Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Abaddon

ASecurity

Red team security mode for OpenClaw. Runs an adversarial audit on demand or nightly — checks exposed ports, credential leaks, file permissions, suspicious processes, and OpenClaw config posture. Assigns a letter grade. Built for macOS deployments.

14 stars
0 votes
0 copies
4 views
Added 9/7/2026
securitybashnodegitapisecurity

Works with

api

Security Analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned 9/7/2026

$npx -y skills add modbender/skill-library-mcp --skill abaddon --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Abaddon?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Abaddon
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-abaddon/badge)](https://www.skillsdirectory.com/skills/modbender-abaddon)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: abaddon
description: Red team security mode for OpenClaw. Runs an adversarial audit on demand or nightly — checks exposed ports, credential leaks, file permissions, suspicious processes, and OpenClaw config posture. Assigns a letter grade. Built for macOS deployments.
---

# Abaddon ⚔️

Most security audits are defensive — they check what you've locked down. Abaddon runs the other direction. It thinks like an attacker. It looks for what an adversary would find, not just what you remember to check.

On demand or every night at 3:45 AM. Letter grade every time.

## What It Checks

**Network & Exposure**
- Listening ports — anything bound to 0.0.0.0 is flagged
- Gateway binding — should be loopback only
- SSH Remote Login state
- Active tunnels (ngrok, cloudflared, unexpected remote access)
- Firewall and stealth mode

**System Integrity**
- SIP, FileVault, Gatekeeper
- macOS version + pending updates
- XProtect / MRT definitions age

**OpenClaw Configuration**
- Exec security mode (full / allowlist / deny)
- Gateway auth enabled?
- Unexpected cron entries
- Unexpected plugins

**File Permissions**
- SOUL.md + AGENTS.md: root-owned, 444
- MEMORY.md, USER.md, AGENT_PROMPT.md, openclaw.json, cron/jobs.json, LaunchAgent plists: 600
- Flags anything 644 or wider on sensitive paths
- Plaintext key scan across workspace

**API Key Handling**
- Keys in Keychain or flat files?
- Keys leaking through env vars?
- Secrets in git history?
- Hardcoded tokens in .zshrc?

**Agent Behavior**
- Memory injection scan (prompt injection attempts in memory files)
- Sub-agent scope check
- Unexpected agent permissions

**Dependencies**
- Homebrew outdated (flags openclaw, ollama, node)
- npm global outdated

## Scoring

| Grade | Criteria |
|-------|----------|
| A | 0 CRITICAL, 0 HIGH |
| B | 0 CRITICAL, 1–2 HIGH |
| C | 1 CRITICAL or 3+ HIGH |
| D | 2+ CRITICAL |
| F | Active compromise indicators |

## Installation

### Step 1 — Copy the Abaddon prompt into your agent

If you have Gideon (the OpenClaw observer agent), append the red team section:

```bash
cat skills/abaddon/templates/abaddon-prompt.md >> ~/.openclaw/workspace/agents/observer/AGENT_PROMPT.md
```

If you don't have Gideon, use the standalone agent prompt:

```bash
cp skills/abaddon/templates/abaddon-prompt.md ~/.openclaw/workspace/agents/abaddon/AGENT_PROMPT.md
```

### Step 2 — Add the nightly cron

```bash
bash skills/abaddon/setup/cron-seed.sh
```

This adds a 3:45 AM CST cron job to `~/.openclaw/cron/jobs.json`. Delivers to Telegram Security topic if configured.

### Step 3 — Lock the agent prompt

```bash
chmod 600 ~/.openclaw/workspace/agents/observer/AGENT_PROMPT.md
```

Your detection playbook should never be world-readable.

## Usage

**Manual trigger** — say any of:
- "run red team"
- "run Abaddon"
- "run full assessment"
- "Abaddon report"

**Nightly** — fires automatically at 3:45 AM CST after the standard defensive audit (3:30 AM).

## Output

Every run produces two things:

1. **Technical report** → `memory/audits/abaddon-YYYY-MM-DD.md` — full command output, evidence, remediation steps
2. **Summary** → posted to Telegram Security topic with letter grade

CRITICAL findings trigger an immediate DM alert.

## Notes

- Designed for macOS (Darwin arm64). Most checks work on Linux with minor path adjustments.
- Assumes OpenClaw gateway is running locally. Remote deployments may need adjusted port/binding checks.
- Pairs with `enoch-tuning` — run `lock-identity.sh` after install to enforce all file permission baselines in one pass.

Attribution

modbendermodbender
View sourceSee grades on GitHubMore from modbender →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes
View all in security →