2.1k Downloads
Overview
Provides a security-hardening assistant for OpenClaw workspaces and ~/.openclaw, combining built‑in security audits, workspace hygiene checks, and optional safe mechanical fixes plus config hardening plans.
Key Advantages
1.Uses OpenClaw’s built-in `security audit` (including `--deep` and optional `--fix`) to surface core configuration and runtime risks.
2.Adds workspace-focused hygiene checks (exec-bit sanity, stray .env files, risky serialization patterns) beyond the default OpenClaw audit.
3.Defaults to read-only analysis (`check` modes); it makes no file or config changes unless explicitly run in `fix` or `apply-config` mode.
4.Applies only constrained, mechanical fixes in `fix` mode (e.g., chmod/exec-bit cleanup, optional `openclaw security audit --fix`), reducing the chance of destructive changes.
5.Generates explicit `config.patch` plans to tighten gateway policy (access controls, log redaction) and shows the patch before applying it via `openclaw gateway call`.','Implements design rules around:
Use Cases
- Security review of an OpenClaw workspace before enabling powerful tools, external access, or running untrusted workflows.
- Routine hygiene checks in CI or pre-deploy pipelines to catch unexpected exec bits, stray .env files, and risky patterns.
- On-demand hardening of a dev or staging environment using `fix --all` to clean permissions and optionally run `security audit --fix`.
- Generating a proposed gateway `config.patch` to tighten inbound access and log redaction, for later manual review and controlled rollout.
- Periodic audits of `~/.openclaw` to ensure configuration and permissions remain sane over time, especially on shared or long-lived machines.
Evaluation Scores
8.2
/ 10
Reliability
7.5
Functionality
8.5
Usability
8.0
Safety
8.8
Performance
8.0
Compatibility
8.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.2/103/19/2026▼
OS: linux-arm64LLM: z-ai/glm-4.5-air
**Quick judgment:** OpenClaw Hardener is a focused, generally well-scoped security helper for OpenClaw environments. It’s best treated as a **conservative audit and hygiene tool with opt-in, mechanical fixes**, not a complete security solution.
**What it does well**
- Leverages `openclaw security audit --deep` (and `--fix` when requested) to surface configuration and runtime issues.
- Adds pragmatic workspace checks: exec-bit sanity, `.env` detection, and heuristic scans for unsafe serialization or similar patterns.
- Strong bias toward safety-by-default: `check`-only unless the user explicitly chooses `fix` or `apply-config`, and patch plans are shown before being applied.
- Config hardening plans are conservative and focused (access control tightening, log redaction), helping reduce attack surface around the gateway.
**Key risks / limitations**
- **Configuration breakage risk:** `fix` and `apply-config` can alter permissions and gateway behavior. Mis-tuned exec-bit cleanup or over-tightened policies may break existing workflows or tools.
- **Heuristic blind spots:** The detection of prompt-injection/exfil risks and unsafe patterns is heuristic and not guaranteed to catch all issues; users should not rely on it as their only defense.
- **False positives & noise:** Aggressive hygiene checks (e.g., `.env` handling, serialization patterns) may flag benign code or files, requiring manual triage.
- **Environment assumptions:** Effectiveness depends on the presence and behavior of `openclaw security audit` and `openclaw gateway call`; unusual setups or older versions may reduce coverage.
**Recommended scenarios**
- Hardening **developer workspaces** and `~/.openclaw` before enabling powerful tools or access to sensitive data.
- Integrating `check --all` into **CI or pre-commit hooks** to maintain baseline hygiene without auto-modifying files.
- Running `fix --all` (with review) on **staging or non-critical environments** first, then rolling into production once effects are understood.
- Using `plan-config` to generate **reviewable gateway hardening patches** that security/infra teams can vet and selectively apply.
Overall, this skill is a strong fit for teams already committed to securing their OpenClaw setups who want an additional, automatable layer of auditing and carefully bounded auto-remediation, with the understanding that manual review and broader security practices are still required.
Comments (0)
No comments yet. Be the first!