Firm Security Audit for Openclaw

A proactive security auditing tool designed to detect and remediate critical vulnerabilities in OpenClaw deployments before they are exposed to the network.

romainsantoli-web
v1.0.0
Mar 1, 2026
0
894
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install firm-security-audit

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install firm-security-audit using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Firm Security Audit?

Firm Security Audit serves as a mandatory security gate for developers using Openclaw Skills. It specifically targets and resolves high-severity gaps such as SQL injection vulnerabilities, improper sandbox configurations, and ephemeral session secrets. By integrating this skill, users can harden their Gateway installations without needing to modify upstream source code, ensuring a robust and compliant AI agent environment.

Firm Security Audit Use Cases

  • Validating security posture before enabling Tailscale Funnel or public network exposure.
  • Automated security gating within CI/CD pipelines to block vulnerable deployments.
  • Routine auditing of existing agent configurations to ensure persistent session security and rate limiting compliance.
  • Generating remediation templates for Nginx, Caddy, and Docker Compose configurations.

How Firm Security Audit Works

  1. The skill initiates a sandbox audit to verify that non-main agent sessions are properly isolated via Docker.
  2. It performs a targeted security scan on API endpoints to identify potential SQL injection paths.
  3. Configuration checks are executed to ensure session secrets are persistent and not regenerated on every restart.
  4. It validates the presence of rate limiting on the WebSocket Gateway, especially when external funnels are active.
  5. If critical findings are detected, it automatically generates a digest and dispatches alerts to configured communication channels like Slack.

Firm Security Audit Setup

To integrate this security layer into your Openclaw Skills workspace, run the following command:

openclaw skill install firm-security-audit

Ensure that mcp-openclaw-extensions version 2.0.0 or higher is installed. You must also provide the paths to your config.yaml and .env files within the tool arguments to allow the audit engine to parse your local environment settings.

Firm Security Audit Data Schema & Taxonomy

The skill organizes its findings and remediation data into structured logs and templates:

Data Type Format Storage/Usage
Audit Results JSON Logged to docs/security-audits/ for compliance tracking
Remediation Snippets YAML / Nginx Provided in-line for quick fixes to config.yaml or proxy configs
Severity Metadata String Categorized as CRITICAL, HIGH, or MEDIUM for automated escalation
Alert Payloads JSON Sent to Slack via firm_export_slack_digest

Firm Security Audit Advanced Features

  • Automated CI/CD integration using the --fail-on flag to block builds with CRITICAL vulnerabilities.
  • Tailscale Funnel sensitivity: triggers aggressive rate limiting requirements when public exposure is detected.
  • Dynamic remediation template generation for various reverse proxies (Nginx/Caddy).
  • Multi-path scanning for deep analysis of API directory structures within Openclaw Skills deployments.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*