Automated security auditing system for detecting hardcoded secrets and container vulnerabilities in development projects.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install security-guardian
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install security-guardian using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Security Guardian is a specialized security auditing module designed to protect your codebase by identifying leaked credentials and infrastructure weaknesses. As a key component of Openclaw Skills, it provides developers with automated tools to scan for API keys, tokens, and other sensitive data, while also performing deep container vulnerability assessments using Trivy.
By integrating this skill into your workflow, you can ensure that security guardrails are enforced throughout the development lifecycle. It not only detects risks but also provides a structured path for remediation, such as moving plaintext secrets into secure managers like mema-vault.
To get started with this skill, ensure that Python 3 is installed and that Trivy is available on your host system for container analysis. This skill is optimized to work alongside other Openclaw Skills.
# Navigate to the skill directory
cd $WORKSPACE/skills/security-guardian
# Make the container scan script executable
chmod +x scripts/scan_container.sh
# Run a secret scan on your project
python3 scripts/scan_secrets.py /path/to/your/project
The skill organizes security findings through script outputs and integrates with external vault schemas.
| Feature | Method | Output |
|---|---|---|
| Secret Detection | scan_secrets.py | File paths and line numbers of suspected leaks |
| CVE Scanning | scan_container.sh | Vulnerability report highlighting severity levels |
| Vaulting | mema-vault | Secure reference keys for redacted secrets |
Loading
An industrial-grade search aggregator that combines multiple data providers into a single, sanitized, and structured JSON output.

A powerful management and monitoring skill for local Pi-hole instances that provides deep insights and control via CLI and FTL database queries.

A powerful management tool for Node-RED instances that enables automated flow deployment, node management, and runtime diagnostics via a streamlined CLI.

An automated command-line tool for running Postman collections to enable seamless API testing and reporting.

Generate high-quality AI images using SDXL and Stable Diffusion 3 directly through your command line or agent workflow.

A high-level technical lead skill for designing scalable software architectures and enforcing industry-standard code quality.








































