ClawdStrike

Audit OpenClaw gateway hosts for security vulnerabilities and generate OK/VULNERABLE reports.

Updated Feb 11, 2026
One-click install
npx skills add https://github.com/storyclaw-official/storyclaw-assistant --skill clawdstrike-storyclaw-official
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ClawdStrike
Source: https://github.com/storyclaw-official/storyclaw-assistant/tree/main/skills/clawdstrike
Command: npx skills add https://github.com/storyclaw-official/storyclaw-assistant --skill clawdstrike-storyclaw-official

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill identifies and mitigates security vulnerabilities within your OpenClaw deployment, ensuring the integrity and safety of your personal AI assistant.

Core Features & Use Cases

  • Security Auditing: Performs a comprehensive audit of your OpenClaw gateway, checking for misconfigurations, exposure risks, and potential attack vectors.
  • Threat Modeling: Generates a clear threat model specific to your OpenClaw setup.
  • Vulnerability Reporting: Produces a deterministic OK/VULNERABLE report with severity, evidence, and actionable fixes.
  • Use Case: Regularly audit your OpenClaw gateway to ensure it's not inadvertently exposing sensitive data or providing an easy entry point for attackers, especially after adding new skills or changing network configurations.

Quick Start

Run the ClawdStrike skill to audit your OpenClaw gateway for security vulnerabilities.

Frequently Asked Questions about ClawdStrike

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit on my OpenClaw gateway?

A security audit for OpenClaw checks gateway configurations, exposure risks, filesystem hygiene, and installed skills to produce an OK or VULNERABLE report with evidence and actionable fixes.

What is threat modeling for an AI gateway and when do I need it?

Threat modeling for an AI gateway identifies potential attack vectors and misconfigurations specific to your setup. You need it after adding new skills or changing network configurations to ensure you are not exposing sensitive data.

How does the audit ensure no secrets are exposed during the security check?

The audit ensures no secrets are exposed by operating under strict safety rules, including verified mode, command allowlisting, and a strict no exfiltration policy during the entire security check process.

Can I audit my OpenClaw deployment after installing new skills?

Yes, you can and should audit your OpenClaw deployment after installing new skills. The audit verifies filesystem hygiene and checks if new skills inadvertently create attack vectors or expose sensitive data.

What is included in the vulnerability report for OpenClaw?

The vulnerability report for OpenClaw includes a deterministic OK or VULNERABLE status, severity levels, evidence of found issues, and actionable fixes to mitigate identified security threats.