A proactive security auditing tool designed to detect and remediate critical vulnerabilities in OpenClaw deployments before they are exposed to the network.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install firm-security-audit
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install firm-security-audit using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Firm Security Audit serves as a mandatory security gate for developers using Openclaw Skills. It specifically targets and resolves high-severity gaps such as SQL injection vulnerabilities, improper sandbox configurations, and ephemeral session secrets. By integrating this skill, users can harden their Gateway installations without needing to modify upstream source code, ensuring a robust and compliant AI agent environment.
To integrate this security layer into your Openclaw Skills workspace, run the following command:
openclaw skill install firm-security-audit
Ensure that mcp-openclaw-extensions version 2.0.0 or higher is installed. You must also provide the paths to your config.yaml and .env files within the tool arguments to allow the audit engine to parse your local environment settings.
The skill organizes its findings and remediation data into structured logs and templates:
| Data Type | Format | Storage/Usage |
|---|---|---|
| Audit Results | JSON | Logged to docs/security-audits/ for compliance tracking |
| Remediation Snippets | YAML / Nginx | Provided in-line for quick fixes to config.yaml or proxy configs |
| Severity Metadata | String | Categorized as CRITICAL, HIGH, or MEDIUM for automated escalation |
| Alert Payloads | JSON | Sent to Slack via firm_export_slack_digest |
--fail-on flag to block builds with CRITICAL vulnerabilities.Loading
A comprehensive bundle of AI-agent configurations designed to power the full lifecycle of SaaS companies from engineering to growth.

A comprehensive security auditing suite for validating OpenClaw runtime environments and configurations.

A comprehensive reliability suite for gateway health monitoring, documentation synchronization, and architecture decision tracking.

A specialized detection engine that scans LLM inputs for 16 distinct prompt injection and jailbreak patterns across multiple severity levels.

A specialized utility pack for on-demand skill discovery and lazy loading within the Openclaw ecosystem.

A comprehensive suite of seven specialized audit tools designed to validate AI agent compliance with the MCP 2025-11-25 protocol specification.








































