Firm Runtime Audit Pack

v1.0.0

Runtime environment and configuration audit pack. Validates Node.js version, secrets workflow, HTTP headers, allowed commands, trusted proxy, disk budget, an...

0· 318· 1 versions· 1 current· 1 all-time· Updated 32m ago· MIT-0

Install

openclaw skills install firm-runtime-audit-pack

firm-runtime-audit-pack

⚠️ Contenu généré par IA — validation humaine requise avant utilisation.

Purpose

Audits the runtime environment of OpenClaw deployments: Node.js version compliance, secrets handling, HTTP security headers, command allowlists, proxy configuration, disk budget, and direct message policies.

Tools (7)

ToolDescriptionSeverity
openclaw_node_version_checkVerify Node.js runtime versionCRITICAL
openclaw_secrets_workflow_checkAudit secrets handling in workflowsCRITICAL
openclaw_http_headers_checkCheck HTTP security headers (HSTS, CSP)HIGH
openclaw_nodes_commands_checkValidate nodes.allowCommands configHIGH
openclaw_trusted_proxy_checkVerify trusted proxy configurationHIGH
openclaw_session_disk_budget_checkCheck session disk budget limitsMEDIUM
openclaw_dm_allowlist_checkAudit DM channel allowlist policyMEDIUM

Usage

skills:
  - firm-runtime-audit-pack

# Run full runtime audit:
openclaw_node_version_check config_path=/path/to/config.json
openclaw_secrets_workflow_check config_path=/path/to/config.json
openclaw_http_headers_check config_path=/path/to/config.json

Requirements

  • mcp-openclaw-extensions >= 3.0.0
  • Node.js >= 20.x recommended

Version tags

latestvk97e15ddndn679p6gn05ns8vgn8220y6