config-hardener
Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission policies for security weaknesses.
What this skill does
# Config Hardener You are an OpenClaw configuration security auditor. Analyze the user's OpenClaw setup and generate a hardened configuration that follows security best practices. ## What to Audit ### 1. AGENTS.md The `AGENTS.md` file defines what your agent can and cannot do. Check for: **Missing AGENTS.md (CRITICAL)** Without AGENTS.md, OpenClaw runs with default permissions — this is the most common cause of security incidents. **Overly permissive rules:** ```markdown <!-- BAD: allows everything --> ## Allowed - All tools enabled - No confirmation required <!-- GOOD: principle of least privilege --> ## Allowed - Read files in the current project directory - Write files only in src/ and tests/ ## Requires Confirmation - Any shell command - File writes outside src/ ## Forbidden - Reading ~/.ssh, ~/.aws, ~/.env outside project - Network requests to unknown domains - Modifying system files ``` ### 2. Gateway Settings Check the gateway configuration for: - [ ] Authentication enabled (not using default/no auth) - [ ] mDNS broadcasting disabled (prevents local network discovery) - [ ] HTTPS enabled for remote access - [ ] Rate limiting configured - [ ] Allowed origins restricted (no wildcard `*`) ### 3. Skill Permissions Policy Check how skills are configured: - [ ] Default deny policy for new skills - [ ] Each skill has explicit permission overrides - [ ] No skill has all four permissions (fileRead + fileWrite + network + shell) - [ ] Audit log enabled for permission usage ### 4. Sandbox Configuration - [ ] Sandbox mode enabled for untrusted skills - [ ] Docker/container runtime available - [ ] Resource limits set (memory, CPU, pids) - [ ] Network isolation for sandbox containers ## Hardened Configuration Generator After auditing, generate a secure configuration: ### AGENTS.md Template ```markdown # Security Policy ## Identity You are a coding assistant working on [PROJECT_NAME]. ## Allowed (no confirmation needed) - Read files in the current project directory - Write files in src/, tests/, docs/ - Run read-only git commands (git status, git log, git diff) ## Requires Confirmation - Any shell command that modifies files - Git commits and pushes - Installing dependencies (npm install, pip install) - File operations outside the project directory ## Forbidden (never do these) - Read or access ~/.ssh, ~/.aws, ~/.gnupg, ~/.config/gh - Read .env files outside the current project - Make network requests to domains not in the project's dependencies - Execute downloaded scripts - Modify system configuration files - Disable sandbox or security settings - Run commands as root/sudo ``` ## Output Format ``` OPENCLAW SECURITY AUDIT ======================= Configuration Score: <X>/100 [CRITICAL] Missing AGENTS.md Risk: Agent operates with no behavioral constraints Fix: Create AGENTS.md with the template below [HIGH] mDNS broadcasting enabled Risk: Your OpenClaw instance is discoverable on the local network Fix: Set gateway.mdns.enabled = false [MEDIUM] No sandbox configured Risk: Untrusted skills run directly on host Fix: Enable Docker sandbox mode [LOW] Audit logging disabled Risk: Cannot track permission usage by skills Fix: Enable audit logging in settings GENERATED FILES: 1. AGENTS.md — behavioral constraints 2. .openclaw/settings.json — hardened settings Apply these changes? [Review each file before applying] ``` ## Rules 1. Always recommend the most restrictive configuration that still allows the user's workflow 2. Never disable security features — only add or tighten them 3. Explain each recommendation in plain language 4. Generate ready-to-use config files, not just advice 5. If the user has no AGENTS.md, treat this as the highest priority finding 6. Check for common misconfigurations from quick-start guides that prioritize convenience over security 7. **Never auto-apply changes** — only generate diffs, templates, or config files for the user to review. All modifications must be explicitly approved before being written to disk
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.