Skip to content
Back to skills

Firm Runtime Audit Pack

ASecurity

Runtime environment and configuration audit pack. Validates Node.js version, secrets workflow, HTTP headers, allowed commands, trusted proxy, disk budget, and DM allowlist. 7 runtime security tools.

  • 14 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 7, 2026
securityrustnodenodejssecurity

Works with

  • mcp

Security analysis

A100/100

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill firm-runtime-audit-pack --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Firm Runtime Audit Pack?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Firm Runtime Audit Pack
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-firm-runtime-audit-pack/badge)](https://www.skillsdirectory.com/skills/modbender-firm-runtime-audit-pack)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: firm-runtime-audit-pack
version: 1.0.0
description: >
  Runtime environment and configuration audit pack.
  Validates Node.js version, secrets workflow, HTTP headers, allowed commands,
  trusted proxy, disk budget, and DM allowlist. 7 runtime security tools.
author: romainsantoli-web
license: MIT
metadata:
  openclaw:
    registry: ClawHub
    requires:
      - mcp-openclaw-extensions >= 3.0.0
tags:
  - runtime
  - audit
  - security
  - nodejs
  - configuration
---

# firm-runtime-audit-pack

> ⚠️ Contenu généré par IA — validation humaine requise avant utilisation.

## Purpose

Audits the runtime environment of OpenClaw deployments: Node.js version compliance,
secrets handling, HTTP security headers, command allowlists, proxy configuration,
disk budget, and direct message policies.

## Tools (7)

| Tool | Description | Severity |
|------|-------------|----------|
| `openclaw_node_version_check` | Verify Node.js runtime version | CRITICAL |
| `openclaw_secrets_workflow_check` | Audit secrets handling in workflows | CRITICAL |
| `openclaw_http_headers_check` | Check HTTP security headers (HSTS, CSP) | HIGH |
| `openclaw_nodes_commands_check` | Validate nodes.allowCommands config | HIGH |
| `openclaw_trusted_proxy_check` | Verify trusted proxy configuration | HIGH |
| `openclaw_session_disk_budget_check` | Check session disk budget limits | MEDIUM |
| `openclaw_dm_allowlist_check` | Audit DM channel allowlist policy | MEDIUM |

## Usage

```yaml
skills:
  - firm-runtime-audit-pack

# Run full runtime audit:
openclaw_node_version_check config_path=/path/to/config.json
openclaw_secrets_workflow_check config_path=/path/to/config.json
openclaw_http_headers_check config_path=/path/to/config.json
```

## Requirements

- `mcp-openclaw-extensions >= 3.0.0`
- Node.js >= 20.x recommended

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…