Vpn Security Check
Sergei-thinker/vpn-setup
Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.
Host security hardening and risk-tolerance configuration for OpenClaw deployments.
$ npx skills add trpc-group/trpc-agent-go --skill healthcheck -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trpc-group/trpc-agent-go healthcheck --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trpc-group/trpc-agent-go.git skills-src && mkdir -p .claude/skills && cp -r skills-src/openclaw/skills/healthcheck .claude/skills/healthcheck && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "healthcheck" agent skill from https://github.com/trpc-group/trpc-agent-go/tree/main/openclaw/skills/healthcheck into .claude/skills/healthcheck/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "healthcheck", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trpc-group/trpc-agent-go/tree/main/openclaw/skills/healthcheckType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trpc-group/trpc-agent-go --skill healthcheck -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trpc-group/trpc-agent-go healthcheck --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trpc-group/trpc-agent-go.git skills-src && mkdir -p .agents/skills && cp -r skills-src/openclaw/skills/healthcheck .agents/skills/healthcheck && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "healthcheck" agent skill from https://github.com/trpc-group/trpc-agent-go/tree/main/openclaw/skills/healthcheck into .agents/skills/healthcheck/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "healthcheck", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trpc-group/trpc-agent-go --skill healthcheck -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trpc-group/trpc-agent-go healthcheck --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trpc-group/trpc-agent-go.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/openclaw/skills/healthcheck .cursor/skills/healthcheck && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "healthcheck" agent skill from https://github.com/trpc-group/trpc-agent-go/tree/main/openclaw/skills/healthcheck into .cursor/skills/healthcheck/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "healthcheck", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trpc-group/trpc-agent-go.git --path openclaw/skills/healthcheck--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trpc-group/trpc-agent-go --skill healthcheck -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trpc-group/trpc-agent-go healthcheck --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trpc-group/trpc-agent-go.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/openclaw/skills/healthcheck .gemini/skills/healthcheck && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "healthcheck" agent skill from https://github.com/trpc-group/trpc-agent-go/tree/main/openclaw/skills/healthcheck into .gemini/skills/healthcheck/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "healthcheck", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trpc-group/trpc-agent-go healthcheckInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trpc-group/trpc-agent-go --skill healthcheck -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trpc-group/trpc-agent-go.git skills-src && mkdir -p .github/skills && cp -r skills-src/openclaw/skills/healthcheck .github/skills/healthcheck && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "healthcheck" agent skill from https://github.com/trpc-group/trpc-agent-go/tree/main/openclaw/skills/healthcheck into .github/skills/healthcheck/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "healthcheck", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trpc-group/trpc-agent-go --skill healthcheck -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trpc-group/trpc-agent-go healthcheck --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trpc-group/trpc-agent-go.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/openclaw/skills/healthcheck .opencode/skills/healthcheck && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "healthcheck" agent skill from https://github.com/trpc-group/trpc-agent-go/tree/main/openclaw/skills/healthcheck into .opencode/skills/healthcheck/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "healthcheck", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
healthcheckHost security hardening and risk-tolerance configuration for OpenClaw deployments.
Healthcheck is an agent skill from trpc-group/trpc-agent-go. Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review, Deployment and Scheduled and recurring tasks. The repository describes itself as: A Go framework for building production agent systems with graph workflows, tools, memory, A2A, AG-UI, MCP, evaluation, and observability. The licence is Apache-2.0.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 5344490. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Healthcheck loads about 2.6k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 1,412 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trpc-group/trpc-agent-go at commit 5344490, republished under its Apache-2.0 licence (© trpc-group). 1,412 words, ~2,626 tokens.
.claude/skills/healthcheck/SKILL.md (or your agent's skills folder).Assess and harden the host running OpenClaw, then align it to a user-defined risk tolerance without breaking access. Use OpenClaw security tooling as a first-class signal, but treat OS hardening as a separate, explicit set of steps.
Before starting, check the current model. If it is below state-of-the-art (e.g., Opus 4.5, GPT 5.2+), recommend switching. Do not block execution.
Try to infer 1–5 from the environment before asking. Prefer simple, non-technical questions if you need confirmation.
Determine (in order):
First ask once for permission to run read-only checks. If granted, run them by default and only ask questions for items you cannot infer or verify. Do not ask for information already visible in runtime or command output. Keep the permission ask as a single sentence, and list follow-up info needed as an unordered list (not numbered) unless you are presenting selectable choices.
If you must ask, use non-technical prompts:
Only ask for the risk profile after system context is known.
If the user grants read-only permission, run the OS-appropriate checks by default. If not, offer them (numbered). Examples:
uname -a, sw_vers, cat /etc/os-release.ss -ltnup (or ss -ltnp if -u unsupported).lsof -nP -iTCP -sTCP:LISTEN.ufw status, firewall-cmd --state, nft list ruleset (pick what is installed)./usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate and pfctl -s info.tmutil status (if Time Machine is used).As part of the default read-only checks, run openclaw security audit --deep. Only offer alternatives if the user requests them:
openclaw security audit (faster, non-probing)openclaw security audit --json (structured output)Offer to apply OpenClaw safe defaults (numbered):
openclaw security audit --fixBe explicit that --fix only tightens OpenClaw defaults and file permissions. It does not change host firewall, SSH, or OS update policies.
If browser control is enabled, recommend that 2FA be enabled on all important accounts, with hardware keys preferred and SMS not sufficient.
As part of the default read-only checks, run openclaw update status.
Report the current channel and whether an update is available.
Ask the user to pick or confirm a risk posture and any required open services/ports (numbered choices below). Do not pigeonhole into fixed profiles; if the user prefers, capture requirements instead of choosing a profile. Offer suggested profiles as optional defaults (numbered). Note that most users pick Home/Workstation Balanced:
Provide a plan that includes:
Always show the plan before any changes.
Offer one of these choices (numbered so users can reply with a single digit):
For each step:
Re-check:
Deliver a final posture report and note any deferred items.
Require explicit approval for:
If unsure, ask.
After OpenClaw install or first hardening pass, run at least one baseline audit and version check:
openclaw security auditopenclaw security audit --deepopenclaw update statusOngoing monitoring is recommended. Use the OpenClaw cron tool/CLI to schedule periodic audits (Gateway scheduler). Do not create scheduled tasks without explicit approval. Store outputs in a user-approved location and avoid secrets in logs.
When scheduling headless cron runs, include a note in the output that instructs the user to call healthcheck so issues can be fixed.
After any audit or hardening pass, explicitly offer scheduling and require a direct response. Use a short prompt like (numbered):
openclaw cron add?”If the user says yes, ask for:
openclaw update statusUse a stable cron job name so updates are deterministic. Prefer exact names:
healthcheck:security-audithealthcheck:update-statusBefore creating, openclaw cron list and match on exact name. If found, openclaw cron edit <id> ....
If not found, openclaw cron add --name <name> ....
Also offer a periodic version check so the user can decide when to update (numbered):
openclaw update status (preferred for source checkouts and channels)npm view openclaw version (published npm version)Use only supported commands and flags:
openclaw security audit [--deep] [--fix] [--json]openclaw status / openclaw status --deepopenclaw health --jsonopenclaw update statusopenclaw cron add|list|runs|runDo not invent CLI flags or imply OpenClaw enforces host firewall/SSH policies.
Record:
Redact secrets. Never log tokens or full credential contents.
Only write to memory files when the user explicitly opts in and the session is a private/local workspace
(per docs/reference/templates/AGENTS.md). Otherwise provide a redacted, paste-ready summary the user can
decide to save elsewhere.
Follow the durable-memory prompt format used by OpenClaw compaction:
memory/YYYY-MM-DD.md.After each audit/hardening run, if opted-in, append a short, dated summary to memory/YYYY-MM-DD.md
(what was checked, key findings, actions taken, any scheduled cron jobs, key decisions,
and all commands executed). Append-only: never overwrite existing entries.
Redact sensitive host details (usernames, hostnames, IPs, serials, service names, tokens).
If there are durable preferences or decisions (risk posture, allowed ports, update policy),
also update MEMORY.md (long-term memory is optional and only used in private sessions).
If the session cannot write to the workspace, ask for permission or provide exact entries the user can paste into the memory files.
© trpc-group, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in openclaw/skills/healthcheck of trpc-group/trpc-agent-go.
Open the folder on GitHubat commit 5344490
We found 9 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 9 other GitHub owners. This page covers the copy in trpc-group/trpc-agent-go, which our catalogue first saw on October 7, 2026.
Healthcheck next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Healthcheck this skilltrpc-group/trpc-agent-go | 1.9k | 9 repos | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Vpn Security CheckSergei-thinker/vpn-setup | 189 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Healthcheckunderstudy-ai/understudy | 462 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Security AuditaAAaqwq/AGI-Super-Team | 105 | 2 repos | ~619 | Automated safety check: Notes | MIT | |
| Robotics Securityarpitg1304/robotics-agent-skills | 369 | — | ~7.8k | Automated safety check: Warn | Apache-2.0 | |
| Frontmcp Production Readinessagentfront/frontmcp | 146 | — | ~6.5k | Automated safety check: Pass | Apache-2.0 |
Sergei-thinker/vpn-setup
Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.
understudy-ai/understudy
Host security hardening and risk-tolerance guidance for Understudy deployments.
aAAaqwq/AGI-Super-Team
Comprehensive security auditing for Clawdbot deployments. An agent skill from aAAaqwq/AGI-Super-Team.
arpitg1304/robotics-agent-skills
Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.
agentfront/frontmcp
Pre-production audit, hardening, and go-live checklists for FrontMCP servers.
jeremylongshore/tons-of-skills-marketplace
Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices.
trpc-group/trpc-agent-go
Use CodexBar CLI local cost usage to summarize per-model usage for Codex or Claude, including the current (most recent) model or a full model breakdown.
trpc-group/trpc-agent-go
Set up and use 1Password CLI (op). An agent skill from trpc-group/trpc-agent-go.
trpc-group/trpc-agent-go
Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.
trpc-group/trpc-agent-go
Batch-generate images via OpenAI Images API. An agent skill from trpc-group/trpc-agent-go.
trpc-group/trpc-agent-go
GitHub operations via gh CLI: issues, PRs, CI runs, code review, API queries.
trpc-group/trpc-agent-go
Get current weather and forecasts via wttr.in or Open-Meteo.
Categories
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Healthcheck is an agent skill from trpc-group/trpc-agent-go. Host security hardening and risk-tolerance configuration for OpenClaw deployments.
Healthcheck fits situations like: A user asks for security audits; firewall/SSH/update hardening; exposure review; openClaw cron scheduling for periodic checks.
Run `npx skills add trpc-group/trpc-agent-go --skill healthcheck -a claude-code`. Or copy the skill folder (openclaw/skills/healthcheck in trpc-group/trpc-agent-go) into .claude/skills/healthcheck in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trpc-group/trpc-agent-go --skill healthcheck -a codex`. Or copy the skill folder (openclaw/skills/healthcheck in trpc-group/trpc-agent-go) into .agents/skills/healthcheck in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trpc-group/trpc-agent-go --skill healthcheck -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/healthcheck, .gemini/skills/healthcheck, .github/skills/healthcheck and .opencode/skills/healthcheck in your project.
Going by SKILL.md and its folder, Healthcheck needs the command-line tools its instructions call (npm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Healthcheck is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Healthcheck: Vpn Security Check (Sergei-thinker/vpn-setup, 189 stars), Healthcheck (understudy-ai/understudy, 462 stars), Security Audit (aAAaqwq/AGI-Super-Team, 105 stars) and Robotics Security (arpitg1304/robotics-agent-skills, 369 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trpc-group (a GitHub organization) maintains it in trpc-group/trpc-agent-go, which has 1,857 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on October 10, 2026.
Source: trpc-group/trpc-agent-go on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.