openclaw-security-checklistOpenClaw 部署前安全检查清单。聚焦合规导向的部署前检查(非事后加固),覆盖防火墙、SSH、API 密钥管理、数据出境合规、多部署场景验证。使用清单式检查,可逐项打勾并生成报告。适用于个人 Mac、VPS、Docker、企业部署场景。
Install via ClawdBot CLI:
clawdbot install yiyuanlu/openclaw-security-checklistGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses system directories or attempts privilege escalation
sudo cpCalls external URL not in known-safe list
https://github.com/your-repo/openclaw-security-checklist.gitUses known external API (expected, informational)
api.anthropic.comAudited Apr 17, 2026 · audit v1.0
Generated Mar 22, 2026
Individual developers using Mac for local OpenClaw development or testing. This scenario focuses on securing personal machines with FileVault encryption, macOS firewall configuration, and disabling unnecessary services to prevent data leaks during deployment.
Users deploying OpenClaw on virtual private servers (VPS) from cloud providers like AWS or Alibaba Cloud. This scenario emphasizes configuring security group rules with minimal open ports, enabling cloud monitoring alerts, and setting up automated snapshots for backup to ensure compliance and resilience.
Teams or individuals running OpenClaw in Docker containers for scalable and isolated environments. This scenario involves checking for non-root user execution, limiting container resources (CPU/memory), and verifying volume permissions to enhance security and prevent privilege escalation risks.
Organizations, especially in regulated industries like finance or healthcare, deploying OpenClaw in enterprise settings. This scenario covers SSO/LDAP integration for access control, centralized audit log collection, and disaster recovery drills to meet strict data security and compliance standards.
Companies offering OpenClaw as a cloud-based service to customers. This model leverages the skill to ensure deployment compliance across multi-tenant environments, reducing legal risks and building trust through automated security checks and reports.
IT security firms providing deployment and compliance consulting for clients using OpenClaw. This model uses the skill to deliver tailored security assessments, generate reports, and guide clients through regulatory requirements, charging for expertise and time.
Organizations offering paid support, training, or premium documentation for OpenClaw users. This model integrates the skill into training materials to teach best practices, with revenue from workshops, certification programs, or enhanced support packages.
💬 Integration Tip
Integrate the security-check script into CI/CD pipelines to automate pre-deployment checks, ensuring compliance before each release and reducing manual effort.
Scored Jun 19, 2026
Use the ClawdHub CLI to search, install, update, and publish agent skills from clawdhub.com. Use when you need to fetch new skills on the fly, sync installed skills to latest or a specific version, or publish new/updated skill folders with the npm-installed clawdhub CLI.
Mission control dashboard for OpenClaw - real-time session monitoring, LLM usage tracking, cost intelligence, and system vitals. View all your AI agents in o...
Transcribe YouTube videos to text by extracting captions and subtitles directly from the video URL using yt-dlp without audio processing.
Manage a self-hosted Trello-like board via `wekancli`. Create, move and archive cards, lists and boards on a WeKan server. Use when user asks about task boar...
Proactive security monitoring, threat scanning, and auto-remediation for OpenClaw deployments
Create or improve SOUL.md files for OpenClaw agents through guided conversation. Use when designing agent personality, crafting a soul, or saying "help me create a soul". Supports self-improvement.