edgeone-clawscan

Audit OpenClaw environments for configuration, supply chain, and privacy risks.

4.4k|438|Updated Dec 25, 2024
One-click install
npx skills add https://github.com/Tencent/AI-Infra-Guard --skill edgeone-clawscan
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: edgeone-clawscan
Source: https://github.com/Tencent/AI-Infra-Guard/tree/main/ClawScan
Command: npx skills add https://github.com/Tencent/AI-Infra-Guard --skill edgeone-clawscan

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides comprehensive security scanning for your OpenClaw environment, identifying configuration risks, supply chain vulnerabilities, and potential privacy leaks.

Core Features & Use Cases

  • OpenClaw Security Scan: Performs a full system audit including configuration, installed skills, and known vulnerabilities.
  • Skill Security Scan: Audits individual skills for supply chain risks and malicious code.
  • Privacy Leakage Risk Assessment: Identifies potential privacy exposures within your OpenClaw setup.
  • Use Case: Before deploying new skills or after significant environment changes, run a full security scan to ensure your OpenClaw instance is robust against threats.

Quick Start

Run a comprehensive security health check for your OpenClaw environment.

Frequently Asked Questions about edgeone-clawscan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security scan on my OpenClaw environment?

To run an OpenClaw security scan, execute a comprehensive health check command to audit system configurations, installed skills, and known vulnerabilities. This process identifies supply chain risks and potential privacy leaks within your setup.

What does supply chain risk assessment for installed skills check for?

Supply chain risk assessment checks installed skills for malicious code and external vulnerabilities using API lookups. It evaluates installed skill packages to detect known CVE advisories and prevent risky software dependencies from compromising your environment.

When should I perform a privacy leakage risk assessment on my OpenClaw setup?

Perform a privacy leakage risk assessment before deploying new skills or after significant environment changes. This identifies potential data exposure vulnerabilities and configuration risks within your OpenClaw instance to ensure robust protection against threats.

Can I audit individual OpenClaw skills for known CVE vulnerabilities?

Yes, you can audit individual OpenClaw skills for known CVE vulnerabilities. The scan matches installed skills against known security advisories and external API databases to detect supply chain risks and identify malicious code patterns.

Does the OpenClaw security scan check for system misconfigurations?

Yes, the OpenClaw security scan includes built-in configuration checks to identify potential security misconfigurations. It performs a full system audit to ensure your environment is robust against threats and prevents data exposure vulnerabilities.

What is the best way to secure an OpenClaw environment against malicious skills?

The best way to secure an OpenClaw environment is running a comprehensive security scan that evaluates skill supply chain risks, matches known CVE vulnerabilities, and assesses local privacy leakage. This identifies malicious skills and configuration risks.