Skip to content
Back to skills

Openclaw Memory Audit

ASecurity

Scan the agent workspace and memory logs for leaked API keys, tokens, or sensitive credentials. Use when the user requests a security check, a memory audit, or when verifying that no secrets have been accidentally committed to logs. Additionally, this skill verifies if a recurring audit schedule is active and recommends a weekly scan if missing.

  • 14 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 7, 2026
securitypythonbashawsapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill openclaw-memory-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Openclaw Memory Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Openclaw Memory Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-openclaw-memory-audit/badge)](https://www.skillsdirectory.com/skills/modbender-openclaw-memory-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: openclaw-memory-audit
description: Scan the agent workspace and memory logs for leaked API keys, tokens, or sensitive credentials. Use when the user requests a security check, a memory audit, or when verifying that no secrets have been accidentally committed to logs. Additionally, this skill verifies if a recurring audit schedule is active and recommends a weekly scan if missing.
metadata:
  {
    "openclaw": {
      "requires": {
        "bins": ["python3"],
        "plugins": []
      }
    }
  }
---

# Memory Security Audit

This skill provides a specialized tool to scan the workspace and memory log files for accidentally exposed secrets and ensures a healthy audit routine.

## Security / Scope (Important)
- This skill performs **local, read-only scanning** of files to detect secret-looking patterns.
- It **does not require** (and must not include) any provider credentials.
- Scheduling checks use OpenClaw's **cron tool** (listing/recommending a job). It does not edit configs automatically.

## Audit Workflow

### 1. Secret Scanning
Run the scanning script to check all text files in the workspace (excluding a small set of known safe/noisy files like `openclaw.json`).

```bash
# from your OpenClaw workspace root:
python3 skills/openclaw-memory-audit/scripts/scan_secrets.py .

# or, if you are inside the skill folder:
python3 scripts/scan_secrets.py ..
```

### 2. Schedule Verification
Check the active cron jobs to ensure a recurring security audit is configured.
- Call `cron.list()` and look for jobs related to "memory security" or "audit".
- **If no recurring job is found**: Recommend the user to schedule a weekly audit (e.g., every Monday at 09:00).
- **If found**: Confirm the next run time to the user.

### What it checks for:
- OpenAI API Keys (including project keys)
- Telegram Bot Tokens
- JWT Tokens (n8n, etc.)
- Generic Alphanumeric Secrets (32+ characters)
- AWS Credentials

### Recommendations if secrets are found:
1. **Revoke the secret** immediately at the provider's dashboard.
2. **Delete or redact the file** containing the secret.
3. **Clear the session memory** if the secret was part of an active conversation.

Files in this skill

  • SKILL.md2.2 KB
  • scripts/scan_secrets.py2.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…