A purple team security tool that maps an agent's attack surface by correlating offensive probes with defensive detections.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install attack-surface-mapper
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install attack-surface-mapper using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Attack Surface Mapper is a specialized security tool designed to provide a comprehensive view of an AI agent's vulnerabilities and defenses. By functioning as a purple team component, it bridges the gap between red team offensive testing and blue team defensive monitoring. This skill ensures that developers utilizing Openclaw Skills can maintain a robust security posture by identifying exactly where attacks might bypass existing detection logic.
It systematically evaluates various components of the agent ecosystem, including communication channels, installed skills, and underlying models. By synthesizing data from multiple security logs, it provides a prioritized hardening plan that helps teams focus on the most critical gaps in their defense coverage.
To configure this skill within your environment, ensure the following directory structure and files are present:
# Create the security directory if it doesn't exist
mkdir -p .security/red-team
mkdir -p .security/audits
# Ensure your red team results are placed in:
# .security/red-team/*.jsonl
# Ensure your blue team audit logs are placed in:
# .security/audits/*.md
Once the files are in place, you can trigger a mapping exercise by asking the agent to map attack surface.
The skill organizes its analysis into a structured matrix, evaluating the relationship between surfaces and attack vectors. The data is exported as follows:
| Attribute | Description |
|---|---|
| Surface | The architectural component (e.g., Channels, Skills, Models, Memory) |
| Vector | The specific method of attack (e.g., Prompt Injection, Typosquatting) |
| Status | The coverage state: COVERED, PARTIAL, or GAP |
| Risk Score | A numerical value derived from impact multiplied by likelihood |
All reports are saved to the .security/ folder using the naming convention surface-map-YYYY-MM-DD.md for historical tracking of Openclaw Skills security trends.
Loading
A forensic-ready governance skill providing an immutable, hash-chained log of every agent action for complete accountability.

Maintain agent integrity through continuous behavioral monitoring and statistical anomaly detection for Openclaw Skills.

An expert-level scholarly writing toolkit that refines academic prose, eliminates AI traces, and implements advanced critical frameworks like those of Dai Jinhua and Wang Min'an.

An AI-powered creative engine for generating tilt-shift miniature scenes, hyper-detailed dioramas, and shallow-depth-of-field fantasy landscapes.

A specialized security framework for detecting, investigating, and neutralizing malicious or compromised bots in multi-agent environments.

A professional developer tool for publishing, versioning, and managing AI agent skills within the ClawhHub ecosystem.








































