Agent skill

Healthcheck

by trpc-group in trpc-group/trpc-agent-go

Host security hardening and risk-tolerance configuration for OpenClaw deployments.

Apache-2.0Auto-check passedSecurity

Install Healthcheck

skills CLI
$ npx skills add trpc-group/trpc-agent-go --skill healthcheck -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trpc-group/trpc-agent-go healthcheck --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trpc-group/trpc-agent-go.git skills-src && mkdir -p .claude/skills && cp -r skills-src/openclaw/skills/healthcheck .claude/skills/healthcheck && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
healthcheck
GitHub stars
1.9k
Used in
9 other repos
Token cost
~2.6k tokens
SKILL.md length
1,412 words
Files
1
Skills in repo
47
Repo updated
First seen
Licence
Apache-2.0

At a glance

Host security hardening and risk-tolerance configuration for OpenClaw deployments.

  • Works in 9 steps: Model self-check (non-blocking) → Establish context (read-only) → Run OpenClaw security audits (read-only) → …
  • A user asks for security audits
  • SKILL.md covers Overview, Core rules, Workflow (follow in order) and Required confirmations (always), plus 4 more sections
  • Calls npm

What it does

Healthcheck is an agent skill from trpc-group/trpc-agent-go. Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Deployment and Scheduled and recurring tasks. The repository describes itself as: A Go framework for building production agent systems with graph workflows, tools, memory, A2A, AG-UI, MCP, evaluation, and observability. The licence is Apache-2.0.

When your agent uses it

  • A user asks for security audits
  • Firewall/SSH/update hardening
  • Exposure review
  • OpenClaw cron scheduling for periodic checks

Example prompts

  • “/healthcheck”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Model self-check (non-blocking)
  2. Establish context (read-only)
  3. Run OpenClaw security audits (read-only)
  4. Check OpenClaw version/update status (read-only)
  5. Determine risk tolerance (after system context)
  6. Produce a remediation plan
  7. Offer execution options
  8. Execute with confirmations
  9. Verify and report

What it can do on your machine

Read from SKILL.md and the folder at commit 5344490. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Healthcheck loads about 2.6k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 1,412 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trpc-group/trpc-agent-go at commit 5344490, republished under its Apache-2.0 licence (© trpc-group). 1,412 words, ~2,626 tokens.

Download SKILL.mdSave it as .claude/skills/healthcheck/SKILL.md (or your agent's skills folder).
name
healthcheck
description
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).

OpenClaw Host Hardening

Overview

Assess and harden the host running OpenClaw, then align it to a user-defined risk tolerance without breaking access. Use OpenClaw security tooling as a first-class signal, but treat OS hardening as a separate, explicit set of steps.

Core rules

  • Recommend running this skill with a state-of-the-art model (e.g., Opus 4.5, GPT 5.2+). The agent should self-check the current model and suggest switching if below that level; do not block execution.
  • Require explicit approval before any state-changing action.
  • Do not modify remote access settings without confirming how the user connects.
  • Prefer reversible, staged changes with a rollback plan.
  • Never claim OpenClaw changes the host firewall, SSH, or OS updates; it does not.
  • If role/identity is unknown, provide recommendations only.
  • Formatting: every set of user choices must be numbered so the user can reply with a single digit.
  • System-level backups are recommended; try to verify status.

Workflow (follow in order)

0) Model self-check (non-blocking)

Before starting, check the current model. If it is below state-of-the-art (e.g., Opus 4.5, GPT 5.2+), recommend switching. Do not block execution.

1) Establish context (read-only)

Try to infer 1–5 from the environment before asking. Prefer simple, non-technical questions if you need confirmation.

Determine (in order):

  1. OS and version (Linux/macOS/Windows), container vs host.
  2. Privilege level (root/admin vs user).
  3. Access path (local console, SSH, RDP, tailnet).
  4. Network exposure (public IP, reverse proxy, tunnel).
  5. OpenClaw gateway status and bind address.
  6. Backup system and status (e.g., Time Machine, system images, snapshots).
  7. Deployment context (local mac app, headless gateway host, remote gateway, container/CI).
  8. Disk encryption status (FileVault/LUKS/BitLocker).
  9. OS automatic security updates status. Note: these are not blocking items, but are highly recommended, especially if OpenClaw can access sensitive data.
  10. Usage mode for a personal assistant with full access (local workstation vs headless/remote vs other).

First ask once for permission to run read-only checks. If granted, run them by default and only ask questions for items you cannot infer or verify. Do not ask for information already visible in runtime or command output. Keep the permission ask as a single sentence, and list follow-up info needed as an unordered list (not numbered) unless you are presenting selectable choices.

If you must ask, use non-technical prompts:

  • “Are you using a Mac, Windows PC, or Linux?”
  • “Are you logged in directly on the machine, or connecting from another computer?”
  • “Is this machine reachable from the public internet, or only on your home/network?”
  • “Do you have backups enabled (e.g., Time Machine), and are they current?”
  • “Is disk encryption turned on (FileVault/BitLocker/LUKS)?”
  • “Are automatic security updates enabled?”
  • “How do you use this machine?” Examples:
    • Personal machine shared with the assistant
    • Dedicated local machine for the assistant
    • Dedicated remote machine/server accessed remotely (always on)
    • Something else?

Only ask for the risk profile after system context is known.

If the user grants read-only permission, run the OS-appropriate checks by default. If not, offer them (numbered). Examples:

  1. OS: uname -a, sw_vers, cat /etc/os-release.
  2. Listening ports:
    • Linux: ss -ltnup (or ss -ltnp if -u unsupported).
    • macOS: lsof -nP -iTCP -sTCP:LISTEN.
  3. Firewall status:
    • Linux: ufw status, firewall-cmd --state, nft list ruleset (pick what is installed).
    • macOS: /usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate and pfctl -s info.
  4. Backups (macOS): tmutil status (if Time Machine is used).
2) Run OpenClaw security audits (read-only)

As part of the default read-only checks, run openclaw security audit --deep. Only offer alternatives if the user requests them:

  1. openclaw security audit (faster, non-probing)
  2. openclaw security audit --json (structured output)

Offer to apply OpenClaw safe defaults (numbered):

  1. openclaw security audit --fix

Be explicit that --fix only tightens OpenClaw defaults and file permissions. It does not change host firewall, SSH, or OS update policies.

If browser control is enabled, recommend that 2FA be enabled on all important accounts, with hardware keys preferred and SMS not sufficient.

3) Check OpenClaw version/update status (read-only)

As part of the default read-only checks, run openclaw update status.

Report the current channel and whether an update is available.

4) Determine risk tolerance (after system context)

Ask the user to pick or confirm a risk posture and any required open services/ports (numbered choices below). Do not pigeonhole into fixed profiles; if the user prefers, capture requirements instead of choosing a profile. Offer suggested profiles as optional defaults (numbered). Note that most users pick Home/Workstation Balanced:

  1. Home/Workstation Balanced (most common): firewall on with reasonable defaults, remote access restricted to LAN or tailnet.
  2. VPS Hardened: deny-by-default inbound firewall, minimal open ports, key-only SSH, no root login, automatic security updates.
  3. Developer Convenience: more local services allowed, explicit exposure warnings, still audited.
  4. Custom: user-defined constraints (services, exposure, update cadence, access methods).
5) Produce a remediation plan

Provide a plan that includes:

  • Target profile
  • Current posture summary
  • Gaps vs target
  • Step-by-step remediation with exact commands
  • Access-preservation strategy and rollback
  • Risks and potential lockout scenarios
  • Least-privilege notes (e.g., avoid admin usage, tighten ownership/permissions where safe)
  • Credential hygiene notes (location of OpenClaw creds, prefer disk encryption)

Always show the plan before any changes.

Show full SKILL.md (572 more words)Show less
6) Offer execution options

Offer one of these choices (numbered so users can reply with a single digit):

  1. Do it for me (guided, step-by-step approvals)
  2. Show plan only
  3. Fix only critical issues
  4. Export commands for later
7) Execute with confirmations

For each step:

  • Show the exact command
  • Explain impact and rollback
  • Confirm access will remain available
  • Stop on unexpected output and ask for guidance
8) Verify and report

Re-check:

  • Firewall status
  • Listening ports
  • Remote access still works
  • OpenClaw security audit (re-run)

Deliver a final posture report and note any deferred items.

Required confirmations (always)

Require explicit approval for:

  • Firewall rule changes
  • Opening/closing ports
  • SSH/RDP configuration changes
  • Installing/removing packages
  • Enabling/disabling services
  • User/group modifications
  • Scheduling tasks or startup persistence
  • Update policy changes
  • Access to sensitive files or credentials

If unsure, ask.

Periodic checks

After OpenClaw install or first hardening pass, run at least one baseline audit and version check:

  • openclaw security audit
  • openclaw security audit --deep
  • openclaw update status

Ongoing monitoring is recommended. Use the OpenClaw cron tool/CLI to schedule periodic audits (Gateway scheduler). Do not create scheduled tasks without explicit approval. Store outputs in a user-approved location and avoid secrets in logs. When scheduling headless cron runs, include a note in the output that instructs the user to call healthcheck so issues can be fixed.

Required prompt to schedule (always)

After any audit or hardening pass, explicitly offer scheduling and require a direct response. Use a short prompt like (numbered):

  1. “Do you want me to schedule periodic audits (e.g., daily/weekly) via openclaw cron add?”

If the user says yes, ask for:

  • cadence (daily/weekly), preferred time window, and output location
  • whether to also schedule openclaw update status

Use a stable cron job name so updates are deterministic. Prefer exact names:

  • healthcheck:security-audit
  • healthcheck:update-status

Before creating, openclaw cron list and match on exact name. If found, openclaw cron edit <id> .... If not found, openclaw cron add --name <name> ....

Also offer a periodic version check so the user can decide when to update (numbered):

  1. openclaw update status (preferred for source checkouts and channels)
  2. npm view openclaw version (published npm version)

OpenClaw command accuracy

Use only supported commands and flags:

  • openclaw security audit [--deep] [--fix] [--json]
  • openclaw status / openclaw status --deep
  • openclaw health --json
  • openclaw update status
  • openclaw cron add|list|runs|run

Do not invent CLI flags or imply OpenClaw enforces host firewall/SSH policies.

Logging and audit trail

Record:

  • Gateway identity and role
  • Plan ID and timestamp
  • Approved steps and exact commands
  • Exit codes and files modified (best effort)

Redact secrets. Never log tokens or full credential contents.

Memory writes (conditional)

Only write to memory files when the user explicitly opts in and the session is a private/local workspace (per docs/reference/templates/AGENTS.md). Otherwise provide a redacted, paste-ready summary the user can decide to save elsewhere.

Follow the durable-memory prompt format used by OpenClaw compaction:

  • Write lasting notes to memory/YYYY-MM-DD.md.

After each audit/hardening run, if opted-in, append a short, dated summary to memory/YYYY-MM-DD.md (what was checked, key findings, actions taken, any scheduled cron jobs, key decisions, and all commands executed). Append-only: never overwrite existing entries. Redact sensitive host details (usernames, hostnames, IPs, serials, service names, tokens). If there are durable preferences or decisions (risk posture, allowed ports, update policy), also update MEMORY.md (long-term memory is optional and only used in private sessions).

If the session cannot write to the workspace, ask for permission or provide exact entries the user can paste into the memory files.

© trpc-group, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in openclaw/skills/healthcheck of trpc-group/trpc-agent-go.

Open the folder on GitHubat commit 5344490

Used in 9 other repositories

We found 9 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 9 other GitHub owners. This page covers the copy in trpc-group/trpc-agent-go, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Healthcheck next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Healthcheck compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Healthcheck this skilltrpc-group/trpc-agent-go1.9k9 repos~2.6kAutomated safety check: PassApache-2.0
Vpn Security CheckSergei-thinker/vpn-setup189—~1.5kAutomated safety check: NotesMIT
Healthcheckunderstudy-ai/understudy462—~1.2kAutomated safety check: PassMIT
Security AuditaAAaqwq/AGI-Super-Team1052 repos~619Automated safety check: NotesMIT
Robotics Securityarpitg1304/robotics-agent-skills369—~7.8kAutomated safety check: WarnApache-2.0
Frontmcp Production Readinessagentfront/frontmcp146—~6.5kAutomated safety check: PassApache-2.0

Similar skills

  • Vpn Security Check

    Sergei-thinker/vpn-setup

    Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.

    189 GitHub stars~1.5k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Healthcheck

    understudy-ai/understudy

    Host security hardening and risk-tolerance guidance for Understudy deployments.

    462 GitHub stars~1.2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Security Audit

    aAAaqwq/AGI-Super-Team

    Comprehensive security auditing for Clawdbot deployments. An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub starsUsed in 2 repos~619 tokens
    SecurityAuto-check: notes
  • Robotics Security

    arpitg1304/robotics-agent-skills

    Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.

    369 GitHub stars~7.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: warnings
  • Pre-production audit, hardening, and go-live checklists for FrontMCP servers.

    146 GitHub stars~6.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Validator Expert

    jeremylongshore/tons-of-skills-marketplace

    Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices.

    2.8k GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from trpc-group/trpc-agent-go

All 47 skills in this repo
  • Model Usage

    trpc-group/trpc-agent-go

    Use CodexBar CLI local cost usage to summarize per-model usage for Codex or Claude, including the current (most recent) model or a full model breakdown.

    1.9k GitHub starsUsed in 16 repos~563 tokens
    Auto-check passed
  • 1password

    trpc-group/trpc-agent-go

    Set up and use 1Password CLI (op). An agent skill from trpc-group/trpc-agent-go.

    1.9k GitHub starsUsed in 14 repos~656 tokens
    Auto-check passed
  • Tmux

    trpc-group/trpc-agent-go

    Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.

    1.9k GitHub starsUsed in 23 repos~868 tokens
    Auto-check passed
  • Openai Image Gen

    trpc-group/trpc-agent-go

    Batch-generate images via OpenAI Images API. An agent skill from trpc-group/trpc-agent-go.

    1.9k GitHub starsUsed in 12 repos~843 tokens
    Auto-check passed
  • GitHub

    trpc-group/trpc-agent-go

    GitHub operations via gh CLI: issues, PRs, CI runs, code review, API queries.

    1.9k GitHub starsUsed in 9 repos~1k tokens
    Auto-check passed
  • Weather

    trpc-group/trpc-agent-go

    Get current weather and forecasts via wttr.in or Open-Meteo.

    1.9k GitHub starsUsed in 8 repos~591 tokens
    Auto-check passed

Questions about Healthcheck

What does Healthcheck do?

Host security hardening and risk-tolerance configuration for OpenClaw deployments. Healthcheck is an agent skill from trpc-group/trpc-agent-go. Host security hardening and risk-tolerance configuration for OpenClaw deployments.

When should I use Healthcheck?

Healthcheck fits situations like: A user asks for security audits; firewall/SSH/update hardening; exposure review; openClaw cron scheduling for periodic checks.

How do I install Healthcheck in Claude Code?

Run `npx skills add trpc-group/trpc-agent-go --skill healthcheck -a claude-code`. Or copy the skill folder (openclaw/skills/healthcheck in trpc-group/trpc-agent-go) into .claude/skills/healthcheck in your project. Claude Code loads it when a task matches its description.

How do I install Healthcheck in Codex?

Run `npx skills add trpc-group/trpc-agent-go --skill healthcheck -a codex`. Or copy the skill folder (openclaw/skills/healthcheck in trpc-group/trpc-agent-go) into .agents/skills/healthcheck in your project. Codex loads it when a task matches its description.

Can I use Healthcheck in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trpc-group/trpc-agent-go --skill healthcheck -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/healthcheck, .gemini/skills/healthcheck, .github/skills/healthcheck and .opencode/skills/healthcheck in your project.

What does Healthcheck need to run?

Going by SKILL.md and its folder, Healthcheck needs the command-line tools its instructions call (npm).

Does Healthcheck access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Healthcheck safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Healthcheck use?

Healthcheck is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Healthcheck use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Healthcheck?

Skills that share tags, products or a category with Healthcheck: Vpn Security Check (Sergei-thinker/vpn-setup, 189 stars), Healthcheck (understudy-ai/understudy, 462 stars), Security Audit (aAAaqwq/AGI-Super-Team, 105 stars) and Robotics Security (arpitg1304/robotics-agent-skills, 369 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Healthcheck?

trpc-group (a GitHub organization) maintains it in trpc-group/trpc-agent-go, which has 1,857 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on October 10, 2026.

Source: trpc-group/trpc-agent-go on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.