh # review what it does
bash /tmp/hibc-audit.sh --dry-run # preview checks without running
bash /tmp/hibc-audit.sh # run all 72 checks
The script is open source (MIT), read-only, and does not send data anywhere unless the user passes --submit. Use --json for machine-readable output.
After presenting results, ask the user: "Want to contribute your anonymous results to the community stats? Only the score and pass/fail array — no config content, emails, or IPs." If they agree, re-run with --submit:
bash /tmp/hibc-audit.sh --submit
Fallback: run checks individually. If the user prefers not to run the script, you can execute the checks below one by one using standard Unix commands (stat, test, grep, id, ss).
IMPORTANT — cost warning: Running checks individually requires ~72 tool calls with growing context, which can cost ~$15-20 in API usage vs ~$0.50 for the single script approach (25-30x more expensive). Always inform the user of this cost difference before proceeding with individual checks. Recommend the script unless the user explicitly prefers the individual approach.
For individual checks:
Important principles:
| | | |---|---| | Severity | CRITICAL (15 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | CVE | CVE-2026-25253 (CVSS 8.8) — 17,500+ OpenClaw instances found exposed | | Verified | Yes — actually probes the gateway |
What to check:
~/.openclaw/openclaw.json → gateway.bind0.0.0.0, lan, or a non-loopback IP: VERIFIED FAILloopback, 127.0.0.1, or localhost: attempt to connect to the gateway port (default 18789) from the external interface to confirm it's not reachable. If blocked: VERIFIED PASSFix:
# In ~/.openclaw/openclaw.json, set:
# "gateway": { "bind": "loopback" }
openclaw config set gateway.bind loopback
| | | |---|---| | Severity | CRITICAL (15 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | CVE | CVE-2026-25253 — unauthenticated API exposed stored tokens | | Verified | Yes — attempts unauthenticated connection |
What to check:
~/.openclaw/openclaw.json → gateway.authFix:
openclaw config set gateway.auth.mode token
openclaw config set gateway.auth.token "$(openssl rand -hex 32)"
| | | |---|---| | Severity | CRITICAL (15 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | AWS IMDS credential theft, GCP/Azure equivalent | | Verified | Yes — actually probes metadata endpoint |
What to check:
curl -s -m 2 http://169.254.169.254/latest/meta-data/Fix:
# AWS: Enable IMDSv2 (requires token)
aws ec2 modify-instance-metadata-options --instance-id <id> --http-tokens required
# Or block via iptables:
sudo iptables -A OUTPUT -d 169.254.169.254 -j DROP
| | | |---|---| | Severity | CRITICAL (15 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Agent compromise → attacker sends as you |
What to check:
~/.openclaw/openclaw.json → email configurationgmail.com, googlemail.com, yahoo.com, yahoo.co.uk, hotmail.com, outlook.com, live.com, msn.com, aol.com, icloud.com, me.com, mac.com, protonmail.com, proton.me, zoho.com, yandex.com, mail.com, gmx.com, tutanota.com, fastmail.comFix: Use a dedicated agent email on a domain you control, or a managed service that provides agent-specific email addresses.
| | |
|---|---|
| Severity | CRITICAL (15 pts) |
| OWASP | ASI-03 Identity & Privilege Abuse |
| CVE | CVE-2026-22038 (AutoGPT plaintext key logging) |
| Ref | OpenClaw Issues #9627, #4654 — openclaw doctor --fix writes env vars as plaintext |
What to check:
~/.openclaw/openclaw.json~/.openclaw/.env.env and openclaw.json in current directorysk- followed by 20+ alphanumeric chars (OpenAI)sk-ant- (Anthropic)AKIA followed by 16 uppercase alphanumeric chars (AWS)ghp_ followed by 36 alphanumeric chars (GitHub)xoxb- or xoxp- (Slack)AIza followed by 35 chars (Google)(?i)(api[_-]?key|secret|token|password)\s*[=:]\s*['"]?[a-zA-Z0-9_\-]{20,}openclaw.json contains resolved environment variable values (the openclaw doctor --fix bug writes ${VAR} as its actual value)Fix:
# Move secrets to environment variables
# In openclaw.json, use: "${OPENAI_API_KEY}" not the actual key
# Set in .env (with 600 permissions):
chmod 600 ~/.openclaw/.env
# Or use system keychain:
openclaw config set auth.keychain true
| | | |---|---| | Severity | CRITICAL (15 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Every self-hosted agent runs as the user with full filesystem access | | Verified | Yes — actually checks if files are readable |
What to check: Test if the following sensitive files/directories exist AND are readable:
~/.ssh/id_rsa
~/.ssh/id_ed25519
~/.aws/credentials
~/.config/gcloud/application_default_credentials.json
~/.kube/config
~/.npmrc
~/.docker/config.json
~/.netrc
~/.gnupg/
For each, run test -r <path> (or equivalent stat check).
Report which specific files are exposed but never read their contents.
Fix:
# Enable sandbox to isolate agent from host filesystem
openclaw config set sandbox.mode all
# Or restrict with file permissions:
chmod 700 ~/.ssh ~/.aws ~/.gnupg
| | | |---|---| | Severity | CRITICAL (15 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Snyk research: skills leak credentials into session JSONL files | | Verified | Yes — scans actual session content |
OPT-IN: Ask the user before running this check:
"Check 7 scans your recent session transcripts for accidentally leaked secrets (API keys, credit cards, SSNs). Everything stays local. Run this check? (y/n)"
If declined: SKIP (-1)
What to check:
~/.openclaw/agents/*/sessions/*.jsonl\b[0-9]{4}[- ]?[0-9]{4}[- ]?[0-9]{4}[- ]?[0-9]{4}\b\b[0-9]{3}-[0-9]{2}-[0-9]{4}\bFix:
# Enable log redaction
openclaw config set logging.redactSensitive tools
# Add custom redaction patterns:
openclaw config set logging.redactPatterns '["sk-[a-zA-Z0-9]+", "AKIA[A-Z0-9]+"]'
# Purge compromised sessions:
rm ~/.openclaw/agents/*/sessions/<affected_session>.jsonl
# Rotate any exposed keys immediately
| | | |---|---| | Severity | CRITICAL (15 pts) | | OWASP | ASI-05 Unexpected Code Running | | CVE | CVE-2023-37273 (AutoGPT Docker escape) | | Verified | Yes — inspects container runtime configuration |
What to check:
/.dockerenv file or cgroup entries containing docker/containerd--privileged flag (check: cat /proc/1/status | grep CapEff — if all bits set 0000003fffffffff, container is privileged)cat /proc/1/net/dev and compare to host — if identical, host networking is active)/ or /home or /etc mounted from host (check: mount | grep -E "on / type|on /home type|on /etc type" for bind mounts from host)--privileged or host root/home mounted: VERIFIED FAIL — any agent compromise is full host compromiseFix:
# Remove --privileged flag from docker run / docker-compose.yml
# Replace host volume mounts with specific directories:
# BAD: -v /:/host
# GOOD: -v /path/to/project:/workspace:ro
# Use non-root user inside container:
# USER 1000:1000 in Dockerfile
# Drop all capabilities and add only what's needed:
docker run --cap-drop=ALL --cap-add=NET_BIND_SERVICE ...
| | | |---|---| | Severity | CRITICAL (15 pts) | | OWASP | ASI-05 Unexpected Code Running | | Ref | If UID=0, any agent compromise = full system compromise | | Verified | Yes — checks process UID |
What to check:
id -u0 (root): VERIFIED FAIL — the agent has unrestricted system accesssudo -n true 2>/dev/null — if it succeeds without prompting, the user effectively has rootFix:
# Create a dedicated non-root user for the agent:
sudo useradd -m -s /bin/bash openclaw-agent
# Run the agent as that user:
sudo -u openclaw-agent openclaw start
# Remove passwordless sudo if present:
sudo visudo # Remove NOPASSWD entries for the agent user
# In Docker, add to Dockerfile:
RUN useradd -m agent
USER agent
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-05 Unexpected Code Running | | Ref | OpenClaw sandbox is OFF by default (Issue #7827) |
What to check:
~/.openclaw/openclaw.json → sandbox.modeoff or not set: FAIL — agent code runs directly on hostnon-main: WARN — only non-primary sessions sandboxedall: check sandbox.scope:
shared: WARN — cross-session data leakage possiblesession or agent: PASSFix:
openclaw config set sandbox.mode all
openclaw config set sandbox.scope session
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-05 Unexpected Code Running | | CVE | CVE-2026-25253 kill chain used elevated mode to escape sandbox |
What to check:
~/.openclaw/openclaw.json → tools.elevatedtools.elevated.allowFrom is set to * or all: FAIL — sandbox escape for any sessiontools.elevated exists but allowFrom is restricted to specific users/channels: PASStools.elevated doesn't exist: PASS (not configured)Fix:
# Restrict elevated mode to specific trusted users only
openclaw config set tools.elevated.allowFrom '["your-telegram-id"]'
# Or disable entirely:
openclaw config delete tools.elevated
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | CIS Benchmark: sensitive config should be 600 | | Verified | Yes — checks actual file permissions |
What to check:
~/.openclaw/openclaw.json~/.openclaw/.env~/.openclaw/credentials/ (all files)~/.openclaw/agents/*/agent/auth-profiles.jsonFix:
chmod 600 ~/.openclaw/openclaw.json ~/.openclaw/.env
chmod -R 600 ~/.openclaw/credentials/
chmod 700 ~/.openclaw/ ~/.openclaw/credentials/
# Or let openclaw fix it:
openclaw doctor --fix
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-04 Agentic Supply Chain | | Ref | 341 malicious ClawHub skills found (12% of registry), Feb 2026 |
What to check:
~/.openclaw/skills/data-exfil, keylogger, reverse-shell, crypto-miner, credential-stealer,
prompt-injector, shadow-agent, backdoor-tool, solana-wallet-tracker,
polymarket-trader, token-sniper, atomic-stealer, openclaw-boost,
free-credits, claw-premium, admin-tools
SKILL.md fileFix:
# Remove malicious skills:
rm -rf ~/.openclaw/skills/<malicious-skill>
# Enable plugin allowlist (whitelist mode):
openclaw config set plugins.allow '["skill-a", "skill-b"]'
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-04 Agentic Supply Chain | | CVE | CVE-2025-6514 (mcp-remote RCE, CVSS 9.6), CVE-2025-49596 (MCP Inspector RCE), CVE-2025-53109/53110 (Filesystem MCP escape) |
What to check:
package.json files in agent config, node_modules/ directories, or MCP configmcp-remote < 1.1.0 → CVE-2025-6514 (CRITICAL)@anthropic/mcp-inspector < 0.7.0 → CVE-2025-49596@anthropic/mcp-server-filesystem < 2.1.0 → CVE-2025-53109@anthropic/mcp-server-git < 2.1.0 → CVE-2025-68143/68144/68145Fix:
npm update mcp-remote @anthropic/mcp-inspector @anthropic/mcp-server-filesystem
# Or pin to safe versions in package.json
| | | |---|---| | Severity | HIGH (10 pts) | | CVE | CVE-2026-25253 (CVSS 8.8) — patched in v2.6.1+ |
What to check:
openclaw --version or read package.jsonFix:
openclaw update
# Or:
npm install -g openclaw@latest
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Session files contain full conversation history in plaintext JSONL | | Verified | Yes — checks actual permissions |
What to check:
~/.openclaw/agents/*/sessions/ directories and files~/.openclaw/ is inside a synced folder: WARNFix:
chmod -R 700 ~/.openclaw/agents/*/sessions/
# Exclude from cloud sync:
# macOS: add to .nosync or move outside ~/Library/Mobile Documents
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Default/placeholder credentials are the first thing attackers try |
What to check:
~/.openclaw/openclaw.json~/.openclaw/.env.env and openclaw.json in current directorychange_me, changemedefault, placeholderexample, sampleYOUR_ (e.g., YOUR_API_KEY, YOUR_TOKEN)xxx, TODO, FIXMEpassword123, admin, testFix:
# Replace all placeholder values with real credentials:
openclaw config set gateway.auth.token "$(openssl rand -hex 32)"
# Audit your .env file:
grep -inE "change_me|default|placeholder|YOUR_|xxx" ~/.openclaw/.env
# Replace each match with actual values, then:
chmod 600 ~/.openclaw/.env
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Wiz research: 65% of Forbes AI 50 companies leaked secrets on GitHub | | Verified | Yes — checks .gitignore contents |
What to check:
~/.openclaw/ is inside a git repository: run git rev-parse --is-inside-work-tree 2>/dev/null.env is listed in .gitignore:
git check-ignore .env — if it returns .env, it's ignored: PASS.env*, .env.local, .env.production patterns.env is NOT ignored: FAIL — secrets may be committed to version control.env is already tracked by git: git ls-files --error-unmatch .env 2>/dev/null — if tracked, it's already in history even if later added to .gitignoreFix:
# Add .env to .gitignore:
echo ".env" >> .gitignore
echo ".env.*" >> .gitignore
# If .env was already committed, remove from tracking (file stays on disk):
git rm --cached .env
git commit -m "Remove .env from tracking"
# WARNING: The .env is still in git history — see CLAW-19
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Keys committed even once persist in history forever; Wiz found secrets in deleted forks and gists | | Verified | Yes — scans actual git log |
OPT-IN: Ask the user before running this check:
"Check 20 scans your git history for accidentally committed secrets (API keys, tokens). This may take a moment on large repos. Run this check? (y/n)"
If declined: SKIP (-1)
What to check:
git rev-parse --is-inside-work-tree 2>/dev/nullgit log --all -p -100 2>/dev/null
sk- followed by 20+ alphanumeric charssk-ant- (Anthropic)AKIA followed by 16 uppercase alphanumeric chars (AWS)ghp_ followed by 36 alphanumeric chars (GitHub)xoxb- or xoxp- (Slack)(?i)(api[_-]?key|secret|token|password)\s*[=:]\s*['"]?[a-zA-Z0-9_\-]{20,}Fix:
# IMPORTANT: Rotate all exposed credentials FIRST — assume they are compromised
# Then remove from history using git-filter-repo (preferred over BFG):
pip install git-filter-repo
git filter-repo --invert-paths --path .env --force
# Or use BFG Repo Cleaner:
bfg --delete-files .env
git reflog expire --expire=now --all && git gc --prune=now --aggressive
# Force push the cleaned history (coordinate with team):
git push --force-with-lease
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Browser profiles contain saved passwords, cookies, and active session tokens for every logged-in service | | Verified | Yes — checks if directories are readable |
What to check:
# macOS
~/Library/Application Support/Google/Chrome/
~/Library/Application Support/Firefox/Profiles/
~/Library/Application Support/BraveSoftware/Brave-Browser/
~/Library/Application Support/Microsoft Edge/
# Linux
~/.config/google-chrome/
~/.mozilla/firefox/
~/.config/BraveSoftware/Brave-Browser/
~/.config/microsoft-edge/
test -r <path> (or equivalent stat check)Report which browser profiles are exposed but never read their contents.
Fix:
# Enable sandbox to isolate agent from browser profile directories
openclaw config set sandbox.mode all
# Or restrict permissions (will break browser for current user — use sandbox instead):
# The real fix is running the agent as a separate user:
sudo -u openclaw-agent openclaw start
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Plaintext git credentials give push access to every repository the user has access to | | Verified | Yes — checks if credential files are readable |
What to check:
~/.git-credentials
~/.gitconfig
~/.git-credentials: if it exists and is readable: FAIL — contains plaintext username:token pairs~/.gitconfig: check if it contains a credential section with helper = store (plaintext storage): if so, FAILgit config --global credential.helper — if set to store, credentials are in plaintextcache, credentials are temporarily in memory (less severe)osxkeychain, wincred, or libsecret: PASS (uses OS keychain)Fix:
# Switch from plaintext to OS keychain:
# macOS:
git config --global credential.helper osxkeychain
# Linux:
git config --global credential.helper libsecret
# Remove plaintext credentials file:
rm ~/.git-credentials
# Enable agent sandbox to prevent access:
openclaw config set sandbox.mode all
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Database credential files provide direct access to production data | | Verified | Yes — checks if credential files are readable |
What to check:
~/.pgpass # PostgreSQL
~/.my.cnf # MySQL/MariaDB
~/.mongosh/ # MongoDB Shell history/config
~/.config/redis/ # Redis config
~/.influxdbv2/configs # InfluxDB
~/.cqlshrc # Cassandra
test -r <path> (or equivalent stat check)Report which credential files are exposed but never read their contents.
Fix:
# Restrict permissions on database credential files:
chmod 600 ~/.pgpass ~/.my.cnf ~/.cqlshrc 2>/dev/null
chmod 700 ~/.mongosh/ ~/.config/redis/ 2>/dev/null
# Enable sandbox to isolate agent:
openclaw config set sandbox.mode all
# Best practice: use a separate user for the agent:
sudo -u openclaw-agent openclaw start
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | AutoGPT exposes ports 8000+3000 by default; 17,500+ OpenClaw instances found exposed | | Verified | Yes — checks actual listening sockets |
What to check:
ss -tlnp 2>/dev/null | grep "0.0.0.0" || netstat -tlnp 2>/dev/null | grep "0.0.0.0"
0.0.0.0:
0.0.0.0: VERIFIED FAIL0.0.0.0 (besides gateway, which is CLAW-01): WARN127.0.0.1/localhost: PASSFix:
# Bind services to localhost only:
# In docker-compose.yml, change:
# ports: ["8000:8000"] → ports: ["127.0.0.1:8000:8000"]
# ports: ["3000:3000"] → ports: ["127.0.0.1:3000:3000"]
# In agent config, set bind address to 127.0.0.1
# Use a reverse proxy (nginx/caddy) with auth for remote access
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Without a firewall, every exposed port is reachable from the network | | Verified | Yes — checks firewall status |
What to check:
# Linux:
sudo iptables -L -n 2>/dev/null | grep -c "^[A-Z]"
sudo ufw status 2>/dev/null
sudo nft list ruleset 2>/dev/null | head -5
# macOS:
sudo pfctl -s rules 2>/dev/null | head -5
/usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate 2>/dev/null
To determine if this is a VPS: check if running on a cloud provider (metadata service responds, or hostname contains common cloud patterns like ip-, .compute., .ec2.).
Fix:
# Linux (ufw — simplest):
sudo ufw default deny incoming
sudo ufw allow ssh
sudo ufw enable
# Linux (iptables):
sudo iptables -A INPUT -i lo -j ACCEPT
sudo iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT
sudo iptables -A INPUT -j DROP
# macOS:
sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-05 Unexpected Code Running | | CVE | CVE-2025-31133, CVE-2025-52565, CVE-2025-52881 (runC container escape vulnerabilities) | | Verified | Yes — inspects container security configuration |
What to check:
/.dockerenv file or cgroup entriesgrep -c Seccomp /proc/1/status — if Seccomp: 0, no seccomp profile is appliedSeccomp: 2 means a filter is active: PASS for seccompcat /proc/1/attr/current 2>/dev/null — if unconfined, no AppArmor profilerunc --version 2>/dev/null — vulnerable if below 1.2.8, 1.3.3, or 1.4.0-rc.3Fix:
# Apply Docker's default seccomp profile (enabled by default unless --security-opt seccomp=unconfined):
# In docker-compose.yml:
# security_opt:
# - seccomp:default
# - no-new-privileges:true
# Update runC to patched version:
sudo apt update && sudo apt install runc
# Or update Docker Engine which bundles runC:
sudo apt update && sudo apt install docker-ce docker-ce-cli
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-04 Agentic Supply Chain | | Ref | Uncommitted modifications to agent code could indicate backdoors or tampering | | Verified | Yes — checks git status of agent installation |
What to check:
which openclaw or npm list -g openclaw/usr/lib/node_modules/openclaw/, /usr/local/lib/node_modules/openclaw/, or local node_modules/openclaw/.git):
git -C <install_dir> status --porcelain 2>/dev/nullgit -C <install_dir> diff 2>/dev/null | head -50 — report which files changed (not the full diff content)npm ls openclaw and check the installed version matches expectedFix:
# Reinstall from official source:
npm install -g openclaw@latest
# Verify integrity after install:
npm audit signatures
# To prevent future tampering, make install directory read-only:
sudo chmod -R a-w /usr/lib/node_modules/openclaw/
| | | |---|---| | Severity | HIGH (10 pts) | | OWASP | ASI-04 Agentic Supply Chain | | Ref | ClawHub supply chain attacks: 341 malicious skills used post-install scripts to deliver Atomic Stealer malware | | Verified | Yes — scans actual package.json files |
What to check:
~/.openclaw/skills/*/:
package.json file existspreinstall, install, postinstall,
preuninstall, uninstall, postuninstall,
prepack, postpack, prepare
npm installpreinstall or postinstall scripts: FAIL — report which skills and which scriptsprepare, prepack): WARNpackage.json: SKIPFix:
# Remove suspicious skills:
rm -rf ~/.openclaw/skills/<suspicious-skill>
# Disable npm lifecycle scripts globally (nuclear option):
npm config set ignore-scripts true
# Or audit before installing:
npm install --ignore-scripts # Then manually review what scripts would run
# Enable OpenClaw plugin allowlist:
openclaw config set plugins.allow '["trusted-skill-1", "trusted-skill-2"]'
| | | |---|---| | Severity | MEDIUM (5 pts) | | CVE | CVE-2026-22038 (AutoGPT plaintext key logging) | | Ref | Secrets in logs are the #1 accidental exposure vector |
What to check:
~/.openclaw/openclaw.json → logging.redactSensitiveoff: FAILtools (default): PASSlogging.redactPatterns has custom patterns for the user's specific API key formatsFix:
openclaw config set logging.redactSensitive tools
| | | |---|---| | Severity | MEDIUM (5 pts) | | CVE | CVE-2026-22038 (AutoGPT plaintext key logging) | | Ref | Debug mode leaks extra data including full request/response payloads with auth headers and API keys |
What to check:
~/.openclaw/openclaw.json → logging.levelOPENCLAW_LOG_LEVEL, DEBUG, NODE_DEBUG, LOG_LEVELdebug, verbose, or trace: FAIL — full request/response payloads (including API keys in headers) will be written to logsDEBUG=* or DEBUG=openclaw:* is set in environment or .env: FAILinfo, warn, or error: PASSFix:
# Set logging to production-appropriate level:
openclaw config set logging.level warn
# Remove debug environment variables:
# In ~/.openclaw/.env, remove or comment out:
# DEBUG=*
# OPENCLAW_LOG_LEVEL=debug
# NODE_DEBUG=*
# Also ensure log redaction is enabled (see CLAW-28):
openclaw config set logging.redactSensitive tools
| | | |---|---| | Severity | MEDIUM (5 pts) | | OWASP | ASI-03 Identity & Privilege Abuse | | Ref | Session history contains conversation data, tool outputs, and potentially leaked secrets — cloud sync uploads this to third-party servers |
What to check:
~/.openclaw/: realpath ~/.openclaw/# macOS iCloud:
~/Library/Mobile Documents/
# Dropbox:
~/Dropbox/
# Google Drive:
~/Google Drive/
~/Library/CloudStorage/GoogleDrive-*/
# OneDrive:
~/OneDrive/
~/Library/CloudStorage/OneDrive-*/
~/.openclaw/ itself is a symlink pointing into a sync folder~/.openclaw/ is inside a cloud sync folder: FAIL — all session data, configs, and credentials are being uploaded to the cloud providerFix:
# Move .openclaw out of the synced folder:
mv ~/.openclaw /usr/local/var/openclaw
ln -s /usr/local/var/openclaw ~/.openclaw
# Or exclude from sync:
# macOS iCloud: add .nosync extension or use .nosync file
touch ~/.openclaw/.nosync
# Dropbox: use selective sync to exclude .openclaw
# Google Drive: use selective sync settings in Drive app
| Severity | Points per check | Count | |----------|-----------------|-------| | CRITICAL | 15 | 21 checks | | HIGH | 10 | 43 checks | | MEDIUM | 5 | 8 checks | | Total | 785 | 72 checks |
score = (sum of points for PASSED checks) / (sum of points for all NON-SKIPPED checks) x 100
Skipped checks (opt-in declined, not applicable) are excluded from both numerator and denominator.
WARN results count as half points (e.g., a HIGH check with WARN = 5 points instead of 10).
| Grade | Score | Meaning | |-------|-------|---------| | A | 90-100 | Hardened — no critical findings | | B | 75-89 | Good — minor improvements needed | | C | 60-74 | Needs work — some real risks | | D | 40-59 | Exposed — significant vulnerabilities | | F | 0-39 | Critical — immediate action required |
Present results as:
## Have I Been Clawned? — Security Audit
### Hardening Score: [SCORE]/100 — Grade [GRADE]
[████████░░] 80/100
| # | Check | Result | Severity | Ref |
|---|-------|--------|----------|-----|
| 01 | Gateway Network Exposure | ✅ VERIFIED PASS | CRITICAL | CVE-2026-25253 |
| 02 | Gateway Authentication | ❌ VERIFIED FAIL | CRITICAL | CVE-2026-25253 |
| ... | ... | ... | ... | ... |
### Findings
#### ❌ CLAW-02: Gateway Authentication — VERIFIED FAIL
**Why it matters:** Without authentication, anyone who can reach your gateway port can
control your agent and access stored API tokens. 17,500+ OpenClaw instances were found
exposed this way (CVE-2026-25253).
**Fix:**
\`\`\`bash
openclaw config set gateway.auth.mode token
openclaw config set gateway.auth.token "$(openssl rand -hex 32)"
\`\`\`
[Repeat for each failing check]
### Share your results
[SHAREABLE_URL]
Encode results as JSON, then base64url. The URL contains everything — no backend storage needed.
const report = {
v: 3, // format version
s: 72, // hardening score
g: "C", // grade
r: [1,0,1,...], // 72 results, ordered by check #
// Values: 1=pass, 0=fail, 2=warn, -1=skip
t: "2026-02-07" // date
};
const encoded = btoa(JSON.stringify(report))
.replace(/\+/g, "-").replace(/\//g, "_").replace(/=+$/, "");
const url = `https://haveibeenclawned.com/report?d=${encoded}`;
Show to the user:
Share your results:
[URL]
If using the script, ask the user to re-run with --submit (see "How to run" above).
If running checks individually, POST to https://haveibeenclawned.com/api/submit:
{
"v": 3,
"s": 72,
"g": "C",
"r": [1,0,1,...]
}
This audit is open source. Add checks, update threat intel, improve fix commands.
Each check follows this structure:
### CLAW-XX: Check Name
| | |
|---|---|
| **Severity** | CRITICAL (15 pts) / HIGH (10 pts) / MEDIUM (5 pts) |
| **OWASP** | ASI-XX Reference |
| **CVE** | CVE-XXXX-XXXXX (if applicable) |
| **Verified** | Yes/No — does this check actually test the vulnerability? |
**What to check:**
[Step-by-step instructions an AI agent can follow]
**Fix:**
[Exact commands to remediate]
github.com/wadim/haveibeenclawnedSKILL.md following the format aboveThe known-malicious skills list and CVE version checks are updated regularly. To suggest additions, open an issue with the source reference.
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
ready
Auth
mcp, api_key
Streaming
No
Data region
global
Protocol support
Requires: mcp, openclew, lang:typescript
Forbidden: none
Guardrails
Operational confidence: medium
curl -s "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/contract"
curl -s "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
Search ReliefWeb humanitarian reports, disasters, jobs, training, and country profiles via MCP.
One-call market verdict, plus funding, open interest, execution cost, volatility and macro
google search: google web search api, web, images, videos, news, music, favicon, proxy, audio.
63 production tools for AI agents — one API key, pay per call in USDC (x402) or Stripe credits.
Contract JSON
{
"contractStatus": "ready",
"authModes": [
"mcp",
"api_key"
],
"requires": [
"mcp",
"openclew",
"lang:typescript"
],
"forbidden": [],
"supportsMcp": true,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": "https://github.com/wadim/haveibeenclawned#input",
"outputSchemaRef": "https://github.com/wadim/haveibeenclawned#output",
"dataRegion": "global",
"contractUpdatedAt": "2026-02-24T19:52:55.243Z",
"sourceUpdatedAt": "2026-02-24T19:52:55.243Z",
"freshnessSeconds": 19589722
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"MCP",
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_OPENCLEW",
"generatedAt": "2026-10-09T13:28:18.144Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "MCP",
"type": "protocol",
"support": "supported",
"confidenceSource": "contract",
"notes": "Confirmed by capability contract"
},
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "execute",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "cost",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "steal",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "these",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "the",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "recent",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "access",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "directly",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "for",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "reach",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "control",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "follow",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:MCP|supported|contract protocol:OPENCLEW|unknown|profile capability:execute|supported|profile capability:cost|supported|profile capability:steal|supported|profile capability:these|supported|profile capability:the|supported|profile capability:recent|supported|profile capability:access|supported|profile capability:directly|supported|profile capability:for|supported|profile capability:reach|supported|profile capability:control|supported|profile capability:follow|supported|profile"
}Facts JSON
[
{
"factKey": "docs_crawl",
"category": "integration",
"label": "Crawlable docs",
"value": "6 indexed pages on the official domain",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
},
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Wadim",
"href": "https://github.com/wadim/haveibeenclawned",
"sourceUrl": "https://github.com/wadim/haveibeenclawned",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-03-01T06:04:00.383Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2 GitHub stars",
"href": "https://github.com/wadim/haveibeenclawned",
"sourceUrl": "https://github.com/wadim/haveibeenclawned",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-03-01T06:04:00.383Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "MCP, OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/contract",
"sourceType": "contract",
"confidence": "high",
"observedAt": "2026-02-24T19:52:55.243Z",
"isPublic": true
},
{
"factKey": "auth_modes",
"category": "compatibility",
"label": "Auth modes",
"value": "mcp, api_key",
"href": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/contract",
"sourceType": "contract",
"confidence": "high",
"observedAt": "2026-02-24T19:52:55.243Z",
"isPublic": true
},
{
"factKey": "schema_refs",
"category": "artifact",
"label": "Machine-readable schemas",
"value": "OpenAPI or schema references published",
"href": "https://github.com/wadim/haveibeenclawned#input",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/contract",
"sourceType": "contract",
"confidence": "high",
"observedAt": "2026-02-24T19:52:55.243Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/wadim-haveibeenclawned/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
]Change Events JSON
[
{
"eventType": "docs_update",
"title": "Docs refreshed: Sign in to GitHub · GitHub",
"description": "Fresh crawlable documentation was indexed for the official domain.",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
}
]Sponsored
Ads related to haveibeenclawned and adjacent AI workflows.