openclaw-security

Audit OpenClaw browser extension security for tab access and permissions.

Updated Feb 21, 2026
One-click install
npx skills add https://github.com/abzhaw/juliaz_agents --skill openclaw-security-abzhaw
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: openclaw-security
Source: https://github.com/abzhaw/juliaz_agents/tree/main/meta/agents/security-agent/skills/09-openclaw-security
Command: npx skills add https://github.com/abzhaw/juliaz_agents --skill openclaw-security-abzhaw

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audits the OpenClaw browser extension to identify tab access risks, confirm CDP exposure is controlled, and ensure skills do not have excessive permissions.

Core Features & Use Cases

  • Tab access auditing: lists attached tabs and flags sensitive sites (banking, email, personal accounts).
  • Permission and gateway review: analyzes skilled permissions, registered workspaces, and path access to detect potential overreach.
  • Use Case: Security teams can verify OpenClaw posture before deployment and after updates.

Quick Start

Run the OpenClaw security audit to scan current workspace registrations and tab activity.

Frequently Asked Questions about openclaw-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a browser extension security audit for tab access risks?

A browser extension security audit identifies tab access risks, CDP exposure, and permissions misuse. It enforces checks for tab scope, sensitive permissions, gateway mappings, and activity logs to detect risky configurations across workspaces.

How do I audit CDP exposure and permissions misuse in browser extensions?

You audit CDP exposure and permissions misuse by scanning workspace registrations, gateway configurations, and recent skill changes. This process checks tab scope and sensitive permissions to ensure minimal access and outputs a risk report with recommendations.

Can I use this security audit to check for sensitive site access on banking and email tabs?

Yes, the security audit can check for sensitive site access. It lists attached tabs and explicitly flags sensitive sites such as banking, email, and personal accounts to prevent unauthorized browser extension access.

When do I need to run a browser extension permissions review?

You need to run a browser extension permissions review before deployment and after updates. Security teams verify posture during these stages to detect potential overreach in skilled permissions, registered workspaces, and path access.

What is the best way to verify gateway mappings and workspace configurations for extensions?

The best way to verify gateway mappings is to analyze skilled permissions, registered workspaces, and path access. This detects potential overreach and ensures risky configurations are flagged in a comprehensive risk report.

Does this audit detect excessive permissions in recent skill changes?

Yes, the audit applies checks across recent skill changes to detect excessive permissions. It enforces reviews of sensitive permissions and activity logs to ensure skills do not overreach their required access scope.