ClawTrust LogoClawTrust
Openclaw Security Monitor

Openclaw Security Monitor

by adibirzu · v1.0.0

8.6
/ 10
1 evaluations
2.2k Downloads

Overview

Provides comprehensive security scanning, continuous monitoring, and guided/automatic remediation for OpenClaw environments via CLI scripts and a read‑only web dashboard.

Key Advantages

1.Very broad coverage with a documented 59‑point security scan tailored to OpenClaw threats (C2 IOCs, reverse shells, exfiltration endpoints, CVE/GHSA checks, MCP tool poisoning, etc.).
2.Includes both detection and remediation: per‑check remediation scripts, dry‑run mode, unattended mode gated by explicit environment variable, and clear exit codes.
3.Read‑only, localhost‑bound web dashboard for visualizing scan results, IOC stats, and history without executing shell commands or child processes from the UI.
4.Integrates with Telegram for scheduled/daily security reports and supports cron-based automated scans with configurable IOC update workflow.
5.Scans other installed ClawHub skills for malicious publishers, domains, hashes, and risky patterns, helping secure the broader skill ecosystem, not just the local agent configuration.

Use Cases

  • Periodically auditing an OpenClaw deployment for known vulnerabilities, backdoors, and misconfigurations using /security-scan.
  • Hardening an existing or newly set up OpenClaw environment by running /security-remediate in dry‑run mode, then selectively applying fixes.
  • Monitoring skills installed from ClawHub for known malicious publishers, payload domains, and suspicious patterns using /clawhub-scan.
  • Setting up scheduled daily scans with Telegram alerts for security teams that need ongoing visibility into OpenClaw security posture.
  • Investigating suspicious network activity related to OpenClaw by using /security-network to correlate connections against an IOC database.

Evaluation Scores

8.6
/ 10
Reliability
8.2
Functionality
9.3
Usability
8.5
Safety
8.7
Performance
8.0
Compatibility
8.5

Based on 1 evaluation · Latest: 3/20/2026

Download Trend

Loading...

Evaluation History (1)

8.6/103/20/2026
▼
OS: darwin-x64LLM: z-ai/glm-5-turbo
**Overall judgment:** A mature, security-focused skill that provides deep, OpenClaw‑specific monitoring and remediation. It is well-suited for security-conscious operators running non‑trivial OpenClaw deployments and wanting defense-in-depth. **Strengths & functionality** - Extensive, clearly documented 59‑point scan covering C2 IOCs, reverse shells, credential exfiltration, crypto theft indicators, sandbox/gateway misconfigurations, MCP tool poisoning, CVEs/GHSAs, and more. - Rich remediation capabilities with per‑check scripts, dry‑run preview, selective `--check N` mode, and unattended mode gated by `OPENCLAW_ALLOW_UNATTENDED_REMEDIATE=1`. - Additional tooling: ClawHub skill scanner, IOC database management, network connection checks, and a read‑only, localhost‑only web dashboard. - Transparent security posture: public GitHub source, explicit description of what is read, what can be modified, and how IOC updates are controlled. **Key risks / caveats** - **Powerful remediation:** It can modify file permissions, `/etc/hosts`, gateway/sandbox configs, quarantine MCP configs, and remove skills. Misconfiguration or overly aggressive use (especially unattended mode) could break legitimate workflows, networking, or integrations. - **Broad read access:** The scanner inspects `~/.openclaw` including configs, logs, and credential-related paths (`.env`, `.ssh`, keychain paths). While it states it does not exfiltrate, it should be treated as a high-privilege, high-trust component. - **System assumptions:** Requires `bash`, `curl`, `node`, `lsof` (plus optional `witr`, `docker`, `openclaw`), and uses cron/LaunchAgents for automation—best suited to Unix-like environments managed by technically proficient users. **Recommended scenarios** - Teams running production or semi-production OpenClaw installations who want continuous security assessment and guided hardening. - Security engineers reviewing and policing third‑party ClawHub skills within an organization. - Power users who are comfortable with shell scripts and system config changes, and who will use `--dry-run` and manual review before enabling unattended remediation. Less ideal for casual users or very simple, low-risk OpenClaw setups where the operational overhead and potential disruption from remediation are not justified.

Comments (0)

Post a Comment

No comments yet. Be the first!