Agent Audit Scanner for Openclaw

A robust security auditing tool designed to detect vulnerabilities, credential leaks, and unsafe code within Openclaw Skills before they are executed.

headyzhang
v0.1.0
Mar 6, 2026
1
977
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install agent-audit-scanner

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install agent-audit-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Agent Audit Scanner?

The Agent Audit Scanner is a specialized security framework tailored for developers and power users of the Openclaw ecosystem. It serves as a gatekeeper, analyzing scripts, configurations, and metadata to identify critical threats such as prompt injection, obfuscated shell commands, and privilege escalation.

By adhering to the 10 OWASP Agentic AI threat categories, this skill ensures that every addition to your agentic workflow is vetted against 49+ detection rules. Integrating this scanner into your routine helps maintain a hardened environment, protecting sensitive files and system integrity from malicious or poorly configured Openclaw Skills that could compromise your workspace.

Agent Audit Scanner Use Cases

  • Auditing a newly downloaded skill before granting execution permissions.
  • Performing a bulk security scan across all installed Openclaw Skills to identify legacy vulnerabilities.
  • Verifying the safety of an Openclaw configuration file for dangerous gateway binds or exposed tokens.
  • Responding to user security inquiries regarding the safety and integrity of specific agentic tools.

How Agent Audit Scanner Works

  1. The user triggers an audit via the /audit command or automatically upon installing a new component.
  2. The scanner accesses the targeted skill directory or the global configuration file in the .openclaw directory.
  3. It parses scripts (Python, JS, Shell) and metadata frontmatter for patterns matching known security threats and credential leaks.
  4. Findings are categorized into four severity tiers—BLOCK, WARN, INFO, or CLEAN—based on a specific confidence score and risk profile.
  5. A comprehensive report is generated, advising the user whether to safely enable, manually inspect, or immediately block the skill.

Agent Audit Scanner Setup

First, install the core auditing engine via pip:

pip install agent-audit && agent-audit --version

Once installed, the scanner can be invoked through the agent or directly via CLI using the bundled scripts to audit your Openclaw Skills.

Agent Audit Scanner Data Schema & Taxonomy

The skill organizes its security intelligence and reporting based on the following structure:

Component Description
Metadata Frontmatter Scans for risky flags like always:true or suspicious network endpoints in SKILL.md.
Config Files Audits .mcp.json and openclaw.json for hardcoded tokens and broad filesystem access.
Source Code Analyzes .py, .sh, .js, and .ts files for obfuscated commands and credential leaks.
Risk Mapping Maps findings to the 56-rule OWASP ASI categorization for standardized reporting.

Agent Audit Scanner Advanced Features

  • Multi-skill bulk auditing capabilities for large-scale Openclaw Skills management.
  • High-confidence BLOCK logic that prevents enabling any skill attempting to modify core system files like SOUL.md, MEMORY.md, or IDENTITY.md.
  • Detailed MCP misconfiguration detection to prevent unauthorized gateway access or open DM policies.
  • Deep pattern matching for social engineering and prompt injection attempts within skill documentation and body text.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*