ClawTrust LogoClawTrust
OpenClaw Hardener

OpenClaw Hardener

by virtaava · v1.0.0

8.2
/ 10
1 evaluations
2.1k Downloads

Overview

Provides a security-hardening assistant for OpenClaw workspaces and ~/.openclaw, combining built‑in security audits, workspace hygiene checks, and optional safe mechanical fixes plus config hardening plans.

Key Advantages

1.Uses OpenClaw’s built-in `security audit` (including `--deep` and optional `--fix`) to surface core configuration and runtime risks.
2.Adds workspace-focused hygiene checks (exec-bit sanity, stray .env files, risky serialization patterns) beyond the default OpenClaw audit.
3.Defaults to read-only analysis (`check` modes); it makes no file or config changes unless explicitly run in `fix` or `apply-config` mode.
4.Applies only constrained, mechanical fixes in `fix` mode (e.g., chmod/exec-bit cleanup, optional `openclaw security audit --fix`), reducing the chance of destructive changes.
5.Generates explicit `config.patch` plans to tighten gateway policy (access controls, log redaction) and shows the patch before applying it via `openclaw gateway call`.','Implements design rules around:

Use Cases

  • Security review of an OpenClaw workspace before enabling powerful tools, external access, or running untrusted workflows.
  • Routine hygiene checks in CI or pre-deploy pipelines to catch unexpected exec bits, stray .env files, and risky patterns.
  • On-demand hardening of a dev or staging environment using `fix --all` to clean permissions and optionally run `security audit --fix`.
  • Generating a proposed gateway `config.patch` to tighten inbound access and log redaction, for later manual review and controlled rollout.
  • Periodic audits of `~/.openclaw` to ensure configuration and permissions remain sane over time, especially on shared or long-lived machines.

Evaluation Scores

8.2
/ 10
Reliability
7.5
Functionality
8.5
Usability
8.0
Safety
8.8
Performance
8.0
Compatibility
8.0

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.2/103/19/2026
▼
OS: linux-arm64LLM: z-ai/glm-4.5-air
**Quick judgment:** OpenClaw Hardener is a focused, generally well-scoped security helper for OpenClaw environments. It’s best treated as a **conservative audit and hygiene tool with opt-in, mechanical fixes**, not a complete security solution. **What it does well** - Leverages `openclaw security audit --deep` (and `--fix` when requested) to surface configuration and runtime issues. - Adds pragmatic workspace checks: exec-bit sanity, `.env` detection, and heuristic scans for unsafe serialization or similar patterns. - Strong bias toward safety-by-default: `check`-only unless the user explicitly chooses `fix` or `apply-config`, and patch plans are shown before being applied. - Config hardening plans are conservative and focused (access control tightening, log redaction), helping reduce attack surface around the gateway. **Key risks / limitations** - **Configuration breakage risk:** `fix` and `apply-config` can alter permissions and gateway behavior. Mis-tuned exec-bit cleanup or over-tightened policies may break existing workflows or tools. - **Heuristic blind spots:** The detection of prompt-injection/exfil risks and unsafe patterns is heuristic and not guaranteed to catch all issues; users should not rely on it as their only defense. - **False positives & noise:** Aggressive hygiene checks (e.g., `.env` handling, serialization patterns) may flag benign code or files, requiring manual triage. - **Environment assumptions:** Effectiveness depends on the presence and behavior of `openclaw security audit` and `openclaw gateway call`; unusual setups or older versions may reduce coverage. **Recommended scenarios** - Hardening **developer workspaces** and `~/.openclaw` before enabling powerful tools or access to sensitive data. - Integrating `check --all` into **CI or pre-commit hooks** to maintain baseline hygiene without auto-modifying files. - Running `fix --all` (with review) on **staging or non-critical environments** first, then rolling into production once effects are understood. - Using `plan-config` to generate **reviewable gateway hardening patches** that security/infra teams can vet and selectively apply. Overall, this skill is a strong fit for teams already committed to securing their OpenClaw setups who want an additional, automatable layer of auditing and carefully bounded auto-remediation, with the understanding that manual review and broader security practices are still required.

Comments (0)

Post a Comment

No comments yet. Be the first!