Skip to content
Back to skills

Openclaw Security Guard

ASecurity

Security audit CLI + live dashboard for OpenClaw. Scans for secrets, config issues, prompt injections, vulnerable dependencies, and unverified MCP servers. Zero telemetry.

  • 14 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
securitygobashnodegitapisecurity

Works with

  • cli
  • api
  • mcp

Security analysis

A96/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 20 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill openclaw-security-guard --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Openclaw Security Guard?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Openclaw Security Guard
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-openclaw-security-guard/badge)](https://www.skillsdirectory.com/skills/modbender-openclaw-security-guard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: openclaw-security-guard
description: Security audit CLI + live dashboard for OpenClaw. Scans for secrets, config issues, prompt injections, vulnerable dependencies, and unverified MCP servers. Zero telemetry.
version: 1.0.0
metadata:
  openclaw:
    requires:
      bins:
        - node
    install:
      - kind: node
        package: openclaw-security-guard
        bins: [openclaw-guard, openclaw-security-guard]
    emoji: "\U0001F6E1"
    homepage: https://github.com/2pidata/openclaw-security-guard
    os:
      - macos
      - linux
      - windows
---

# OpenClaw Security Guard

The missing security layer for your OpenClaw installation.

## What it does

Run `openclaw-guard audit` to scan your OpenClaw setup across 5 categories:

- **Secrets Scanner** -- Detects API keys, tokens, passwords across 15+ formats + entropy analysis
- **Config Auditor** -- Checks sandbox mode, DM policy, gateway binding, rate limiting
- **Prompt Injection Detector** -- 50+ patterns: instruction overrides, role hijacking, jailbreaks
- **Dependency Scanner** -- npm CVE scanning
- **MCP Server Auditor** -- Allowlist-based verification of installed MCP servers

## Quick start

```bash
npm install -g openclaw-security-guard

# Full audit
openclaw-guard audit

# Fix issues automatically (with backup)
openclaw-guard fix --auto

# Launch live dashboard
openclaw-guard dashboard
```

## Features

- **Security Score** (0-100) -- one number for your security posture
- **Auto-hardening** -- interactive, automatic, or dry-run modes
- **Live dashboard** -- real-time monitoring at localhost:18790
- **Pre-commit hooks** -- catch secrets before they're committed
- **Multi-language** -- English, French, Arabic
- **Zero telemetry** -- no tracking, no network requests, 100% local

## Links

- **Repository:** https://github.com/2pidata/openclaw-security-guard
- **Author:** [Miloud Belarebia](https://github.com/miloudbelarebia) / [2PiData](https://2pidata.com)
- **License:** MIT

Files in this skill

  • PUBLICATION_GUIDE.md2.2 KB
  • README.md9.7 KB
  • SKILL.md2 KB
  • docs/README.md3 KB
  • docs/api/cli.md5.7 KB
  • docs/api/programmatic.md9.9 KB
  • docs/ar/README.md12 KB
  • docs/en/README.md15.7 KB
  • docs/fr/README.md13.7 KB
  • docs/guides/getting-started.md3.7 KB
  • package.json2.9 KB
  • src/cli/index.js24 KB
  • src/dashboard/server.js23.1 KB
  • src/hardening/auto-hardener.js2.1 KB
  • src/index.js3.8 KB
  • src/monitors/cost-monitor.js601 B
  • src/monitors/realtime-monitor.js1.2 KB
  • src/scanners/config-auditor.js14.4 KB
  • src/scanners/dependency-scanner.js1.6 KB
  • src/scanners/mcp-server-auditor.js2.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…