Preflyt Security Scanner for Openclaw

A non-intrusive security tool that scans deployed URLs for exposed secrets, source code, and misconfigured infrastructure.

doureios39
v1.0.1
Mar 5, 2026
0
924
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install preflyt

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install preflyt using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Preflyt Security Scanner?

Preflyt is a specialized security auditing skill designed for the post-deployment phase of web development. It functions as an automated inspector that probes public-facing URLs to ensure no sensitive information—such as .env files, database credentials, or .git repositories—is accidentally exposed to the internet. As a vital addition to the Openclaw Skills ecosystem, it provides developers with a safety net that catches common devops oversights before they can be exploited by malicious actors.

This skill is particularly valuable because it performs read-only, non-intrusive checks from an outside-in perspective, mimicking how a scanner might first scout a target. By integrating this into your daily workflow, you ensure that every infrastructure change or code push is validated against high-severity security risks without requiring complex manual auditing processes.

Preflyt Security Scanner Use Cases

  • Validating security posture immediately after deploying a web application to production or staging.
  • Auditing backend APIs (Node, Python, Go) for exposed configuration files or server-side source code.
  • Verifying that infrastructure changes haven't inadvertently opened dangerous ports for MySQL, Redis, or MongoDB.
  • Checking for missing security headers like HSTS, CSP, and X-Frame-Options to prevent common web attacks.
  • Identifying directory listings and dangerous file parsing on public-facing servers.

How Preflyt Security Scanner Works

  1. The agent detects a successful deployment or infrastructure update targeting a public URL.
  2. It triggers the Preflyt scanning engine via the command line to probe the target endpoint.
  3. The skill performs a series of read-only HTTP requests to look for common misconfigurations like exposed .env files or .git folders.
  4. It checks for open database ports and missing security headers that could lead to data leakage.
  5. Results are categorized by severity; if high-severity findings are identified, the agent immediately alerts the user with specific remediation steps.

Preflyt Security Scanner Setup

To use this tool within the Openclaw Skills environment, ensure you have Node.js installed. You can run a scan manually using npx:

npx preflyt-check https://your-deployed-url.com

To integrate it into automated deployment scripts or CI/CD pipelines and force a failure on security findings:

npx preflyt-check https://your-deployed-url.com --fail

For users with a Pro license, you can activate unlimited scans by including your license key:

npx preflyt-check https://your-deployed-url.com --key YOUR_LICENSE_KEY

Preflyt Security Scanner Data Schema & Taxonomy

Preflyt organizes scan results into severity levels and specific technical categories. The following structure outlines the data evaluated during a scan:

Category Items Scanned
Secrets .env, config.json, database passwords, API keys
Source Leakage .git folders, .svn, server.js, app.py, source maps
Databases Exposed ports for MySQL, Postgres, Redis, MongoDB
Security Headers HSTS, Content-Security-Policy, X-Frame-Options
Server Config Directory listings, server version leakage, insecure cookies

All results are displayed in the terminal by default to maintain privacy. If the --share flag is used, a temporary report is generated on preflyt.dev for team review.

Preflyt Security Scanner Advanced Features

  • CI/CD Integration: Automatically block deployments using the --fail flag if the scan detects vulnerabilities.
  • Shareable Reports: Generate secure, public links for 30 days to share findings with team members.
  • Pro License Support: Unlock unlimited scanning capabilities for high-frequency deployment environments.
  • Multi-Agent Automation: This Openclaw Skills component can be chained with deployment agents to provide a mandatory security gate for every code push.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*