ClawdStrike

Audit OpenClaw gateway hosts for security vulnerabilities and configuration risks.

111|20|Updated Feb 9, 2026
One-click install
npx skills add https://github.com/profbernardoj/everclaw --skill clawdstrike
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ClawdStrike
Source: https://github.com/profbernardoj/everclaw/tree/main/security/clawdstrike
Command: npx skills add https://github.com/profbernardoj/everclaw --skill clawdstrike

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps you proactively identify and fix security vulnerabilities in your OpenClaw environment before attackers can exploit them.

Core Features & Use Cases

  • Comprehensive Security Audit: Checks for common attack vectors like malicious skills, exposed ports, weak policies, and plaintext secrets.
  • Actionable Fixes: Provides clear, safe instructions to remediate identified risks.
  • Use Case: Before deploying new skills or after a configuration change, run ClawdStrike to ensure your OpenClaw gateway and host are hardened against known threats, generating a detailed report with evidence.

Quick Start

Run the ClawdStrike security audit to verify your OpenClaw configuration.

Frequently Asked Questions about ClawdStrike

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an OpenClaw security audit and threat model on my gateway host?

You can secure your OpenClaw gateway by auditing its host environment and configuration against known compromise paths. The audit generates an OK/VULNERABLE report with evidence and fixes for identified risks.

What security vulnerabilities should I check for in an OpenClaw deployment?

When checking OpenClaw security vulnerabilities, you must look for malicious skills, open ports, exposed control UIs, weak tool policies, and plaintext secrets. Auditing these areas hardens your host against compromise.

When should I run a threat model and security audit on my OpenClaw configuration?

You should run an OpenClaw threat model and security audit before deploying new skills or after any configuration change. This proactive hardening verifies your gateway posture and catches risks introduced by the updates.

Can I audit plaintext secrets and weak tool policies in OpenClaw without external dependencies?

Yes, you can audit plaintext secrets and weak tool policies in OpenClaw without external dependencies. The audit uses built-in scripts and references to verify your environment and provide a detailed OK/VULNERABLE report.

What is the best way to harden an OpenClaw gateway against malicious skills?

The best way to harden an OpenClaw gateway against malicious skills is to run a comprehensive security audit. This identifies weak policies and exposed control UIs, providing clear, safe instructions to remediate the risks.