Security audit
Security Hardening Toolkit V1.0
Security checks for vulnerabilities and agentic risk
Overview
This skill is a manual OpenClaw security-hardening checklist whose sensitive commands are disclosed and aligned with incident response and configuration-audit use.
Installers should treat this as a checklist, not automation. Review each command before running it, back up configuration files, expect some steps to require administrative privileges or interrupt services, and rotate credentials through provider dashboards without exposing secret values to the agent.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
