scanner-for-openclawSecurity expert for OpenClaw deployments. Audits local configuration files for vulnerabilities in network settings, channel policies, and tool permissions. P...
Install via ClawdBot CLI:
clawdbot install zoowii/scanner-for-openclawGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/openclaw/openclaw/tree/main/skills/openclaw-security-scannerAudited Apr 16, 2026 · audit v1.0
Generated Mar 21, 2026
After setting up OpenClaw, a DevOps engineer runs the scanner to check for misconfigurations like exposed admin ports or overly permissive channel policies. This ensures the deployment is secure before going live, preventing unauthorized access and data breaches.
A financial institution uses the scanner to audit their OpenClaw configuration for compliance with internal security policies and regulations. It identifies issues like missing TLS settings or weak tool permissions, helping maintain audit trails and reduce risk.
An IT administrator schedules weekly scans to monitor OpenClaw's security posture over time. The scanner detects changes in network bindings or channel policies, allowing proactive remediation before vulnerabilities are exploited in production environments.
Before deploying OpenClaw updates to a multi-user environment, a security team runs the scanner to validate configuration changes. It flags critical issues like allow-all tool execution policies, ensuring safe rollouts and minimizing downtime.
After a suspicious activity report, a security analyst uses the scanner to audit OpenClaw's configuration for signs of compromise, such as unauthorized channel access or altered permissions. This aids in root cause analysis and swift remediation.
Offer the scanner as a free, open-source tool to build trust and community adoption. Monetize through premium features like automated remediation scripts, detailed compliance reporting, or enterprise support services for large deployments.
Provide professional services to help organizations integrate the scanner into their DevOps pipelines or security frameworks. Offer custom audits, training workshops, and ongoing maintenance to ensure optimal security configurations.
Host the scanner as a cloud-based service with a web interface, allowing users to upload configurations for analysis without local installation. Generate revenue through tiered subscription plans based on scan frequency, user seats, or advanced analytics.
💬 Integration Tip
Integrate the scanner into CI/CD pipelines using its CLI commands to automatically audit configuration changes before deployment, ensuring security checks are part of the development workflow.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...