Security Guardian for Openclaw

Automated security auditing system for detecting hardcoded secrets and container vulnerabilities in development projects.

1999azzar
v1.1.0
Feb 17, 2026
0
2.3k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install security-guardian

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install security-guardian using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Security Guardian?

Security Guardian is a specialized security auditing module designed to protect your codebase by identifying leaked credentials and infrastructure weaknesses. As a key component of Openclaw Skills, it provides developers with automated tools to scan for API keys, tokens, and other sensitive data, while also performing deep container vulnerability assessments using Trivy.

By integrating this skill into your workflow, you can ensure that security guardrails are enforced throughout the development lifecycle. It not only detects risks but also provides a structured path for remediation, such as moving plaintext secrets into secure managers like mema-vault.

Security Guardian Use Cases

  • Scanning project directories for leaked API keys, tokens, and hardcoded credentials.
  • Auditing Docker images for HIGH and CRITICAL vulnerabilities prior to deployment.
  • Automating security checks within a continuous integration pipeline for Openclaw Skills projects.
  • Enforcing credential isolation by migrating plaintext secrets to a dedicated vault.

How Security Guardian Works

  1. The user points the secret scanning tool at a specific project directory to search for patterns matching credentials.
  2. If findings are detected, the skill provides the exact file and line number for the leak.
  3. The developer is prompted to redact the secret and transition it to a secure environment variable or vault lookup.
  4. For infrastructure security, the skill triggers a shell script that utilizes Trivy to analyze container images.
  5. The system identifies vulnerabilities by severity, allowing the developer to apply patches or update base images.

Security Guardian Setup

To get started with this skill, ensure that Python 3 is installed and that Trivy is available on your host system for container analysis. This skill is optimized to work alongside other Openclaw Skills.

# Navigate to the skill directory
cd $WORKSPACE/skills/security-guardian

# Make the container scan script executable
chmod +x scripts/scan_container.sh

# Run a secret scan on your project
python3 scripts/scan_secrets.py /path/to/your/project

Security Guardian Data Schema & Taxonomy

The skill organizes security findings through script outputs and integrates with external vault schemas.

Feature Method Output
Secret Detection scan_secrets.py File paths and line numbers of suspected leaks
CVE Scanning scan_container.sh Vulnerability report highlighting severity levels
Vaulting mema-vault Secure reference keys for redacted secrets

Security Guardian Advanced Features

  • Direct integration with mema-vault for automated secret remediation and management.
  • High-severity filtering to prioritize critical vulnerabilities over low-impact issues.
  • Automated exit-code signaling to prevent insecure builds within the Openclaw Skills framework.
  • Customizable scanning scope to protect system directories while focusing on project code.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Requires
Github Stars: 0
forks: 0

Featured*