Skip to content
Back to skills

Security Sentinel

ASecurity

Scan the workspace for security vulnerabilities, exposed secrets, and misconfigurations.

  • 33 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 5, 2026
securityjavascriptjavabashnodegitapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add dvcrn/openclaw-skills-marketplace --skill security-sentinel --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Sentinel?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Sentinel
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dvcrn-security-sentinel/badge)](https://www.skillsdirectory.com/skills/dvcrn-security-sentinel)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-sentinel
description: "Scan the workspace for security vulnerabilities, exposed secrets, and misconfigurations."
---

# Security Sentinel

A unified security scanner for OpenClaw workspaces. Detects vulnerabilities in dependencies (npm audit), exposed secrets (regex patterns), and unsafe file permissions.

## Usage

### CLI

Run a full security scan:

```bash
node skills/security-sentinel/index.js
```

This will output a JSON report to stdout.
If risks are detected (high/critical vulnerabilities, secrets, or bad permissions), it exits with code 1.

### Options

- `--skip-audit`: Skip the npm audit step (faster)
- `--no-fail`: Do not exit with code 1 even if risks are detected (useful for monitoring only)

### Programmatic

```javascript
const sentinel = require('./skills/security-sentinel');

const report = await sentinel.scan();

if (report.status === 'risk_detected') {
  console.error('Security issues found:', report);
}
```

## Features

1. **Dependency Audit**: Runs `npm audit` to check `package.json` dependencies for known CVEs.
2. **Secret Detection**: Scans workspace files for patterns resembling API keys, passwords, and private keys.
3. **Permission Check**: Verifies critical files (`package.json`, `.env`) are not world-writable.

## Configuration

- **Ignored Paths**: `node_modules`, `.git`, `logs`, `temp`, `.openclaw/cache`.
- **Secret Patterns**: Generic API Key, Password, Private Key, Feishu App Secret.

Files in this skill

  • SKILL.md1.4 KB
  • index.js4.8 KB
  • package-lock.json5.4 KB
  • package.json305 B
  • scan.js5.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…