Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

OpenClaw Security Audit

v0.1.0

Automates security audits for OpenClaw gateway by checking key configuration settings to identify and report common security risks.

0· 562· 1 versions· 1 current· 1 all-time· Updated 15h ago· MIT-0

Install

openclaw skills install openclaw-security-policy-check

OpenClaw Security Policy Check

自动化安全审计配置工具,检测 OpenClaw 网关常见安全配置问题。

使用方法

node {baseDir}/scripts/audit.cjs

工作流程

  1. 读取配置文件:自动定位 ~/.openclaw/openclaw.json
  2. 检查配置:5 项关键安全配置
  3. 执行审计:运行 openclaw security audit --deep
  4. 输出报告:汇总修复结果和审计发现

检查项说明

配置项不安全值安全值
gateway.bind0.0.0.0127.0.0.1
gateway.auth.token短或默认32位强随机
controlUi.allowInsecureAuthtruefalse
tools.exec.securityfullallowlist
tools.exec.askoffon-miss

注意事项

  • 首次使用建议备份配置文件
  • 修改 token 后需要重启网关使配置生效
  • 需要有 openclaw 命令行工具

Version tags

latestvk976sfw0z9e8t9jwnen5xtzkcx82mtjg