Skip to content
Back to skills

Openclaw Action

ASecurity

GitHub Action for automated security scanning of agent workspaces. Detects exposed secrets, prompt/shell injection, and data exfiltration patterns in PRs and commits.

  • 14 stars
  • 0 votes
  • 0 copies
  • 4 views
  • Added September 7, 2026
securitypythonshellgitapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill openclaw-action --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Openclaw Action?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Openclaw Action
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-openclaw-action/badge)](https://www.skillsdirectory.com/skills/modbender-openclaw-action)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: openclaw-action
description: "GitHub Action for automated security scanning of agent workspaces. Detects exposed secrets, prompt/shell injection, and data exfiltration patterns in PRs and commits."
user-invocable: false
metadata: {"openclaw":{"emoji":"🛡️","requires":{"bins":["python3"]},"os":["darwin","linux","win32"]}}
---

# OpenClaw Security Action

GitHub Action that scans agent skills for security issues on every PR.

## What It Scans

| Scanner | What It Catches |
|---------|-----------------|
| **sentry** | API keys, tokens, passwords, credentials in code |
| **bastion** | Prompt injection markers, shell injection patterns |
| **egress** | Suspicious network calls, data exfiltration patterns |

## Quick Start

Add to `.github/workflows/security.yml`:

```yaml
name: Security Scan
on:
  pull_request:
    paths:
      - 'skills/**'
      - '.openclaw/**'
  push:
    branches: [main]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: AtlasPA/openclaw-action@v1
        with:
          workspace: '.'
          fail-on-findings: 'true'
```

## Inputs

| Input | Default | Description |
|-------|---------|-------------|
| `workspace` | `.` | Path to scan |
| `fail-on-findings` | `true` | Fail the check if issues found |
| `scan-secrets` | `true` | Enable secret scanning |
| `scan-injection` | `true` | Enable injection scanning |
| `scan-egress` | `true` | Enable egress scanning |

## Outputs

| Output | Description |
|--------|-------------|
| `findings-count` | Total number of issues found |
| `has-critical` | `true` if critical/high severity issues |

## Philosophy

This action **detects and alerts only**. It will:
- Flag security issues in PR checks
- Annotate specific lines with findings
- Generate a summary report

It will NOT:
- Automatically modify your code
- Quarantine or delete files
- Make any changes to your repository

For automated remediation, see [OpenClaw Pro](https://github.com/sponsors/AtlasPA).

## Requirements

- Python 3.8+ (auto-installed by action)
- No external dependencies

Files in this skill

  • README.md4.9 KB
  • SKILL.md2.1 KB
  • action.yml2.5 KB
  • scripts/scan.py9.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…