openclaw-security
Unified security suite for agent workspaces. Installs, configures, and orchestrates all 11 OpenClaw security tools in one command — integrity, secrets, permissions, network, audit trail, signing, supply chain, credentials, injection defense, compliance, and incident response.
Best use case
openclaw-security is best used when you need a repeatable AI agent workflow instead of a one-off prompt.
Unified security suite for agent workspaces. Installs, configures, and orchestrates all 11 OpenClaw security tools in one command — integrity, secrets, permissions, network, audit trail, signing, supply chain, credentials, injection defense, compliance, and incident response.
Teams using openclaw-security should expect a more consistent output, faster repeated execution, less prompt rewriting.
When to use this skill
- You want a reusable workflow that can be run more than once with consistent structure.
When not to use this skill
- You only need a quick one-off answer and do not need a reusable workflow.
- You cannot install or maintain the underlying files, dependencies, or repository context.
Installation
Claude Code / Cursor / Codex
Manual Installation
- Download SKILL.md from GitHub
- Place it in
.claude/skills/openclaw-security/SKILL.mdinside your project - Restart your AI agent — it will auto-discover the skill
How openclaw-security Compares
| Feature / Agent | openclaw-security | Standard Approach |
|---|---|---|
| Platform Support | Not specified | Limited / Varies |
| Context Awareness | High | Baseline |
| Installation Complexity | Unknown | N/A |
Frequently Asked Questions
What does this skill do?
Unified security suite for agent workspaces. Installs, configures, and orchestrates all 11 OpenClaw security tools in one command — integrity, secrets, permissions, network, audit trail, signing, supply chain, credentials, injection defense, compliance, and incident response.
Where can I find the source code?
You can find the source code on GitHub using the link provided at the top of the page.
Related Guides
AI Agents for Coding
Browse AI agent skills for coding, debugging, testing, refactoring, code review, and developer workflows across Claude, Cursor, and Codex.
Best AI Skills for Claude
Explore the best AI skills for Claude and Claude Code across coding, research, workflow automation, documentation, and agent operations.
AI Agents for Marketing
Discover AI agents for marketing workflows, from SEO and content production to campaign research, outreach, and analytics.
SKILL.md Source
# OpenClaw Security Suite
One skill to install, configure, and orchestrate the entire OpenClaw security stack.
## Install All Security Tools
```bash
python3 {baseDir}/scripts/security.py install --workspace /path/to/workspace
```
Installs all 11 free security skills from ClawHub.
## Unified Dashboard
```bash
python3 {baseDir}/scripts/security.py status --workspace /path/to/workspace
```
Aggregated health check across all installed security tools.
## Full Security Scan
```bash
python3 {baseDir}/scripts/security.py scan --workspace /path/to/workspace
```
Runs every scanner: integrity verification, secret detection, permission audit, network DLP, supply chain analysis, injection scanning, credential exposure, and compliance audit.
## First-Time Setup
```bash
python3 {baseDir}/scripts/security.py setup --workspace /path/to/workspace
```
Initializes all tools that need it: integrity baseline, skill signing, audit ledger, compliance policy.
## Update All Tools
```bash
python3 {baseDir}/scripts/security.py update --workspace /path/to/workspace
```
Updates all installed security skills to latest versions via ClawHub.
## List Installed Tools
```bash
python3 {baseDir}/scripts/security.py list --workspace /path/to/workspace
```
Shows which security tools are installed and their versions.
## Pro Protection Sweep
```bash
python3 {baseDir}/scripts/security.py protect --workspace /path/to/workspace
```
Runs automated countermeasures across all installed Pro tools. Requires Pro versions.
## What Gets Orchestrated
| Tool | Domain | Free | Pro |
|------|--------|------|-----|
| **warden** | Workspace integrity, injection detection | Detect | Restore, rollback, quarantine |
| **sentry** | Secret/credential scanning | Detect | Redact, quarantine |
| **arbiter** | Permission auditing | Detect | Revoke, enforce |
| **egress** | Network DLP, exfiltration detection | Detect | Block, allowlist |
| **ledger** | Hash-chained audit trail | Record | Freeze, forensics |
| **signet** | Cryptographic skill signing | Verify | Reject, restore |
| **sentinel** | Supply chain security | Scan | Quarantine, block |
| **vault** | Credential lifecycle | Audit | Fix, rotate |
| **bastion** | Prompt injection defense | Scan | Sanitize, enforce |
| **marshal** | Compliance/policy enforcement | Audit | Enforce, hooks |
| **triage** | Incident response & forensics | Investigate | Contain, remediate |
## Requirements
- Python 3.8+
- No external dependencies (stdlib only)
- Cross-platform: Windows, macOS, LinuxRelated Skills
openclaw-youtube
YouTube SERP Scout for agents. Search top-ranking videos, channels, and trends for content research and competitor tracking.
openclaw-search
Intelligent search for agents. Multi-source retrieval with confidence scoring - web, academic, and Tavily in one unified API.
openclaw-media-gen
Generate images & videos with AIsa. Gemini 3 Pro Image (image) + Qwen Wan 2.6 (video) via one API key.
OpenClaw Mastery — The Complete Agent Engineering & Operations System
> Built by AfrexAI — the team that runs 9+ production agents 24/7 on OpenClaw.
Cybersecurity Risk Assessment
You are a cybersecurity risk assessment specialist. When the user needs a security audit, threat assessment, or compliance review, follow this framework.
afrexai-cybersecurity-engine
Complete cybersecurity assessment, threat modeling, and hardening system. Use when conducting security audits, threat modeling, penetration testing, incident response, or building security programs from scratch. Works with any stack — zero external dependencies.
security-guardian
Automated security auditing for OpenClaw projects. Scans for hardcoded secrets (API keys, tokens) and container vulnerabilities (CVEs) using Trivy. Provides structured reports to help maintain a clean and secure codebase.
openclaw-safe-change-flow
Safe OpenClaw config change workflow with backup, minimal edits, validation, health checks, and rollback. Single-instance first; secondary instance optional.
jqopenclaw-node-invoker
统一通过 Gateway 的 node.invoke 调用 JQOpenClawNode 能力(file.read、file.write、process.exec、process.manage、system.run、process.which、system.info、system.screenshot、system.notify、system.clipboard、system.input、node.selfUpdate)。当用户需要远程文件读写、文件移动/删除、目录创建/删除、进程管理(列表/搜索/终止)、远程进程执行、命令可执行性探测、系统信息采集、截图采集、系统弹窗、系统剪贴板读写、输入控制(鼠标/键盘)、节点自更新、节点命令可用性排查或修复 node.invoke 参数错误时使用。
SX-security-audit
全方位安全审计技能。检查文件权限、环境变量、依赖漏洞、配置文件、网络端口、Git 安全、Shell 安全、macOS 安全、密钥检测等。支持 CLI 参数、JSON 输出、配置文件。当用户要求"安全检查"、"漏洞扫描"、"权限检查"、"安全审计"时使用此技能。
openclaw-stock-skill
使用 data.diemeng.chat 提供的接口查询股票日线、分钟线、财务指标等数据,支持 A 股等市场。
openclaw-whatsapp
WhatsApp bridge for OpenClaw — send/receive messages, auto-reply agents, QR pairing, message search, contact sync