Crawler Summary

security-scanner answer-first brief

一键检查 OpenClaw 安全配置,防止被黑客监控。基于 Composio 专业安全指南的 16 项全面检查。 --- name: security-scanner description: 一键检查 OpenClaw 安全配置,防止被黑客监控。基于 Composio 专业安全指南的 16 项全面检查。 homepage: https://github.com/cicoccc/openclaw-security-scanner metadata: {"openclaw":{"emoji":"🛡️","requires":{"bins":["openclaw"]}}} --- 🛡️ OpenClaw Security Scanner 一键检查你的 OpenClaw 配置是否安全,防止配置不当导致的安全风险。 基于专业安全指南:Composio Security Guide、OpenClaw Official Docs。 快速检查 运行完整的安全扫描(16 项检查): **输出:** - 安全评分(0-100) - 三层风险分类(主机/自 Published capability contract available. No trust telemetry is available yet. 1 GitHub stars reported by the source. Last updated 3/1/2026.

Freshness

Last checked 3/1/2026

Best For

Contract is available with explicit auth and schema references.

Not Ideal For

security-scanner is not ideal for teams that need stronger public trust telemetry, lower setup complexity, or more explicit contract coverage before production rollout.

Evidence Sources Checked

editorial-content, capability-contract, runtime-metrics, public facts pack

Claim this agent
Agent DossierGitHubSafety: 89/100

security-scanner

一键检查 OpenClaw 安全配置,防止被黑客监控。基于 Composio 专业安全指南的 16 项全面检查。 --- name: security-scanner description: 一键检查 OpenClaw 安全配置,防止被黑客监控。基于 Composio 专业安全指南的 16 项全面检查。 homepage: https://github.com/cicoccc/openclaw-security-scanner metadata: {"openclaw":{"emoji":"🛡️","requires":{"bins":["openclaw"]}}} --- 🛡️ OpenClaw Security Scanner 一键检查你的 OpenClaw 配置是否安全,防止配置不当导致的安全风险。 基于专业安全指南:Composio Security Guide、OpenClaw Official Docs。 快速检查 运行完整的安全扫描(16 项检查): **输出:** - 安全评分(0-100) - 三层风险分类(主机/自

OpenClawself-declared

Public facts

7

Change events

1

Artifacts

0

Freshness

Mar 1, 2026

Verifiededitorial-contentNo verified compatibility signals1 GitHub stars

Published capability contract available. No trust telemetry is available yet. 1 GitHub stars reported by the source. Last updated 3/1/2026.

1 GitHub starsSchema refs publishedTrust evidence available

Trust score

Unknown

Compatibility

OpenClaw

Freshness

Mar 1, 2026

Vendor

Cicoccc

Artifacts

0

Benchmarks

0

Last release

Unpublished

Executive Summary

Key links, install path, and a quick operational read before the deeper crawl record.

Verifiededitorial-content

Summary

Published capability contract available. No trust telemetry is available yet. 1 GitHub stars reported by the source. Last updated 3/1/2026.

Setup snapshot

git clone https://github.com/cicoccc/openclaw-security-scanner.git
  1. 1

    Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.

  2. 2

    Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Evidence Ledger

Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.

Verifiededitorial-content
Vendor (1)

Vendor

Cicoccc

profilemedium
Observed Mar 1, 2026Source linkProvenance
Compatibility (2)

Protocol compatibility

OpenClaw

contractmedium
Observed Feb 24, 2026Source linkProvenance

Auth modes

api_key

contracthigh
Observed Feb 24, 2026Source linkProvenance
Artifact (1)

Machine-readable schemas

OpenAPI or schema references published

contracthigh
Observed Feb 24, 2026Source linkProvenance
Adoption (1)

Adoption signal

1 GitHub stars

profilemedium
Observed Mar 1, 2026Source linkProvenance
Security (1)

Handshake status

UNKNOWN

trustmedium
Observed unknownSource linkProvenance
Integration (1)

Crawlable docs

6 indexed pages on the official domain

search_documentmedium
Observed Apr 15, 2026Source linkProvenance

Release & Crawl Timeline

Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.

Self-declaredagent-index

Artifacts Archive

Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.

Self-declaredGITHUB OPENCLEW

Extracted files

0

Examples

4

Snippets

0

Languages

typescript

Parameters

Executable Examples

bash

{baseDir}/scripts/security_check.sh

bash

{baseDir}/scripts/security_fix.sh

bash

{baseDir}/scripts/security_report.sh

text

🛡️  OpenClaw Security Scanner v2.0
Based on Professional Security Guidelines
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔍 检查分类:
  🔴 主机安全 (Host Compromise)
  🟡 自动化控制 (Agency Control)
  🔵 凭证保护 (Credential Leakage)

━━━ 🔴 主机安全检查 ━━━
✅ Gateway 绑定配置... 安全
✅ 端口监听状态... 安全
⚠️  Docker 隔离... 直接运行在主机

━━━ 🔵 凭证保护检查 ━━━
❌ 明文 API Keys... 发现 3 个可疑凭证

📊 安全评分: 72/100
👍 良好 - 有小问题需要优化

🎯 风险分类:
  🔴 主机安全风险: 0
  🟡 自动化控制风险: 1
  🔵 凭证泄露风险: 2

Docs & README

Full documentation captured from public sources, including the complete README when available.

Self-declaredGITHUB OPENCLEW

Docs source

GITHUB OPENCLEW

Editorial quality

ready

一键检查 OpenClaw 安全配置,防止被黑客监控。基于 Composio 专业安全指南的 16 项全面检查。 --- name: security-scanner description: 一键检查 OpenClaw 安全配置,防止被黑客监控。基于 Composio 专业安全指南的 16 项全面检查。 homepage: https://github.com/cicoccc/openclaw-security-scanner metadata: {"openclaw":{"emoji":"🛡️","requires":{"bins":["openclaw"]}}} --- 🛡️ OpenClaw Security Scanner 一键检查你的 OpenClaw 配置是否安全,防止配置不当导致的安全风险。 基于专业安全指南:Composio Security Guide、OpenClaw Official Docs。 快速检查 运行完整的安全扫描(16 项检查): **输出:** - 安全评分(0-100) - 三层风险分类(主机/自

Full README

name: security-scanner description: 一键检查 OpenClaw 安全配置,防止被黑客监控。基于 Composio 专业安全指南的 16 项全面检查。 homepage: https://github.com/cicoccc/openclaw-security-scanner metadata: {"openclaw":{"emoji":"🛡️","requires":{"bins":["openclaw"]}}}

🛡️ OpenClaw Security Scanner

一键检查你的 OpenClaw 配置是否安全,防止配置不当导致的安全风险。

基于专业安全指南:Composio Security Guide、OpenClaw Official Docs。

快速检查

运行完整的安全扫描(16 项检查):

{baseDir}/scripts/security_check.sh

输出:

  • 安全评分(0-100)
  • 三层风险分类(主机/自动化/凭证)
  • 详细问题列表
  • 修复建议

一键修复

自动修复发现的安全问题:

{baseDir}/scripts/security_fix.sh

修复内容:

  • Gateway 绑定设置
  • 启用 Token 认证
  • 文件权限修复
  • 插件白名单设置
  • 自动备份配置

生成报告

生成详细的安全报告(Markdown 格式):

{baseDir}/scripts/security_report.sh

检查项目

🔴 主机安全 (Host Compromise)

  • Gateway 绑定配置(bind: all = 危险)
  • 端口监听状态(0.0.0.0 = 暴露)
  • 认证配置(auth.mode: none = 无保护)
  • Docker 隔离检查(建议容器化)
  • 版本检查(v2026.1.29+ 强制密码)

🟡 自动化控制 (Agency Control)

  • 工具权限审计(tools.elevated)
  • Hooks 安全检查
  • 浏览器控制审计
  • 频道访问策略(open = 任何人可消息)

🔵 凭证保护 (Credential Leakage)

  • 明文 API Keys 扫描(最重要!)
  • Credentials 目录权限
  • 配置文件权限
  • 会话历史文件权限
  • 日志文件权限
  • 插件白名单
  • Tailscale 配置

评分说明

  • 90-100: ✨ 优秀 - 配置非常安全
  • 70-89: 👍 良好 - 有小问题需要优化
  • 50-69: ⚠️ 需要改进 - 存在中等风险
  • 0-49: 🚨 危险 - 立即修复!

使用场景

  • 首次部署后验证配置
  • 定期安全检查(建议每周)
  • 看到安全警告后快速自查
  • 生成合规报告
  • 防止类似 1800+ 实例暴露的灾难

输出示例

🛡️  OpenClaw Security Scanner v2.0
Based on Professional Security Guidelines
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

🔍 检查分类:
  🔴 主机安全 (Host Compromise)
  🟡 自动化控制 (Agency Control)
  🔵 凭证保护 (Credential Leakage)

━━━ 🔴 主机安全检查 ━━━
✅ Gateway 绑定配置... 安全
✅ 端口监听状态... 安全
⚠️  Docker 隔离... 直接运行在主机

━━━ 🔵 凭证保护检查 ━━━
❌ 明文 API Keys... 发现 3 个可疑凭证

📊 安全评分: 72/100
👍 良好 - 有小问题需要优化

🎯 风险分类:
  🔴 主机安全风险: 0
  🟡 自动化控制风险: 1
  🔵 凭证泄露风险: 2

注意事项

  • 自动修复会修改配置文件(会先备份)
  • 建议先运行检查,确认后再修复
  • 与官方 openclaw security audit --deep 配合使用最佳
  • 定期检查可防患于未然

参考资源

Contract & API

Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.

Verifiedcapability-contract

Contract coverage

Status

ready

Auth

api_key

Streaming

No

Data region

global

Protocol support

OpenClaw: self-declared

Requires: openclew, lang:typescript

Forbidden: none

Guardrails

Operational confidence: medium

Contract is available with explicit auth and schema references.
Trust confidence is not low and verification freshness is acceptable.
Invocation examples
curl -s "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/snapshot"
curl -s "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/contract"
curl -s "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/trust"

Reliability & Benchmarks

Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.

Missingruntime-metrics

Trust signals

Handshake

UNKNOWN

Confidence

unknown

Attempts 30d

unknown

Fallback rate

unknown

Runtime metrics

Observed P50

unknown

Observed P95

unknown

Rate limit

unknown

Estimated cost

unknown

No benchmark suites or observed failure patterns are available.

Media & Demo

Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.

Missingno-media
No screenshots, media assets, or demo links are available.

Related Agents

Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.

Self-declaredprotocol-neighbors
GITHUB_REPOSactivepieces

Rank

70

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

Traction

No public download signal

Freshness

Updated 2d ago

OPENCLAW
GITHUB_REPOScherry-studio

Rank

70

AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs

Traction

No public download signal

Freshness

Updated 5d ago

MCPOPENCLAW
GITHUB_REPOSAionUi

Rank

70

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

Traction

No public download signal

Freshness

Updated 6d ago

MCPOPENCLAW
GITHUB_REPOSCopilotKit

Rank

70

The Frontend for Agents & Generative UI. React + Angular

Traction

No public download signal

Freshness

Updated 23d ago

OPENCLAW
Machine Appendix

Contract JSON

{
  "contractStatus": "ready",
  "authModes": [
    "api_key"
  ],
  "requires": [
    "openclew",
    "lang:typescript"
  ],
  "forbidden": [],
  "supportsMcp": false,
  "supportsA2a": false,
  "supportsStreaming": false,
  "inputSchemaRef": "https://github.com/cicoccc/openclaw-security-scanner#input",
  "outputSchemaRef": "https://github.com/cicoccc/openclaw-security-scanner#output",
  "dataRegion": "global",
  "contractUpdatedAt": "2026-02-24T19:44:53.573Z",
  "sourceUpdatedAt": "2026-02-24T19:44:53.573Z",
  "freshnessSeconds": 4428468
}

Invocation Guide

{
  "preferredApi": {
    "snapshotUrl": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/snapshot",
    "contractUrl": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/contract",
    "trustUrl": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/trust"
  },
  "curlExamples": [
    "curl -s \"https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/snapshot\"",
    "curl -s \"https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/contract\"",
    "curl -s \"https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/trust\""
  ],
  "jsonRequestTemplate": {
    "query": "summarize this repo",
    "constraints": {
      "maxLatencyMs": 2000,
      "protocolPreference": [
        "OPENCLEW"
      ]
    }
  },
  "jsonResponseTemplate": {
    "ok": true,
    "result": {
      "summary": "...",
      "confidence": 0.9
    },
    "meta": {
      "source": "GITHUB_OPENCLEW",
      "generatedAt": "2026-04-17T01:52:42.094Z"
    }
  },
  "retryPolicy": {
    "maxAttempts": 3,
    "backoffMs": [
      500,
      1500,
      3500
    ],
    "retryableConditions": [
      "HTTP_429",
      "HTTP_503",
      "NETWORK_TIMEOUT"
    ]
  }
}

Trust JSON

{
  "status": "unavailable",
  "handshakeStatus": "UNKNOWN",
  "verificationFreshnessHours": null,
  "reputationScore": null,
  "p95LatencyMs": null,
  "successRate30d": null,
  "fallbackRate": null,
  "attempts30d": null,
  "trustUpdatedAt": null,
  "trustConfidence": "unknown",
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Capability Matrix

{
  "rows": [
    {
      "key": "OPENCLEW",
      "type": "protocol",
      "support": "unknown",
      "confidenceSource": "profile",
      "notes": "Listed on profile"
    }
  ],
  "flattenedTokens": "protocol:OPENCLEW|unknown|profile"
}

Facts JSON

[
  {
    "factKey": "docs_crawl",
    "category": "integration",
    "label": "Crawlable docs",
    "value": "6 indexed pages on the official domain",
    "href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceType": "search_document",
    "confidence": "medium",
    "observedAt": "2026-04-15T05:03:46.393Z",
    "isPublic": true
  },
  {
    "factKey": "vendor",
    "category": "vendor",
    "label": "Vendor",
    "value": "Cicoccc",
    "href": "https://github.com/cicoccc/openclaw-security-scanner",
    "sourceUrl": "https://github.com/cicoccc/openclaw-security-scanner",
    "sourceType": "profile",
    "confidence": "medium",
    "observedAt": "2026-03-01T06:04:53.259Z",
    "isPublic": true
  },
  {
    "factKey": "traction",
    "category": "adoption",
    "label": "Adoption signal",
    "value": "1 GitHub stars",
    "href": "https://github.com/cicoccc/openclaw-security-scanner",
    "sourceUrl": "https://github.com/cicoccc/openclaw-security-scanner",
    "sourceType": "profile",
    "confidence": "medium",
    "observedAt": "2026-03-01T06:04:53.259Z",
    "isPublic": true
  },
  {
    "factKey": "protocols",
    "category": "compatibility",
    "label": "Protocol compatibility",
    "value": "OpenClaw",
    "href": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/contract",
    "sourceUrl": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/contract",
    "sourceType": "contract",
    "confidence": "medium",
    "observedAt": "2026-02-24T19:44:53.573Z",
    "isPublic": true
  },
  {
    "factKey": "auth_modes",
    "category": "compatibility",
    "label": "Auth modes",
    "value": "api_key",
    "href": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/contract",
    "sourceUrl": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/contract",
    "sourceType": "contract",
    "confidence": "high",
    "observedAt": "2026-02-24T19:44:53.573Z",
    "isPublic": true
  },
  {
    "factKey": "schema_refs",
    "category": "artifact",
    "label": "Machine-readable schemas",
    "value": "OpenAPI or schema references published",
    "href": "https://github.com/cicoccc/openclaw-security-scanner#input",
    "sourceUrl": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/contract",
    "sourceType": "contract",
    "confidence": "high",
    "observedAt": "2026-02-24T19:44:53.573Z",
    "isPublic": true
  },
  {
    "factKey": "handshake_status",
    "category": "security",
    "label": "Handshake status",
    "value": "UNKNOWN",
    "href": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/trust",
    "sourceUrl": "https://xpersona.co/api/v1/agents/cicoccc-openclaw-security-scanner/trust",
    "sourceType": "trust",
    "confidence": "medium",
    "observedAt": null,
    "isPublic": true
  }
]

Change Events JSON

[
  {
    "eventType": "docs_update",
    "title": "Docs refreshed: Sign in to GitHub · GitHub",
    "description": "Fresh crawlable documentation was indexed for the official domain.",
    "href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceType": "search_document",
    "confidence": "medium",
    "observedAt": "2026-04-15T05:03:46.393Z",
    "isPublic": true
  }
]

Sponsored

Ads related to security-scanner and adjacent AI workflows.