Agent skill

Openclaw Deployment Hardening

by BagelHole in BagelHole/DevOps-Security-Agent-Skills

Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification.

MITAuto-check passedDevOps & Cloud

Install Openclaw Deployment Hardening

skills CLI
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill openclaw-deployment-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BagelHole/DevOps-Security-Agent-Skills openclaw-deployment-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/hardening/openclaw-deployment-hardening .claude/skills/openclaw-deployment-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openclaw-deployment-hardening
GitHub stars
1.2k
Token cost
~822 tokens
SKILL.md length
296 words
Files
1
Skills in repo
44
Repo updated
First seen
Licence
MIT

At a glance

Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification.

  • Works in 5 steps: Dependency and lockfile vulnerability… → Image scan for OS/package vulnerabilities. → Secret scanning across source and build… → …
  • Shipping OpenClaw with Docker
  • SKILL.md covers Enforce a Secure Build Pipeline, Lock Down Container Runtime, Gate Production Promotion and Protect Data and Session…, plus 3 more sections
  • Calls kubectl, npm and trivy

What it does

Openclaw Deployment Hardening is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification. Use when shipping OpenClaw with Docker, Kubernetes, or automated release pipelines.

Its SKILL.md is about 820 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment, CI/CD and Container orchestration. It works with Kubernetes and Docker. The repository describes itself as: Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container… The licence is MIT.

When your agent uses it

  • Shipping OpenClaw with Docker
  • Automated release pipelines

Example prompts

  • “/openclaw-deployment-hardening”

Requirements

  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Dependency and lockfile vulnerability scan (fail on critical CVEs).
  2. Image scan for OS/package vulnerabilities.
  3. Secret scanning across source and build context.
  4. SBOM generation and artifact signing.
  5. Policy check that blocks deploy when controls fail.

What it can do on your machine

Read from SKILL.md and the folder at commit 0365f57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • npm
    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openclaw Deployment Hardening loads about 822 tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 296 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~822

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BagelHole/DevOps-Security-Agent-Skills at commit 0365f57, republished under its MIT licence (© BagelHole). 296 words, ~822 tokens.

Download SKILL.mdSave it as .claude/skills/openclaw-deployment-hardening/SKILL.md (or your agent's skills folder).
name
openclaw-deployment-hardening
description
Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification. Use when shipping OpenClaw with Docker, Kubernetes, or automated release pipelines.
license
MIT
metadata.author
devops-skills
metadata.version
1.0

OpenClaw Deployment Hardening

Use this skill to add repeatable security gates around OpenClaw build and deployment workflows.

Enforce a Secure Build Pipeline

Add mandatory controls to CI before artifacts are promoted:

  1. Dependency and lockfile vulnerability scan (fail on critical CVEs).
  2. Image scan for OS/package vulnerabilities.
  3. Secret scanning across source and build context.
  4. SBOM generation and artifact signing.
  5. Policy check that blocks deploy when controls fail.

Example CI step order:

bash
# Build
npm ci
npm run build

# Security gates
trivy fs .
trivy image my-registry/openclaw:${GIT_SHA}
syft my-registry/openclaw:${GIT_SHA} -o spdx-json > sbom.json
cosign sign --key cosign.key my-registry/openclaw:${GIT_SHA}

Lock Down Container Runtime

Run OpenClaw with restrictive defaults:

  • Non-root user in container
  • Read-only root filesystem where possible
  • Drop all Linux capabilities, add back only required
  • no-new-privileges enabled
  • Constrained CPU/memory limits to reduce abuse impact
  • Seccomp/AppArmor (or equivalent) profile enforced

Kubernetes-oriented expectations:

  • runAsNonRoot: true
  • allowPrivilegeEscalation: false
  • readOnlyRootFilesystem: true
  • network policy deny-all baseline with explicit allow rules

Gate Production Promotion

Require explicit promotion checks:

  • Security sign-off on CVE exceptions.
  • Signed artifact verification in deployment stage.
  • Drift check between expected and live manifest values.
  • Deployment only from immutable tags or digests.

Avoid mutable latest tags for production OpenClaw services.

Protect Data and Session Surfaces

  • Minimize prompt/response retention by policy.
  • Mask secrets and PII in logs before shipping to SIEM.
  • Encrypt persistent volumes and backups.
  • Isolate tenant/session data boundaries when serving multiple teams.

Post-Deploy Verification

Run a hardening smoke test immediately after rollout:

bash
kubectl get pods -n openclaw
kubectl auth can-i --as=system:serviceaccount:openclaw:default list secrets -n openclaw
kubectl get networkpolicy -n openclaw
kubectl logs deploy/openclaw -n openclaw --tail=200

Verify:

  • Pod security context matches policy.
  • Service account permissions are least privilege.
  • Ingress auth/rate limits are effective.
  • No plaintext secrets appear in logs.

Incident-Ready Rollback Pattern

Maintain a hardened rollback workflow:

  1. Freeze further rollouts.
  2. Revoke suspect tokens and rotate secrets.
  3. Roll back to last signed known-good image digest.
  4. Re-run post-deploy hardening verification.
  5. Capture timeline and artifacts for forensics.

© BagelHole, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in security/hardening/openclaw-deployment-hardening of BagelHole/DevOps-Security-Agent-Skills.

Open the folder on GitHubat commit 0365f57

Compare with similar skills

Openclaw Deployment Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openclaw Deployment Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openclaw Deployment Hardening this skillBagelHole/DevOps-Security-Agent-Skills1.2k—~822Automated safety check: PassMIT
Gem Devops Guidelinesgithub/awesome-copilot40k1 repos~743Automated safety check: PassMIT
Devops Excellencemajiayu000/spellbook287—~2.4kAutomated safety check: NotesMIT
Devops Deploymentyonatangross/orchestkit292—~2.7kAutomated safety check: PassMIT
Deployment EngineerDokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI508—~225Automated safety check: PassCustom licence
Maintainx Deploy Integrationjeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: NotesMIT

Similar skills

  • Gem Devops Guidelines

    github/awesome-copilot

    Official

    Design or review infrastructure, deployment, CI/CD, Docker, Kubernetes, health checks, rollback, feature flags, production readiness, and mobile release workflows.

    40k GitHub starsUsed in 1 repo~743 tokens
    DevOps & CloudAuto-check passed
  • Devops Excellence

    majiayu000/spellbook

    DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.

    287 GitHub stars~2.4k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Devops Deployment

    yonatangross/orchestkit

    A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.

    292 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Deployment Engineer

    Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI

    MASTER DEPLOY: CI/CD Pipelines, Docker, K8s, GitOps. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI.

    508 GitHub stars~225 tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Maintainx Deploy Integration

    jeremylongshore/tons-of-skills-marketplace

    Deploy MaintainX integrations to production environments. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Deployment Automation

    aiskillstore/marketplace

    Automate application deployment to cloud platforms and servers.

    433 GitHub starsUsed in 1 repo~3k tokens
    DevOps & CloudAuto-check: notes

More from BagelHole/DevOps-Security-Agent-Skills

All 44 skills in this repo
  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Incident Response

    BagelHole/DevOps-Security-Agent-Skills

    Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~4.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Kubernetes Ops

    BagelHole/DevOps-Security-Agent-Skills

    Deploy, scale, and manage Kubernetes workloads. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~2.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Linux Hardening

    BagelHole/DevOps-Security-Agent-Skills

    Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~662 tokensUpdated 4 mo ago
    Auto-check: notes
  • Prometheus Grafana

    BagelHole/DevOps-Security-Agent-Skills

    Set up metrics collection and visualization with Prometheus and Grafana.

    1.2k GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Vulnerability Scanning

    BagelHole/DevOps-Security-Agent-Skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    1.2k GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Openclaw Deployment Hardening

What does Openclaw Deployment Hardening do?

Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification. Openclaw Deployment Hardening is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification.

When should I use Openclaw Deployment Hardening?

Openclaw Deployment Hardening fits situations like: shipping OpenClaw with Docker; automated release pipelines.

How do I install Openclaw Deployment Hardening in Claude Code?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill openclaw-deployment-hardening -a claude-code`. Or copy the skill folder (security/hardening/openclaw-deployment-hardening in BagelHole/DevOps-Security-Agent-Skills) into .claude/skills/openclaw-deployment-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Openclaw Deployment Hardening in Codex?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill openclaw-deployment-hardening -a codex`. Or copy the skill folder (security/hardening/openclaw-deployment-hardening in BagelHole/DevOps-Security-Agent-Skills) into .agents/skills/openclaw-deployment-hardening in your project. Codex loads it when a task matches its description.

Can I use Openclaw Deployment Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill openclaw-deployment-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openclaw-deployment-hardening, .gemini/skills/openclaw-deployment-hardening, .github/skills/openclaw-deployment-hardening and .opencode/skills/openclaw-deployment-hardening in your project.

What does Openclaw Deployment Hardening need to run?

Going by SKILL.md and its folder, Openclaw Deployment Hardening needs the command-line tools its instructions call (kubectl, npm and trivy). Our summary lists: Docker.

Does Openclaw Deployment Hardening access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Openclaw Deployment Hardening safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openclaw Deployment Hardening use?

Openclaw Deployment Hardening is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openclaw Deployment Hardening use?

About 822 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openclaw Deployment Hardening?

Skills that share tags, products or a category with Openclaw Deployment Hardening: Gem Devops Guidelines (github/awesome-copilot, 40k stars), Devops Excellence (majiayu000/spellbook, 287 stars), Devops Deployment (yonatangross/orchestkit, 292 stars) and Deployment Engineer (Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI, 508 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openclaw Deployment Hardening?

BagelHole (a GitHub user) maintains it in BagelHole/DevOps-Security-Agent-Skills, which has 1,152 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on May 22, 2026.

Source: BagelHole/DevOps-Security-Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.