Security Analysis for Openclaw

A professional security auditing tool designed to identify vulnerabilities, instruction injections, and data exfiltration risks within codebases and agent configurations.

kylehuan
v1.0.0
Feb 5, 2026
1
3.5k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install skill-security-audit

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install skill-security-audit using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Security Analysis?

The Security Analysis skill is a specialized utility for Openclaw Skills designed to perform deep security audits and vulnerability assessments. It enables AI agents to systematically scan source code for critical flaws such as injection vulnerabilities, broken access control, and hardcoded secrets.

By adhering to the principle of least privilege and assuming all external input is malicious, this skill ensures that security reviews are both thorough and safe. It provides a robust layer of defense for modern development workflows by identifying not just standard code vulnerabilities, but also agent-specific threats like instruction injection and hidden malicious directives.

Security Analysis Use Cases

  • Performing SAST (Static Application Security Testing) on new or existing codebases to identify flaws.
  • Auditing Openclaw Skills files for instruction injection, social engineering attempts, or hidden malicious commands.
  • Identifying sensitive data leaks including hardcoded API keys, tokens, or private credentials.
  • Evaluating LLM safety parameters to prevent prompt injection and unauthorized data exfiltration.
  • Reviewing access control logic to prevent IDOR vulnerabilities and unauthorized privilege escalation.

How Security Analysis Works

  1. The user triggers the process by explicitly requesting a security analysis or code review.
  2. The agent utilizes read-only operations to scan the codebase without modifying any source files.
  3. The skill evaluates the code and configuration files against a comprehensive checklist covering injection, privacy, and safety threats.
  4. Vulnerabilities are categorized by severity—Critical, High, Medium, or Low—based on their potential impact.
  5. A structured high-fidelity report is generated, with all artifacts stored in a dedicated security directory.

Security Analysis Setup

To enable security auditing within your Openclaw Skills environment, ensure the security-analysis skill is correctly referenced in your agent configuration. You can initiate a scan by targeting a specific directory:

# Example command to trigger a security review
openclaw run security-analysis --path ./src

The tool requires read permissions for the target files. All analysis artifacts and reports will be saved to the .shield_security/ directory automatically.

Security Analysis Data Schema & Taxonomy

The skill organizes its findings into a structured taxonomy to ensure clarity and actionable insights.

Field Description
Vulnerability The brief name and type of the security flaw
Severity Impact rating (Critical to Low) based on the severity rubric
Location Precise file path and line numbers where the issue exists
Content The specific code snippet or instruction that is vulnerable
Recommendation A detailed explanation of how to remediate the identified risk

Technical artifacts and logs are maintained within the .shield_security/ folder to isolate security data from the main project source.

Security Analysis Advanced Features

  • Targeted detection for LLM-specific vulnerabilities such as instruction overrides and deceptive social engineering prompts.
  • Strict high-fidelity reporting rules that filter out hypothetical weaknesses to focus on executable, high-impact risks.
  • Automated privacy violation tracking that follows data flow from sensitive sources to external sinks.
  • Specialized checklist for reviewing Openclaw Skills to ensure agent instructions do not bypass system safety guidelines.
  • Support for identifying complex injection attacks including SSRF, XSS, and SQLi within AI-generated workflows.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*