Agent skill

Openclaw Security Checker

by jd-opensource in jd-opensource/JoySafeter

OpenClaw 安全检测工具,基于安全实践指南验证配置安全、权限隔离、网络策略、日志审计和运行时完整性. An agent skill from jd-opensource/JoySafeter.

Apache-2.0Auto-check passedSecurity

Install Openclaw Security Checker

skills CLI
$ npx skills add jd-opensource/JoySafeter --skill openclaw-security-checker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jd-opensource/JoySafeter openclaw-security-checker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jd-opensource/JoySafeter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/openclaw-security-checker .claude/skills/openclaw-security-checker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openclaw-security-checker
GitHub stars
313
Token cost
~1.2k tokens
SKILL.md length
323 words
Files
3 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

OpenClaw 安全检测工具,基于安全实践指南验证配置安全、权限隔离、网络策略、日志审计和运行时完整性. An agent skill from jd-opensource/JoySafeter.

  • Works in 4 steps: 配置安全检查 → 权限与隔离检查 → 网络安全检查 → …
  • Security work in your project
  • SKILL.md covers Purpose, Prerequisites, Core Workflow and 检查项目详情, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Openclaw Security Checker is an agent skill from jd-opensource/JoySafeter. OpenClaw 安全检测工具,基于安全实践指南验证配置安全、权限隔离、网络策略、日志审计和运行时完整性

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/tools.md` and `references/workflows.md`).

It sits in Security. The repository describes itself as: 🚀 JoySafeter: An enterprise AI Agent Platform—Not just chatting. building、running、testing, and tracing autonomous Agent Teams with visual orchestration... The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/openclaw-security-checker”

Requirements

  • Docker

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 配置安全检查
  2. 权限与隔离检查
  3. 网络安全检查
  4. 日志审计检查

What it can do on your machine

Read from SKILL.md and the folder at commit 12234a1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openclaw Security Checker loads about 1.2k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 20 tokens; SKILL.md has 323 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jd-opensource/JoySafeter at commit 12234a1, republished under its Apache-2.0 licence (© jd-opensource). 323 words, ~1,179 tokens.

Download SKILL.mdSave it as .claude/skills/openclaw-security-checker/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
openclaw-security-checker
description
OpenClaw 安全检测工具,基于安全实践指南验证配置安全、权限隔离、网络策略、日志审计和运行时完整性
version
1.0.0
author
security-audit
homepage
https://docs.openclaw.ai/security
metadata.category
security
metadata.risk
safe

OpenClaw 安全检测器

基于《OpenClaw 极简安全实践指南》和《安全验证与攻防演练手册》的全面安全检测工具。对 OpenClaw 实例的配置、权限、隔离、网络、日志进行系统化审查,输出可量化的安全评分和修复建议。

Purpose

OpenClaw 实例运行在 Docker 容器中,每用户独占一个容器(JoySafeter 架构)。该技能负责对实例的安全面进行系统化检测,覆盖部署前配置审查、运行时权限验证、隔离区合规检查三个阶段。

Prerequisites

环境要求
  • OpenClaw 实例已部署并可访问(本地或容器内)
  • 对 ~/.openclaw/ 目录有读取权限
  • openclaw.json 配置文件可读
目标实例信息
  • OpenClaw 版本号(openclaw --version)
  • 部署模式:local / docker / kubernetes
  • Gateway 端口和绑定范围

Core Workflow

  1. 配置文件扫描: 解析 openclaw.json,检查 gateway 认证、绑定范围、工具权限、模型配置中的安全隐患。
  2. 凭证暴露检测: 扫描配置文件、环境变量、日志中是否存在明文 API Key、Token、密码。
  3. Gateway 安全审计: 验证 gateway 绑定地址、认证方式、CORS 白名单、trusted proxies 配置。
  4. 工具权限验证: 检查 tools.profile 设置,验证文件系统访问范围、命令执行权限、网络访问策略。
  5. 文件权限检查: 验证 ~/.openclaw/ 目录及关键文件的权限位,确保配置文件不可被其他用户读取。
  6. 隔离区合规检查: 扫描 _quarantine 目录,列出被隔离的技能及原因,验证隔离机制是否正常运作。
  7. 运行时完整性验证: 通过 SHA-256 哈希校验核心文件完整性,对比安装时的基线值。
  8. 日志审计分析: 检查最近操作日志中的可疑模式(大量失败请求、敏感操作、红线触发记录)。
  9. 网络策略检查: 验证出站网络请求白名单、DNS 解析范围、容器网络隔离状态。

检查项目详情

1. 配置安全检查
检查项风险等级检测规则扣分
API Key 明文暴露CRITICAL正则匹配 sk-*, key-*, token: 等模式-20
Gateway 绑定 0.0.0.0HIGH检查 gateway.bind 是否为 0.0.0.0 或 lan-10
工具权限设为 fullMEDIUMtools.profile === "full"-5
CORS 白名单过宽MEDIUMallowedOrigins 包含 *-5
认证 Token 弱强度HIGHToken 长度 < 32 或 entropy < 4.0-10
禁用设备认证HIGHdangerouslyDisableDeviceAuth: true-10
模型 context 过大LOWcontextWindow > 200000-2
未配置 TLSMEDIUMGateway 未启用 HTTPS-5
自动更新已禁用LOWupdate.checkOnStart: false-3
2. 权限与隔离检查
检查项风险等级检测规则扣分
配置文件权限过宽HIGHopenclaw.json 权限非 600/640-10
工作区目录权限MEDIUM/workspace/ 权限非 700/750-5
以 root 运行CRITICAL当前进程 UID == 0-20
文件系统未限制HIGHtools.fs.workspaceOnly: false-10
隔离区异常MEDIUM_quarantine 中存在未审查的技能-5
3. 网络安全检查
检查项风险等级检测规则扣分
trusted proxies 过宽MEDIUM包含 /8 大段网络-5
出站无白名单HIGH未配置出站网络限制-10
Gateway 暴露在公网CRITICAL端口可从容器外访问-15
4. 日志审计检查
检查项风险等级检测规则扣分
敏感操作无日志HIGH关键操作缺少审计记录-10
可疑操作模式MEDIUM短时间内大量异常请求-5
红线触发记录CRITICAL检测到已触发的安全红线-15
日志文件可写MEDIUM日志文件权限允许修改-5

安全评分体系

评分公式

基础分 100 分,每项检查根据风险等级扣分:

最终分 = max(0, 100 - Σ 扣分)
安全等级
等级分数范围含义建议操作
A90-100安全状态良好保持现有配置,定期复检
B80-89有少量警告建议在下次维护窗口修复
C70-79存在中等风险应在一周内修复
D60-69存在较大风险需要立即关注并修复
F0-59严重安全问题必须立即停止服务并修复

示例输出

╔══════════════════════════════════════╗
║      OpenClaw 安全检测报告          ║
╠══════════════════════════════════════╣
║ 实例: openclaw-a1b2c3d4             ║
║ 版本: 2026.3.11                     ║
║ 部署: Docker 容器                   ║
║ 检测时间: 2026-03-13 10:30:00 UTC   ║
╚══════════════════════════════════════╝

▶ 配置安全检查
  ✗ [HIGH] Gateway 绑定范围为 lan,建议收窄为 localhost
  ✗ [MEDIUM] tools.profile 设置为 full,建议使用 restricted
  ✗ [HIGH] dangerouslyDisableDeviceAuth 已启用
  ✓ API Key 未暴露
  ✓ 认证 Token 强度合格

▶ 权限与隔离检查
  ✓ 以 node 用户运行 (非 root)
  ✓ 配置文件权限正常 (600)
  ✗ [MEDIUM] /workspace/skills 目录权限为 755,建议 750

▶ 网络安全检查
  ✗ [MEDIUM] trusted proxies 包含 10.0.0.0/8 大段
  ✓ Gateway 仅容器内可达

▶ 日志审计检查
  ✓ 最近 24h 无可疑操作
  ✓ 无红线触发记录

╔══════════════════════════════════════╗
║ 安全评分: B (82/100)                ║
║ 严重问题: 0 | 高危: 2 | 警告: 3    ║
╠══════════════════════════════════════╣
║ 修复建议:                           ║
║ 1. 将 gateway.bind 改为 localhost   ║
║ 2. 启用设备认证                      ║
║ 3. 将 tools.profile 改为 restricted ║
╚══════════════════════════════════════╝

Tool Categories

CategoryToolsPurpose
配置解析jq, node (JSON parser)解析 openclaw.json 配置文件
凭证扫描grep, TruffleHog patterns检测明文密钥和 Token
权限检查stat, ls, id验证文件权限和运行用户
完整性校验sha256sum, openssl dgst核心文件哈希验证
网络检测ss, netstat, iptables端口绑定和网络策略检查
日志分析grep, jq, awk审计日志模式匹配

安全原则

  • 事前: 行为层黑名单 + 安全审计 + 配置基线
  • 事中: 权限收窄 + 哈希基线 + 运行时监控
  • 事后: 每晚自动巡检 + 显性化汇报 + 修复追踪

References

  • references/tools.md - 工具函数签名和参数说明
  • references/workflows.md - 检测流程定义和判定规则

© jd-opensource, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/openclaw-security-checker of jd-opensource/JoySafeter.

  • SKILL.md
  • references/tools.md
  • references/workflows.md

Open the folder on GitHubat commit 12234a1

Compare with similar skills

Openclaw Security Checker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openclaw Security Checker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openclaw Security Checker this skilljd-opensource/JoySafeter313—~1.2kAutomated safety check: PassApache-2.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from jd-opensource/JoySafeter

  • Planning With Files

    jd-opensource/JoySafeter

    Implements Manus-style file-based planning for complex tasks.

    313 GitHub starsUsed in 19 repos~1.8k tokens
    Auto-check: notes
  • Openclaw Threat Detect

    jd-opensource/JoySafeter

    OpenClaw 攻击模式检测工具,识别数据外传、反弹Shell、文件泄露、Prompt注入、供应链投毒等高危行为,支持 MITRE ATT&CK 映射

    313 GitHub stars~1.3k tokensUpdated 29 days ago
    Auto-check: warnings

Categories

Questions about Openclaw Security Checker

What does Openclaw Security Checker do?

OpenClaw 安全检测工具,基于安全实践指南验证配置安全、权限隔离、网络策略、日志审计和运行时完整性. An agent skill from jd-opensource/JoySafeter. Openclaw Security Checker is an agent skill from jd-opensource/JoySafeter.

When should I use Openclaw Security Checker?

Openclaw Security Checker fits situations like: security work in your project.

How do I install Openclaw Security Checker in Claude Code?

Run `npx skills add jd-opensource/JoySafeter --skill openclaw-security-checker -a claude-code`. Or copy the skill folder (skills/openclaw-security-checker in jd-opensource/JoySafeter) into .claude/skills/openclaw-security-checker in your project. Claude Code loads it when a task matches its description.

How do I install Openclaw Security Checker in Codex?

Run `npx skills add jd-opensource/JoySafeter --skill openclaw-security-checker -a codex`. Or copy the skill folder (skills/openclaw-security-checker in jd-opensource/JoySafeter) into .agents/skills/openclaw-security-checker in your project. Codex loads it when a task matches its description.

Can I use Openclaw Security Checker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jd-opensource/JoySafeter --skill openclaw-security-checker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openclaw-security-checker, .gemini/skills/openclaw-security-checker, .github/skills/openclaw-security-checker and .opencode/skills/openclaw-security-checker in your project.

What does Openclaw Security Checker need to run?

SKILL.md names no scripts, command-line tools or credentials: Openclaw Security Checker is instructions for the agent only. Our summary lists: Docker.

Does Openclaw Security Checker access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Openclaw Security Checker safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openclaw Security Checker use?

Openclaw Security Checker is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openclaw Security Checker use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Openclaw Security Checker?

Skills that share tags, products or a category with Openclaw Security Checker: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openclaw Security Checker?

jd-opensource (a GitHub organization) maintains it in jd-opensource/JoySafeter, which has 313 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 9, 2026.

Source: jd-opensource/JoySafeter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.