2.2k Downloads
Overview
Perform a structured, read-only security audit of OpenClaw/Clawdbot/Moltbot deployments and their host environment, identifying misconfigurations, exposure risks, and remediation steps.
Key Advantages
1.Read-only, non-destructive auditing with strong guardrails against risky actions or data exfiltration.
2.Comprehensive, opinionated checklist covering gateway exposure, auth, exec policies, skills, credentials, permissions, and logs.
3.Produces a standardized, terminal-friendly report with explicit OK/VULNERABLE/UNKNOWN findings, impact, and concrete fixes.
4.Specifically tailored to OpenClaw/Clawdbot installations, including gateway ports, control UI risks, and skill supply-chain concerns.
5.Built-in handling for partial visibility: marks checks as UNKNOWN when required tools/configs are unavailable, with explanations.
Use Cases
- One-off security review of a new OpenClaw/Clawdbot deployment before exposing it beyond localhost.
- Regular hardening checks on an existing OpenClaw gateway to catch configuration drift or newly introduced risks.
- Auditing a host for leaked OpenClaw credentials or overly permissive file/dir permissions in ~/.openclaw.
- Reviewing installed OpenClaw skills for supply-chain risk, hidden shell execution, or untrusted sources.
- Investigating whether Control UI or gateway endpoints are unintentionally exposed to public networks or misconfigured behind a reverse proxy.
Evaluation Scores
8.2
/ 10
Reliability
7.5
Functionality
8.5
Usability
8.5
Safety
9.0
Performance
7.0
Compatibility
8.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.2/103/19/2026▼
OS: darwin-x64LLM: deepseek/deepseek-v3.2
**Judgement**
A strong, specialized security-audit skill for OpenClaw/Clawdbot deployments. It is well-scoped, read-only by default, and follows a clear, methodical checklist that is suitable for most Linux-based OpenClaw environments.
**Key Risks / Limitations**
- Relies on common Linux utilities (`ss`, `systemctl`, `journalctl`, `find`, etc.); coverage and reliability will degrade on stripped-down systems, non-Linux OSes, or containers without these tools.
- Some checks (e.g., `find / -perm -4000`) can be relatively heavy on large systems, which may impact performance during the audit.
- Focuses on configuration and host-level misconfigurations; it does not replace deeper application-specific security testing or network penetration testing.
**Recommended Scenarios**
- Use when you need a structured, repeatable hardening review of an OpenClaw/Clawdbot/Moltbot setup, especially prior to exposing it to the internet or to untrusted users.
- Use for periodic re-audits after changing gateway config, adding new skills, or modifying exec/tool policies.
- Particularly helpful for identifying unsafe public exposure of the gateway/control UI, weak exec policies, plaintext secrets in `~/.openclaw`, and risky or untrusted skills, along with concrete remediation steps.
Comments (0)
No comments yet. Be the first!