phy-openclaw-multibot-auditSecurity audit for multi-tenant OpenClaw Telegram bots. Checks workspace isolation, filesystem sandboxing, session scoping, auth separation, error leaking, a...
Install via ClawdBot CLI:
clawdbot install phy041/phy-openclaw-multibot-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdCalls external URL not in known-safe list
https://docs.openclaw.ai/gateway/securityAI Analysis
The skill is a security audit checklist for OpenClaw bot deployments. It references the official OpenClaw documentation URL for context and mentions system files like /etc/passwd as examples of what an insecure bot could access, not as actions the skill itself performs. The skill's purpose is defensive and educational, posing no inherent risk.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Before launching a public OpenClaw Telegram bot with open access, use this audit to ensure session isolation and filesystem sandboxing are configured to prevent cross-user data leaks. This is critical for bots serving multiple adversarial users, such as customer support or content generation services.
After adding multi-user support to an existing OpenClaw bot, run the audit to validate that new configurations like session.dmScope and workspaceOnly settings are correctly applied. This helps avoid security gaps when scaling from single to multi-tenant operations.
During a security review of an OpenClaw gateway serving multiple users, apply the audit checklist to assess isolation mechanisms and identify vulnerabilities like exec command exposure. This is essential for compliance in regulated industries like finance or healthcare.
When cross-user data leakage is suspected in a Telegram bot, use this audit to systematically check session isolation, filesystem access, and auth profile separation to pinpoint and remediate security breaches.
Offer specialized security auditing services for OpenClaw bot deployments, using this skill to identify and fix multi-tenant vulnerabilities. Charge per audit or subscription for ongoing reviews, targeting bot developers and enterprises.
Provide managed hosting for OpenClaw Telegram bots with built-in security configurations from this audit, ensuring isolation and compliance for clients. Generate revenue through hosting fees and premium support packages.
Sell developer tools or training courses based on this audit skill, helping teams implement secure multi-tenant bots. Revenue comes from tool licenses, workshops, and certification programs for security best practices.
💬 Integration Tip
Integrate this audit into CI/CD pipelines to automatically check security configurations before deployment, and use it alongside monitoring tools to detect isolation failures in production.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...