Agent skill

Openclaw Deployment Hardening

by sickn33 in sickn33/agentic-awesome-skills

Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification.

MITAuto-check passedDevOps & Cloud

Install Openclaw Deployment Hardening

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill openclaw-deployment-hardening -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills openclaw-deployment-hardening --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/openclaw-deployment-hardening .claude/skills/openclaw-deployment-hardening && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openclaw-deployment-hardening
GitHub stars
47k
Used in
1 other repo
Token cost
~1.1k tokens
SKILL.md length
367 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification.

  • Works in 5 steps: Dependency and lockfile vulnerability… → Image scan for OS/package vulnerabilities. → Secret scanning across source and build… → …
  • Tasks that involve Deployment
  • SKILL.md covers Enforce a Secure Build Pipeline, Lock Down Container Runtime, Gate Production Promotion and Protect Data and Session…, plus 5 more sections
  • Calls kubectl, npm and trivy

What it does

Openclaw Deployment Hardening is an agent skill from sickn33/agentic-awesome-skills. Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not…

It sits in DevOps & Cloud, covering Deployment and CI/CD. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Deployment
  • Tasks that involve CI/CD

Example prompts

  • “/openclaw-deployment-hardening”

Requirements

  • Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Dependency and lockfile vulnerability scan (fail on critical CVEs).
  2. Image scan for OS/package vulnerabilities.
  3. Secret scanning across source and build context.
  4. SBOM generation and artifact signing.
  5. Policy check that blocks deploy when controls fail.

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • npm
    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Openclaw Deployment Hardening loads about 1.1k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 367 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 367 words, ~1,099 tokens.

Download SKILL.mdSave it as .claude/skills/openclaw-deployment-hardening/SKILL.md (or your agent's skills folder).
name
openclaw-deployment-hardening
description
Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification.
compatibility
Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.
category
security
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

OpenClaw Deployment Hardening

Use this skill to add repeatable security gates around OpenClaw build and deployment workflows.

Enforce a Secure Build Pipeline

Add mandatory controls to CI before artifacts are promoted:

  1. Dependency and lockfile vulnerability scan (fail on critical CVEs).
  2. Image scan for OS/package vulnerabilities.
  3. Secret scanning across source and build context.
  4. SBOM generation and artifact signing.
  5. Policy check that blocks deploy when controls fail.

Example CI step order:

bash
# Build
npm ci
npm run build

# Security gates
trivy fs .
trivy image my-registry/openclaw:${GIT_SHA}
syft my-registry/openclaw:${GIT_SHA} -o spdx-json > sbom.json
cosign sign --key cosign.key my-registry/openclaw:${GIT_SHA}

Lock Down Container Runtime

Run OpenClaw with restrictive defaults:

  • Non-root user in container
  • Read-only root filesystem where possible
  • Drop all Linux capabilities, add back only required
  • no-new-privileges enabled
  • Constrained CPU/memory limits to reduce abuse impact
  • Seccomp/AppArmor (or equivalent) profile enforced

Kubernetes-oriented expectations:

  • runAsNonRoot: true
  • allowPrivilegeEscalation: false
  • readOnlyRootFilesystem: true
  • network policy deny-all baseline with explicit allow rules

Gate Production Promotion

Require explicit promotion checks:

  • Security sign-off on CVE exceptions.
  • Signed artifact verification in deployment stage.
  • Drift check between expected and live manifest values.
  • Deployment only from immutable tags or digests.

Avoid mutable latest tags for production OpenClaw services.

Protect Data and Session Surfaces

  • Minimize prompt/response retention by policy.
  • Mask secrets and PII in logs before shipping to SIEM.
  • Encrypt persistent volumes and backups.
  • Isolate tenant/session data boundaries when serving multiple teams.
Show full SKILL.md (163 more words)Show less

Post-Deploy Verification

Run a hardening smoke test immediately after rollout:

bash
kubectl get pods -n openclaw
kubectl auth can-i --as=system:serviceaccount:openclaw:default list secrets -n openclaw
kubectl get networkpolicy -n openclaw
kubectl logs deploy/openclaw -n openclaw --tail=200

Verify:

  • Pod security context matches policy.
  • Service account permissions are least privilege.
  • Ingress auth/rate limits are effective.
  • No plaintext secrets appear in logs.

Incident-Ready Rollback Pattern

Maintain a hardened rollback workflow:

  1. Freeze further rollouts.
  2. Revoke suspect tokens and rotate secrets.
  3. Roll back to last signed known-good image digest.
  4. Re-run post-deploy hardening verification.
  5. Capture timeline and artifacts for forensics.
  • container-hardening (container-hardening) - Container security baseline controls
  • kubernetes-hardening (kubernetes-hardening) - Pod and cluster hardening patterns
  • sbom-supply-chain (sbom-supply-chain) - SBOM, signing, and provenance controls

When to Use

  • You need the security workflow covered by this skill (secrets, scanning, network defense, operations, AI security) inside an authorized scope.

Limitations

  • Apply guidance only within authorized scope; test destructive steps in non-production first.
  • Docs-only import: upstream scripts and templates not bundled.
Example
bash
# Read-only first: inventory before any active step.
which <tool> && <tool> --help | head -n 20

Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/openclaw-deployment-hardening of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Openclaw Deployment Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openclaw Deployment Hardening compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openclaw Deployment Hardening this skillsickn33/agentic-awesome-skills47k1 repos~1.1kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
AI News RadarLearnPrompt/ai-news-radar1.8k—~2.5kAutomated safety check: NotesMIT
Use Vercel Actionamondnet/vercel-action764—~2.7kAutomated safety check: PassMIT
CI CD And Automationdzhalaevd/Donatello1357 repos~2.7kAutomated safety check: NotesApache-2.0
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • AI News Radar

    LearnPrompt/ai-news-radar

    A skill your agent uses when working on AI News Radar, 24 小时 AI 更新雷达, AI 更新雷达, 伯乐Skill, or Scout Skill: finding high-signal AI/tech sources, adding RSS/OPML/GitHub feeds, checking source health…

    1.8k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Use Vercel Action

    amondnet/vercel-action

    Wire amondnet/vercel-action into a GitHub Actions workflow to deploy Vercel projects from CI.

    764 GitHub stars~2.7k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • CI CD And Automation

    dzhalaevd/Donatello

    Automates CI/CD pipeline setup. An agent skill from dzhalaevd/Donatello.

    135 GitHub starsUsed in 7 repos~2.7k tokens
    DevOps & CloudAuto-check: notes
  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Deployments Cicd

    vercel/vercel-plugin

    Official

    Vercel deployment and CI/CD expert guidance. An agent skill from vercel/vercel-plugin.

    301 GitHub starsUsed in 1 repo~3k tokens
    DevOps & CloudAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Openclaw Deployment Hardening

What does Openclaw Deployment Hardening do?

Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification. Openclaw Deployment Hardening is an agent skill from sickn33/agentic-awesome-skills. Secure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification.

When should I use Openclaw Deployment Hardening?

Openclaw Deployment Hardening fits situations like: tasks that involve Deployment; tasks that involve CI/CD.

How do I install Openclaw Deployment Hardening in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill openclaw-deployment-hardening -a claude-code`. Or copy the skill folder (skills/openclaw-deployment-hardening in sickn33/agentic-awesome-skills) into .claude/skills/openclaw-deployment-hardening in your project. Claude Code loads it when a task matches its description.

How do I install Openclaw Deployment Hardening in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill openclaw-deployment-hardening -a codex`. Or copy the skill folder (skills/openclaw-deployment-hardening in sickn33/agentic-awesome-skills) into .agents/skills/openclaw-deployment-hardening in your project. Codex loads it when a task matches its description.

Can I use Openclaw Deployment Hardening in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill openclaw-deployment-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openclaw-deployment-hardening, .gemini/skills/openclaw-deployment-hardening, .github/skills/openclaw-deployment-hardening and .opencode/skills/openclaw-deployment-hardening in your project.

What does Openclaw Deployment Hardening need to run?

Going by SKILL.md and its folder, Openclaw Deployment Hardening needs the command-line tools its instructions call (kubectl, npm and trivy). Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled..

Does Openclaw Deployment Hardening access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Openclaw Deployment Hardening safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openclaw Deployment Hardening use?

Openclaw Deployment Hardening is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openclaw Deployment Hardening use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openclaw Deployment Hardening?

Skills that share tags, products or a category with Openclaw Deployment Hardening: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), AI News Radar (LearnPrompt/ai-news-radar, 1.8k stars), Use Vercel Action (amondnet/vercel-action, 764 stars) and CI CD And Automation (dzhalaevd/Donatello, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openclaw Deployment Hardening?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.