Privacy Scanner for Openclaw

A pre-publication security tool that scans your codebase for sensitive data and private credentials to prevent accidental leaks.

m17y
v1.1.0
Mar 7, 2026
0
846
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install privacy-scanner

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install privacy-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Privacy Scanner?

The Privacy Scanner is an essential security utility designed for developers using Openclaw Skills. It acts as a automated gatekeeper, scanning your skill directory or codebase for 20 types of sensitive information, including API keys, internal IP addresses, and private tokens. By integrating this into your workflow, you ensure that no private data is accidentally leaked when publishing to ClawHub or other public repositories, maintaining high security standards for all your Openclaw Skills projects.

Privacy Scanner Use Cases

  • Scan codebases before pushing to public GitHub repositories or ClawHub.
  • Detect hardcoded API keys from providers like OpenAI, Anthropic, or Stripe.
  • Identify accidental exposure of internal network configurations and IP addresses.
  • Audit environment variables and sensitive files like .env or SSH private keys.
  • Ensure compliance with publishing protocols for Openclaw Skills.

How Privacy Scanner Works

  1. The user triggers the privacy-scan.sh script within the target Openclaw Skills directory.
  2. The scanner parses the codebase against 20 predefined security patterns using optimized regex.
  3. The tool automatically skips non-essential directories like node_modules, .git, and binary files to ensure performance.
  4. A report is generated categorizing findings as Pass (✅), Warning (⚠️ for potential placeholders), or Failure (❌ for confirmed sensitive data).
  5. In strict mode, the process terminates with a non-zero exit code if high-severity issues are found, preventing unsafe deployments.

Privacy Scanner Setup

To use this tool with your Openclaw Skills, run the script via bash. You can scan the current directory or specify a target path.

# Scan the current directory
bash ~/.openclaw/skills/privacy-scanner/scripts/privacy-scan.sh

# Or scan a specific skill directory
bash ~/.openclaw/skills/privacy-scanner/scripts/privacy-scan.sh ~/.openclaw/skills/my-skill

# Run in strict mode for CI/CD pipelines
bash ~/.openclaw/skills/privacy-scanner/scripts/privacy-scan.sh --strict /path/to/skill

Privacy Scanner Data Schema & Taxonomy

The scanner organizes findings by severity and category. Below is the metadata taxonomy used by the skill:

Category Detection Content Severity
Webhooks Feishu, Discord, Slack Webhook URLs Critical
Credentials API Keys (sk-, ghp_), Bearer Tokens, JWT Critical
Infrastructure Internal/Public IPs, Database Connections High
Personal Data Phone numbers, Email addresses, Hostnames Warning
Files .env, credentials.json, SSH Private Keys Critical

Privacy Scanner Advanced Features

  • Strict mode for automated pipeline integration and zero-tolerance security enforcement.
  • Intelligent path exclusion for node_modules, .git, backups, and various binary file formats.
  • Comprehensive support for 20 distinct sensitive data patterns including platform-specific IDs (Feishu, Discord, Telegram).
  • Native integration with the ClawHub publishing workflow to maintain the integrity of the Openclaw Skills ecosystem.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*