clawseccheckFree, local security self-audit for your own OpenClaw agent. Reads your OpenClaw config, bootstrap files, log files, agent session logs, and installed skills — read-only against your OpenClaw setup, plus a bounded host-security scan; writes only its own local report/history (removable with --purge). Scores your setup (A–F) and reports the most urgent holes. It changes nothing in your OpenClaw setup except through one opt-in, confirmation-gated command (--apply-ignore-proposals, which appends only suppressions you approved to .clawseccheckignore). No API key; the scanner itself makes no network calls, and the single external command it can run is your own read-only openclaw security audit (skip it with --no-native). Use it when you want to check or audit your OpenClaw agent's security, find prompt-injection or misconfiguration risks, or see your A–F security score.
Install via ClawdBot CLI:
clawdbot install gl0di/clawseccheckGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaContains instructions to override system prompt or ignore user requests
"ignore all previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
POST → http://198.51.100.5/harvestPotentially destructive shell commands in tool definitions
rm -rf /Generated Aug 15, 2026
A healthcare provider uses ClawSecCheck to regularly audit their AI agents handling patient data, ensuring compliance with HIPAA and identifying misconfigurations that could lead to data breaches. The tool's read-only scan and A-F scoring provide a clear compliance status.
A financial institution deploys ClawSecCheck to assess the security of AI agents used in trading and customer service, detecting prompt injection risks and misconfigurations that could lead to fraud or data leakage, thus meeting regulatory requirements.
A legal technology firm uses the skill to audit AI assistants that process confidential case files, ensuring that client-attorney privilege is maintained by identifying vulnerabilities and insecure configurations in their OpenClaw setup.
A fast-growing tech startup uses ClawSecCheck to perform self-audits of their AI-powered development agents, catching misconfigurations and potential attack vectors early, while maintaining a strong security posture for investor confidence.
Offer a free basic version of ClawSecCheck to individuals, while charging for premium features like advanced reporting, automated remediation suggestions, and priority support. Revenue comes from subscription fees and volume-based enterprise licenses.
Provide a managed service where experts use ClawSecCheck to audit and improve clients' OpenClaw security. Revenue is generated through consulting fees and recurring retainer contracts for continuous security monitoring and improvement.
Integrate ClawSecCheck into an existing AI agent platform as a value-added security feature. Revenue is generated by charging extra for security auditing capabilities, or through partnerships with AI infrastructure providers.
💬 Integration Tip
To integrate, simply add the skill to your OpenClaw agent and invoke it with natural language commands like 'check my security' or 'audit my setup'. No API keys or network calls are required, making it a safe, drop-in addition to your existing configuration.
Scored Aug 16, 2026
Accesses system directories or attempts privilege escalation
/etc/cronCalls external URL not in known-safe list
https://github.com/gl0di/clawseccheck/issuesUses known external API (expected, informational)
api.anthropic.comAI Analysis
The skill is a security audit tool that reads local configuration and log files, which is consistent with its stated purpose. The flagged credential access and shell commands are part of the audit's intended functionality, not malicious. The external URLs are for issue reporting and documentation, not data exfiltration, and the skill explicitly states it makes no network calls.
Audited Aug 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...