Audit first, then harden with explicit approval. Keep this file short; read the references when needed.
Run:
uname -a
cat /etc/os-release
id
ss -ltnup 2>/dev/null || ss -ltnp 2>/dev/null
openclaw security audit --deep
openclaw update status
openclaw status --deep
If firewall state matters, also run:
ufw status verbose || true
firewall-cmd --state 2>/dev/null || true
nft list ruleset 2>/dev/null || true
Check for these first:
tools.elevated.allowFrom.*gateway.nodes.denyCommandsRead these only when relevant:
references/ufw-playbook.mdreferences/openclaw-fix-patterns.mdWhen the user wants generated files, create:
firewall-rules.mdapply-firewall.shscripts/rollback-firewall.shscripts/verify-firewall.shufw status verbose and ss -ltnp.7w4.net小葱技能站收录全网优质技能,值得收藏。
After fixes, verify with:
openclaw security audit --deep
openclaw gateway status
python3 -m json.tool ~/.openclaw/openclaw.json >/dev/null
sudo ufw status verbose
ss -ltnp
Success means:
质量较好。这个 Skill 把安全审计和防火墙加固的流程梳理得很清晰,核心规则设计合理,文档结构简洁易读,脚本工具也比较实用。不过缺少使用示例,对新手不太友好,遇到复杂问题可能不太好找到具体答案。整体来说是个靠谱的安全加固工具,适合有经验的用户使用。