Back to skills
SKILL.md
Openclaw Security Guard
ASecuritySecurity audit CLI + live dashboard for OpenClaw. Scans for secrets, config issues, prompt injections, vulnerable dependencies, and unverified MCP servers. Zero telemetry.
- 14 stars
- 0 votes
- 0 copies
- 2 views
- Added September 7, 2026
Works with
Security analysis
96/100- Installs packages at runtime which could introduce malicious dependencies
Pro scans all 20 files and shows the line behind each finding
npx -y skills add modbender/skill-library-mcp --skill openclaw-security-guard --agent claude-codeAre you the author of Openclaw Security Guard?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/modbender-openclaw-security-guard)---
name: openclaw-security-guard
description: Security audit CLI + live dashboard for OpenClaw. Scans for secrets, config issues, prompt injections, vulnerable dependencies, and unverified MCP servers. Zero telemetry.
version: 1.0.0
metadata:
openclaw:
requires:
bins:
- node
install:
- kind: node
package: openclaw-security-guard
bins: [openclaw-guard, openclaw-security-guard]
emoji: "\U0001F6E1"
homepage: https://github.com/2pidata/openclaw-security-guard
os:
- macos
- linux
- windows
---
# OpenClaw Security Guard
The missing security layer for your OpenClaw installation.
## What it does
Run `openclaw-guard audit` to scan your OpenClaw setup across 5 categories:
- **Secrets Scanner** -- Detects API keys, tokens, passwords across 15+ formats + entropy analysis
- **Config Auditor** -- Checks sandbox mode, DM policy, gateway binding, rate limiting
- **Prompt Injection Detector** -- 50+ patterns: instruction overrides, role hijacking, jailbreaks
- **Dependency Scanner** -- npm CVE scanning
- **MCP Server Auditor** -- Allowlist-based verification of installed MCP servers
## Quick start
```bash
npm install -g openclaw-security-guard
# Full audit
openclaw-guard audit
# Fix issues automatically (with backup)
openclaw-guard fix --auto
# Launch live dashboard
openclaw-guard dashboard
```
## Features
- **Security Score** (0-100) -- one number for your security posture
- **Auto-hardening** -- interactive, automatic, or dry-run modes
- **Live dashboard** -- real-time monitoring at localhost:18790
- **Pre-commit hooks** -- catch secrets before they're committed
- **Multi-language** -- English, French, Arabic
- **Zero telemetry** -- no tracking, no network requests, 100% local
## Links
- **Repository:** https://github.com/2pidata/openclaw-security-guard
- **Author:** [Miloud Belarebia](https://github.com/miloudbelarebia) / [2PiData](https://2pidata.com)
- **License:** MIT
Files in this skill
- PUBLICATION_GUIDE.md
- README.md
- SKILL.md
- docs/README.md
- docs/api/cli.md
- docs/api/programmatic.md
- docs/ar/README.md
- docs/en/README.md
- docs/fr/README.md
- docs/guides/getting-started.md
- package.json
- src/cli/index.js
- src/dashboard/server.js
- src/hardening/auto-hardener.js
- src/index.js
- src/monitors/cost-monitor.js
- src/monitors/realtime-monitor.js
- src/scanners/config-auditor.js
- src/scanners/dependency-scanner.js
- src/scanners/mcp-server-auditor.js
Attribution
Comments
Loading comments…