Security Hardener

👤 mariusfit 📦 v1.0.0 ⭐ 4.4 ⬇️ 2.8K 下载
🔒 IT运维与安全 免费

📖 技能介绍

Security Hardener

Audit your OpenClaw configuration and apply security best practices automatically.

Quick Start

# Full security audit (read-only, no changes)
python scripts/hardener.py audit

# Audit a specific config file
python scripts/hardener.py audit --config /path/to/openclaw.json

# Audit with JSON output
python scripts/hardener.py audit -f json

# Auto-fix issues (creates backup first)
python scripts/hardener.py fix

# Fix specific issues only
python scripts/hardener.py fix --only gateway,permissions

# Scan for exposed credentials in config
python scripts/hardener.py scan-secrets

# Generate a security report
python scripts/hardener.py report -o security-report.md

# Check file permissions
python scripts/hardener.py check-perms

Commands

Command Args Description
audit [--config PATH] [-f FORMAT] Full security audit (read-only)
fix [--config PATH] [--only CHECKS] Auto-fix issues (with backup)
scan-secrets [--config PATH] Scan for exposed API keys/tokens
report [-o FILE] Generate detailed security report
check-perms [--config-dir PATH] Check file permissions

Security Checks

Check Severity Description
gateway-bind CRITICAL Gateway not bound to loopback
exposed-keys CRITICAL API keys in config instead of .env
insecure-auth HIGH allowInsecureAuth or dangerouslyDisableDeviceAuth enabled
exec-sandbox HIGH exec sandbox mode not set to restricted
file-perms HIGH Config files readable by others (not 600)
agent-allow-all MEDIUM agentToAgent.allow: ["*"] is overly permissive
no-heartbeat MEDIUM No heartbeat configured (can't detect outages)
no-session-reset MEDIUM No session reset policy (memory leak risk)
no-pruning LOW No context pruning (cost and performance impact)
no-memory-flush LOW Memory flush disabled (context loss on pruning)

Scoring

The audit produces a security score from 0-100:

  • 90-100: Excellent — production-ready
  • 70-89: Good — minor improvements recommended
  • 50-69: Fair — several issues to address
  • 0-49: Poor — critical issues require immediate attention

    小葱技能7w4.net持续更新中。

Example Output

╔══════════════════════════════════════════════════╗
║  OPENCLAW SECURITY AUDIT                         ║
╠══════════════════════════════════════════════════╣
║  Score: 75/100 (Good)                            ║
║                                                  ║
║  ✅ Gateway bound to loopback                    ║
║  ✅ No exposed API keys in config                ║
║  ⚠️  exec sandbox mode: unrestricted             ║
║  ⚠️  agentToAgent allow: * (too permissive)      ║
║  ❌ File permissions too open (644 → should be 600) ║
║  ✅ Heartbeat configured                         ║
║  ✅ Session reset policy active                   ║
║  ⚠️  No context pruning configured               ║
╚══════════════════════════════════════════════════╝

🤖 AI 评测

这是一款实用的安全审计工具,能自动检测 OpenClaw 配置中的10类安全隐患,并支持一键修复。界面友好、输出清晰,修复前会自动备份。评分系统让安全状况一目了然。扣分项是部分功能偶有小问题,以及缺少详细的配置说明文档。总体而言质量可靠,能有效提升部署安全性,适合对安全有要求的用户使用。

📊 多维度评分

适应性4.5
规范性4.3
有效性4.3
可靠性4.4
可信度4.5

📁 包含文件 (4 个)

📄 README.md 1.4 KB
📄 SKILL.md 3.7 KB
📄 _meta.json 139 B
📄 scripts/hardener.py 16.1 KB