What problem does it solve? Hosts running OpenClaw often ship with weak firewall, SSH, and update configurations, and users lack a structured way to assess exposure and apply hardening without locking themselves out. ## Core Features & Use Cases - Read-only security audits: Runs openclaw security audit --deep, port scans, firewall checks, and backup/encryption status checks to build a posture summary. - Risk-profile-based remediation: Produces a step-by-step hardening plan with exact commands, rollback strategy, and explicit approval gates for every state-changing action. - Scheduled monitoring: Sets up recurring audits and update checks via openclaw cron with stable job names like healthcheck:security-audit. - Use Case: A user running OpenClaw on a VPS asks for a security review; the skill audits listening ports and SSH config, proposes a deny-by-default firewall plan, and schedules weekly audits after approval. ## Quick Start Ask the agent to run a security healthcheck on this machine and harden it to a balanced home workstation profile.