Clawstrike Security Audit for Openclaw

A comprehensive security auditing tool designed to identify misconfigurations and attack paths within OpenClaw deployments.

misirov
v0.1.0
Feb 5, 2026
0
2.4k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install macarena-test

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install macarena-test using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Clawstrike Security Audit?

Clawstrike is a specialized security auditing skill designed to harden OpenClaw gateway hosts and protect your infrastructure. It performs deep inspections of configuration files, filesystem permissions, and third-party plugin integrations to identify potential vulnerabilities. By leveraging a strict verified mode and a curated allowlist of commands, Clawstrike ensures that the audit process itself is secure and non-destructive. This skill provides developers with a clear OK/VULNERABLE status report, supported by redacted evidence and actionable remediation steps. It is a vital component for anyone managing production-grade Openclaw Skills who needs to ensure their environment remains resilient against unauthorized access and configuration drift.

Clawstrike Security Audit Use Cases

  • Audit OpenClaw gateway hosts for exposure and potential misconfigurations.
  • Generate automated threat models for local and remote deployments.
  • Verify the security posture of third-party plugins and untrusted skill files.
  • Ensure filesystem hygiene through permission checks and SUID/SGID identification.
  • Produce deterministic security reports for compliance or internal security reviews.

How Clawstrike Security Audit Works

  1. Initialize verified collection by executing mandatory scripts to gather system state without user intervention.
  2. Process the generated evidence bundle to analyze the operating system, runtime context, and configuration paths.
  3. Evaluate the deployment against a mandatory checklist of security requirements, including firewall status and discovery settings.
  4. Synthesize a threat model based on findings to highlight real-world attack paths.
  5. Generate a formatted report that includes an evidence table, severity ratings, and recommended fixes.

Clawstrike Security Audit Setup

To begin using Clawstrike, ensure you are in the OpenClaw directory and run the collection script to generate the required evidence bundle.

./scripts/collect_verified.sh

For a more comprehensive analysis of the local gateway, use the deep probe flag:

./scripts/collect_verified.sh --deep

Once the verified-bundle.json is created, the skill can analyze the data and generate a report based on the provided Openclaw Skills reference files.

Clawstrike Security Audit Data Schema & Taxonomy

Clawstrike organizes its data through a structured evidence bundle and a series of reference documents to ensure consistency.

Component Description
verified-bundle.json The primary data source containing system state, redacted config keys, and command output.
required-checks.md The authoritative list of security tests applied to the gathered evidence.
evidence-template.md The schema used to map verified evidence to specific security findings.
report-format.md The Markdown structure used for the final OK/VULNERABLE output.

Clawstrike Security Audit Advanced Features

  • Verified Mode execution ensures only pre-approved, safe commands from a strict allowlist are run.
  • Automated redaction of secrets, tokens, and sensitive credentials during evidence collection to prevent data leaks.
  • Deep probing capabilities for granular local gateway host analysis and filesystem auditing.
  • Supply chain scanning to identify patterns and risks in third-party Openclaw Skills files.
  • Deterministic reporting based on an authoritative configuration key map and version-specific risk guidance.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*