Agent skill

Clawdbot Self Security Audit

by sundial-org in sundial-org/awesome-openclaw-skills

Perform a comprehensive read-only security audit of Clawdbot's own configuration.

No licenceAuto-check passedSecurity

Install Clawdbot Self Security Audit

skills CLI
$ npx skills add sundial-org/awesome-openclaw-skills --skill clawdbot-self-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sundial-org/awesome-openclaw-skills clawdbot-self-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sundial-org/awesome-openclaw-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/clawdbot-self-security-audit .claude/skills/clawdbot-self-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clawdbot-self-security-audit
GitHub stars
663
Used in
1 other repo
Token cost
~4.4k tokens
SKILL.md length
1,307 words
Files
3
Skills in repo
383
Repo updated
First seen
Licence
None found

At a glance

Perform a comprehensive read-only security audit of Clawdbot's own configuration.

  • Works in 12 steps: Gateway Exposure 🔴 Critical → DM Policy Configuration 🟠 High → Group Access Control 🟠 High → …
  • User asks to run security check
  • SKILL.md covers Core Philosophy, Security Principles, Trust Hierarchy and Audit Commands, plus 6 more sections
  • Calls openssl, curl and git; reaches docs.clawd.bot and x.com; needs CLAWDBOT_GATEWAY_TOKEN

What it does

Clawdbot Self Security Audit is an agent skill from sundial-org/awesome-openclaw-skills. Perform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities across the system. Use when user asks to "run security check", "audit clawdbot", "check security hardening", or "what vulnerabilities does my Clawdbot have". This skill uses Clawdbot's internal capabilities and file system access to inspect configuration, detect misconfigurations, and recommend remediations. It is designed to be extensible -…

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `README.md` and `skill.json`).

It sits in Security, covering Security review. The repository describes itself as: Top OpenClaw skills, with the most popular and useful ones.

When your agent uses it

  • User asks to run security check
  • Check security hardening
  • What vulnerabilities does my Clawdbot have

Example prompts

  • “run security check”
  • “audit clawdbot”
  • “check security hardening”
  • “/clawdbot-self-security-audit”

Requirements

  • A credential in CLAWDBOT_GATEWAY_TOKEN

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Gateway Exposure 🔴 Critical
  2. DM Policy Configuration 🟠 High
  3. Group Access Control 🟠 High
  4. Credentials Security 🔴 Critical
  5. Browser Control Exposure 🟠 High
  6. Gateway Bind & Network Exposure 🟠 High
  7. Tool Access & Sandboxing 🟡 Medium
  8. File Permissions & Local Disk Hygiene 🟡 Medium
  9. Plugin Trust & Model Hygiene 🟡 Medium
  10. Logging & Redaction 🟡 Medium
  11. Prompt Injection Protection 🟡 Medium
  12. Dangerous Command Blocking 🟡 Medium

What it can do on your machine

Read from SKILL.md and the folder at commit b80cde2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl
    • curl
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • docs.clawd.bot
    • x.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CLAWDBOT_GATEWAY_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Clawdbot Self Security Audit loads about 4.4k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 1,307 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,307 words (~4,415 tokens).

“This skill empowers Clawdbot to audit its own security posture using first-principles reasoning. Rather than relying on a static script, Clawdbot learns the framework and applies it dynamically to detect vulnerabilities, understand their impact, and recommend specific remediations.”

— opening of SKILL.md by sundial-org
name
clawdbot-self-security-audit
homepage
https://github.com/TheSethRose/Clawdbot-Security-Check

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files in skills/clawdbot-self-security-audit of sundial-org/awesome-openclaw-skills.

  • SKILL.md
  • README.md
  • skill.json

Open the folder on GitHubat commit b80cde2

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sundial-org/awesome-openclaw-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Clawdbot Self Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clawdbot Self Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clawdbot Self Security Audit this skillsundial-org/awesome-openclaw-skills6631 repos~4.4kAutomated safety check: PassNone
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from sundial-org/awesome-openclaw-skills

All 383 skills in this repo
  • UI UX Pro Max

    sundial-org/awesome-openclaw-skills

    UI/UX design intelligence and implementation guidance for building polished interfaces.

    663 GitHub starsUsed in 2 repos~657 tokens
    Auto-check passed
  • Web Deploy GitHub

    sundial-org/awesome-openclaw-skills

    Create and deploy single-page static websites to GitHub Pages with autonomous workflow.

    663 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Clawd Modifier

    sundial-org/awesome-openclaw-skills

    Modify Clawd, the Claude Code mascot. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~625 tokensUpdated 7 mo ago
    Auto-check passed
  • Figma

    sundial-org/awesome-openclaw-skills

    Professional Figma design analysis and asset export. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~1.7k tokensUpdated 7 mo ago
    Auto-check: notes
  • Habit Flow

    sundial-org/awesome-openclaw-skills

    AI-powered atomic habit tracker with natural language logging, streak tracking, smart reminders, and coaching.

    663 GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed
  • Edge Tts

    sundial-org/awesome-openclaw-skills

    Text-to-speech conversion using node-edge-tts npm package for generating audio from text.

    663 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed

Categories

Questions about Clawdbot Self Security Audit

What does Clawdbot Self Security Audit do?

Perform a comprehensive read-only security audit of Clawdbot's own configuration. Clawdbot Self Security Audit is an agent skill from sundial-org/awesome-openclaw-skills. Perform a comprehensive read-only security audit of Clawdbot's own configuration.

When should I use Clawdbot Self Security Audit?

Clawdbot Self Security Audit fits situations like: user asks to run security check; check security hardening; what vulnerabilities does my Clawdbot have.

How do I install Clawdbot Self Security Audit in Claude Code?

Run `npx skills add sundial-org/awesome-openclaw-skills --skill clawdbot-self-security-audit -a claude-code`. Or copy the skill folder (skills/clawdbot-self-security-audit in sundial-org/awesome-openclaw-skills) into .claude/skills/clawdbot-self-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Clawdbot Self Security Audit in Codex?

Run `npx skills add sundial-org/awesome-openclaw-skills --skill clawdbot-self-security-audit -a codex`. Or copy the skill folder (skills/clawdbot-self-security-audit in sundial-org/awesome-openclaw-skills) into .agents/skills/clawdbot-self-security-audit in your project. Codex loads it when a task matches its description.

Can I use Clawdbot Self Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sundial-org/awesome-openclaw-skills --skill clawdbot-self-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clawdbot-self-security-audit, .gemini/skills/clawdbot-self-security-audit, .github/skills/clawdbot-self-security-audit and .opencode/skills/clawdbot-self-security-audit in your project.

What does Clawdbot Self Security Audit need to run?

Going by SKILL.md and its folder, Clawdbot Self Security Audit needs the command-line tools its instructions call (openssl, curl and git) and credentials named CLAWDBOT_GATEWAY_TOKEN. Our summary lists: A credential in CLAWDBOT_GATEWAY_TOKEN.

Does Clawdbot Self Security Audit access the network?

SKILL.md names 3 domains. In commands or code: docs.clawd.bot, x.com and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Clawdbot Self Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Clawdbot Self Security Audit use?

No licence was found for Clawdbot Self Security Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Clawdbot Self Security Audit use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Clawdbot Self Security Audit?

Skills that share tags, products or a category with Clawdbot Self Security Audit: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clawdbot Self Security Audit?

sundial-org (a GitHub organization) maintains it in sundial-org/awesome-openclaw-skills, which has 663 GitHub stars. The repository holds 383 skills in this directory. The repository was last updated on March 7, 2026.

Source: sundial-org/awesome-openclaw-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.