Agent skill

Security Guide

by jnMetaCode in jnMetaCode/shellward

OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation

Apache-2.0Auto-check: warningsSecurity

Install Security Guide

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add jnMetaCode/shellward --skill security-guide -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jnMetaCode/shellward security-guide --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jnMetaCode/shellward.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-guide .claude/skills/security-guide && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-guide
GitHub stars
140
Token cost
~644 tokens
SKILL.md length
292 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation

  • Works in 6 steps: Network Control / 网络控制 → Container Isolation / 容器隔离 → Credential Management / 凭证管理 → …
  • Tasks that involve Prompt injection and agent security
  • SKILL.md covers Security Checklist, Available Commands and Response Style
  • Calls docker

What it does

Security Guide is an agent skill from jnMetaCode/shellward. OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation

Its SKILL.md is about 640 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Prompt injection and agent security, Deployment and LLM guardrails. It works with Model Context Protocol and LangChain. The repository describes itself as: AI 应用合规网关 · 一行命令体检 AI 项目的「数据出境 / 硬编码密钥 / 个人信息暴露」(网安法·PIPL·等保2.0·数据出境·AI标识),并给出境内模型替代建议;可作运行时防护拦截注入与数据外泄 · 中文优先 · 零依赖 · 开源. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Prompt injection and agent security
  • Tasks that involve Deployment
  • Tasks that involve LLM guardrails

Example prompts

  • “/security-guide”

Requirements

  • Node.js
  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Network Control / 网络控制
  2. Container Isolation / 容器隔离
  3. Credential Management / 凭证管理
  4. Audit Logging / 审计日志
  5. Plugin Security / 插件安全
  6. Patch Management / 补丁管理

What it can do on your machine

Read from SKILL.md and the folder at commit 78444dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Guide loads about 644 tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 292 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~644

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteMentions a .env fileSKILL.md:32
    - Scan for plaintext secrets in .env, .bashrc, environment variables
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:35
    - Suggest `chmod 600 ~/.env ~/.ssh/* ~/.aws/credentials`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jnMetaCode/shellward at commit 78444dd, republished under its Apache-2.0 licence (© jnMetaCode). 292 words, ~644 tokens.

Download SKILL.mdSave it as .claude/skills/security-guide/SKILL.md (or your agent's skills folder).
name
security-guide
description
OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation
user-invocable
true
disable-model-invocation
false

ShellWard Security Deployment Guide / 安全部署指南

When the user invokes this skill, provide a complete security deployment checklist based on the following best practices. Check the current system state using available tools and give actionable recommendations.

Security Checklist

1. Network Control / 网络控制
  • Check if OpenClaw gateway port (19000/19001) is exposed to public network
  • Recommend binding to 127.0.0.1 or using a reverse proxy with authentication
  • Suggest firewall rules: ufw allow from 127.0.0.1 to any port 19000
  • For cloud servers: check security group rules
2. Container Isolation / 容器隔离
  • Recommend running OpenClaw in Docker with restricted capabilities:
    docker run --cap-drop=ALL --cap-add=NET_BIND_SERVICE \
      --read-only --tmpfs /tmp \
      -u 1000:1000 \
      openclaw
  • Suggest resource limits: --memory=2g --cpus=1
  • Mount only necessary directories
3. Credential Management / 凭证管理
  • Scan for plaintext secrets in .env, .bashrc, environment variables
  • Recommend using a secret manager (Vault, doppler, etc.)
  • Check file permissions on sensitive files (should be 0600)
  • Suggest chmod 600 ~/.env ~/.ssh/* ~/.aws/credentials
4. Audit Logging / 审计日志
  • Verify ShellWard audit log is active at ~/.openclaw/shellward/audit.jsonl
  • Show recent security events
  • Recommend log rotation and backup strategy
  • Suggest sending critical events to external SIEM
5. Plugin Security / 插件安全
  • List all installed plugins and check for known risks
  • Disable auto-update for plugins
  • Only install from trusted sources
  • Scan plugin code for suspicious patterns
6. Patch Management / 补丁管理
  • Check current OpenClaw version
  • Report known vulnerabilities for current version
  • Recommend upgrade path
  • Check Node.js version (must be >= 22.12)

Available Commands

Remind the user about ShellWard's quick commands:

  • /security — Full security status overview
  • /audit [count] [filter] — View audit log
  • /harden — Scan for issues, /harden fix to auto-fix
  • /scan-plugins — Scan plugins for security risks
  • /check-updates — Check versions and vulnerabilities

Response Style

  • Be concise and actionable
  • Use the user's language (detect from their message)
  • Prioritize critical issues first
  • For each issue, provide the exact command to fix it
  • Ask for confirmation before executing destructive operations

© jnMetaCode, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-guide of jnMetaCode/shellward.

Open the folder on GitHubat commit 78444dd

Compare with similar skills

Security Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Guide this skilljnMetaCode/shellward140—~644Automated safety check: WarnApache-2.0
Moai Ref LLM Securitymodu-ai/moai-adk1.2k—~4.5kAutomated safety check: PassApache-2.0
Reins Runtime Securitypegasi-ai/reins392—~1.4kAutomated safety check: WarnApache-2.0
PolygraphBankrBot/skills1.2k—~3.4kAutomated safety check: PassNone
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
AI SAFE2 Secure Build CopilotCyberStrategyInstitute/ai-safe2-framework146—~2.7kAutomated safety check: PassCustom licence

Similar skills

  • Moai Ref LLM Security

    modu-ai/moai-adk

    AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and…

    1.2k GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • Reins Runtime Security

    pegasi-ai/reins

    Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.

    392 GitHub stars~1.4k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings
  • Polygraph

    BankrBot/skills

    Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.

    1.2k GitHub stars~3.4k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure.

    146 GitHub stars~2.7k tokensUpdated today
    SecurityAuto-check passed
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes

More from jnMetaCode/shellward

  • China AI Compliance Audit

    jnMetaCode/shellward

    按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…

    140 GitHub stars~1.1k tokensUpdated 9 days ago
    Auto-check passed

Questions about Security Guide

What does Security Guide do?

OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation. Security Guide is an agent skill from jnMetaCode/shellward.

When should I use Security Guide?

Security Guide fits situations like: tasks that involve Prompt injection and agent security; tasks that involve Deployment; tasks that involve LLM guardrails.

How do I install Security Guide in Claude Code?

Run `npx skills add jnMetaCode/shellward --skill security-guide -a claude-code`. Or copy the skill folder (skills/security-guide in jnMetaCode/shellward) into .claude/skills/security-guide in your project. Claude Code loads it when a task matches its description.

How do I install Security Guide in Codex?

Run `npx skills add jnMetaCode/shellward --skill security-guide -a codex`. Or copy the skill folder (skills/security-guide in jnMetaCode/shellward) into .agents/skills/security-guide in your project. Codex loads it when a task matches its description.

Can I use Security Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jnMetaCode/shellward --skill security-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-guide, .gemini/skills/security-guide, .github/skills/security-guide and .opencode/skills/security-guide in your project.

What does Security Guide need to run?

Going by SKILL.md and its folder, Security Guide needs the command-line tools its instructions call (docker). Our summary lists: Node.js; Docker.

Does Security Guide access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Guide safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Security Guide use?

Security Guide is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Guide use?

About 644 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Guide?

Skills that share tags, products or a category with Security Guide: Moai Ref LLM Security (modu-ai/moai-adk, 1.2k stars), Reins Runtime Security (pegasi-ai/reins, 392 stars), Polygraph (BankrBot/skills, 1.2k stars) and Forensify (alexgreensh/repo-forensics, 188 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Guide?

jnMetaCode (a GitHub user) maintains it in jnMetaCode/shellward, which has 140 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 28, 2026.

Source: jnMetaCode/shellward on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.