Security Scanner for Openclaw

A professional security automation toolkit for penetration testing, service discovery, and vulnerability assessment across web apps and infrastructure.

dmx64
v1.0.0
Feb 10, 2026
4
12.4k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install security-scanner

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install security-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Security Scanner?

The Security Scanner skill is a comprehensive toolkit designed for automated penetration testing and vulnerability assessment. It empowers developers and security researchers to automate reconnaissance, service discovery, and vulnerability detection across various targets. By leveraging industry-standard tools like nmap and nuclei, this skill provides a structured approach to identifying security gaps before they can be exploited, making it a vital component of the Openclaw Skills ecosystem for maintaining robust infrastructure.

Security Scanner Use Cases

  • Conducting fast reconnaissance and host discovery on internal or external subnets.
  • Performing comprehensive full port scans and service version detection to map attack surfaces.
  • Identifying CVEs and common web vulnerabilities within applications automatically.
  • Analyzing SSL/TLS certificates and configurations for potential security weaknesses.
  • Generating structured security audit reports for compliance and remediation tracking.

How Security Scanner Works

  1. Initialize the scanning process by providing a target URL, IP address, or network range.
  2. Execute initial reconnaissance to discover live hosts and active services.
  3. Run targeted vulnerability templates using nuclei to detect specific CVEs and misconfigurations.
  4. Perform deep-dive analysis on SSL/TLS layers and web headers using specialized tools like sslscan and nikto.
  5. Consolidate all findings into a structured markdown report located in the reports directory.
  6. Review the prioritized recommendations to begin the remediation process within the Openclaw Skills framework.

Security Scanner Setup

Ensure that the necessary security binaries are installed on your host machine before using this skill.

# Install common security tools
sudo apt update && sudo apt install nmap nikto sslscan -y

# Install nuclei (via go or binary download)
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

Once the dependencies are met, you can trigger scans directly through your agent using the Openclaw Skills configuration.

Security Scanner Data Schema & Taxonomy

The skill organizes its findings into time-stamped reports to ensure auditability.

Report Component Details
File Path reports/security-scan-YYYY-MM-DD.md
Metadata Includes Target IP/URL and Scan Timestamp
Service Map Table of open ports, protocols, and detected service versions
Vulnerabilities List of findings categorized by severity (Critical, High, Medium, Low)
SSL Report Results of certificate validation and cipher suite analysis
Recommendations Actionable remediation steps for each identified vulnerability

Security Scanner Advanced Features

  • Multi-stage reconnaissance workflows that chain host discovery with deep service scanning.
  • Automated CVE detection using the most recent community-contributed nuclei templates.
  • Support for full-spectrum port scanning and OS fingerprinting to identify shadow IT.
  • Integration with specialized SSL analysis tools like testssl.sh for high-assurance environments.
  • Built-in ethical guardrails and best-practice prompts to ensure authorized testing within the Openclaw Skills ecosystem.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*