Skip to content
Back to skills

Security Monitor

ASecurity

Comprehensive security audit for OpenClaw deployments. Checks Docker port bindings, SSH config, openclaw.json settings, file permissions, exposed services, and firewall rules. Scores your deployment 0-100 with actionable recommendations. Use for security hardening and compliance checks.

  • 33 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 5, 2026
securitygobashdockergitapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add dvcrn/openclaw-skills-marketplace --skill security-monitor --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Monitor?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Monitor
[![Security: A โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/dvcrn-security-monitor/badge)](https://www.skillsdirectory.com/skills/dvcrn-security-monitor)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-monitor
description: "Comprehensive security audit for OpenClaw deployments. Checks Docker port bindings, SSH config, openclaw.json settings, file permissions, exposed services, and firewall rules. Scores your deployment 0-100 with actionable recommendations. Use for security hardening and compliance checks."
homepage: https://www.agxntsix.ai
---

# Security Monitor ๐Ÿ›ก๏ธ

**Comprehensive security audit for OpenClaw deployments.**

Scans your Docker configuration, SSH settings, firewall rules, OpenClaw config, and file permissions. Produces a security score (0-100) with actionable recommendations.

## Quick Start

```bash
# Run full audit
bash {baseDir}/scripts/security_audit.sh

# JSON output
bash {baseDir}/scripts/security_audit.sh --json

# Specific checks only
bash {baseDir}/scripts/security_audit.sh --check docker
bash {baseDir}/scripts/security_audit.sh --check ssh
bash {baseDir}/scripts/security_audit.sh --check config
bash {baseDir}/scripts/security_audit.sh --check files
bash {baseDir}/scripts/security_audit.sh --check network
```

## What It Checks

### OpenClaw Config (25 points)
- `allowInsecureAuth` must be `false`
- `dmPolicy` must not be open/allow-all
- Port bindings must use `127.0.0.1`
- API keys not hardcoded in config
- Secure model permissions

### Docker Security (25 points)
- All port bindings use `127.0.0.1` (not `0.0.0.0`)
- No privileged containers (except necessary)
- Docker socket permissions
- Container resource limits
- No `--net=host` unless needed

### SSH Configuration (20 points)
- Root login disabled (`PermitRootLogin no`)
- Password authentication disabled
- Key-based auth only
- Non-standard port (bonus)
- Fail2ban or similar active

### Network & Services (15 points)
- No unnecessary exposed ports
- Firewall active (ufw/iptables)
- Only expected services listening
- HTTPS/TLS termination configured

### File Permissions (15 points)
- openclaw.json not world-readable
- SSH keys proper permissions (600)
- .env files not world-readable
- Docker socket permissions
- No sensitive files in /tmp

## Scoring

| Score | Rating | Meaning |
|-------|--------|---------|
| 90-100 | ๐ŸŸข Excellent | Production-ready |
| 70-89 | ๐ŸŸก Good | Minor improvements needed |
| 50-69 | ๐ŸŸ  Fair | Several issues to address |
| 0-49 | ๐Ÿ”ด Critical | Immediate action required |

## Output Example

```
โ•โ•โ• Security Audit Report โ•โ•โ•
Date: 2026-02-15 00:30:00

[CONFIG] โœ… allowInsecureAuth: false
[CONFIG] โœ… dmPolicy: allowlist
[CONFIG] โœ… Ports bound to 127.0.0.1
[DOCKER] โœ… All containers bind to 127.0.0.1
[DOCKER] โš ๏ธ  No resource limits on openclaw container
[SSH]    โœ… Root login disabled
[SSH]    โœ… Password auth disabled
[NET]    โœ… UFW active
[FILES]  โœ… Config file permissions OK

Score: 92/100 โ€” ๐ŸŸข Excellent
Issues: 1 warning

Recommendations:
  1. Add resource limits to Docker containers
```

## Credits
Built by [M. Abidi](https://www.linkedin.com/in/mohammad-ali-abidi) | [agxntsix.ai](https://www.agxntsix.ai)
[YouTube](https://youtube.com/@aiwithabidi) | [GitHub](https://github.com/aiwithabidi)
Part of the **AgxntSix Skill Suite** for OpenClaw agents.

๐Ÿ“… **Need help setting up OpenClaw for your business?** [Book a free consultation](https://cal.com/agxntsix/abidi-openclaw)

Files in this skill

  • SKILL.md3.2 KB
  • scripts/security_audit.sh12.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading commentsโ€ฆ