Clawaudit

Automated security audit for OpenClaw gateway hosts

Security⚠ ReviewIntermediatev1.9.4
Last verified:March 2026

About

Clawaudit is the official automated security audit skill for OpenClaw gateway hosts — currently in active development. It performs threat modelling on your OpenClaw installation, audits skill configurations for dangerous patterns, checks for exposed environment variables, and produces a structured security report. Given thousands of unvetted community skills exist, having an automated auditor on your gateway is increasingly important.

Use Cases

  • Audit your entire OpenClaw setup for security vulnerabilities in one command
  • Detect skills with dangerous shell access or environment variable exposure
  • Generate a security report you can share with clients or your team
  • Monitor your gateway host for new threats as the skill ecosystem evolves

What Clawaudit can access

Broad access

Read this skill's SKILL.md in full before installing it. Run it against a disposable host or test account first, and give it the narrowest credentials that still work.

  • Runs commands on the host

    This skill executes commands on the machine running the agent. That is the broadest permission you can grant: anything the agent user can do, this skill can do.

    This skill's own description refers to "shell"

These permissions are inferred from this listing — the credentials it declares, any maintainer warning, and the operations its own description mentions. ClawVault has not audited this skill's source code. Treat it as a starting point for your own review, not a substitute for one.

Installing Clawaudit on OpenClaw

An OpenClaw skill is a directory containing a SKILL.md file: Markdown with YAML frontmatter. At startup OpenClaw scans the eligible skill directories and injects a compressed description of each skill into its system prompt, so the agent knows what it can do and invokes a skill when a request matches.

  1. 1

    Find the skill in the registry

    openclaw skills search clawaudit

    ClawHub is the public registry for OpenClaw skills. Searching first gives you the exact owner-qualified reference, which is what the install command needs. Omit the query to browse the default feed.

  2. 2

    Check what it does and who published it

    openclaw skills verify @<owner>/clawaudit

    verify prints ClawHub's verification envelope, including its scan decision and, when available, a commit-pinned source URL. Add --card to read the generated Skill Card instead. Substitute the owner handle returned by the search above.

  3. 3

    Install it

    openclaw skills install @<owner>/clawaudit

    Native ClawHub skills use an @owner/slug reference. By default this installs into the active workspace skills/ directory; add --global to install into the shared managed directory instead. You can also install from Git with git:owner/repo, or from a local folder with ./path.

  4. 4

    Confirm the agent can see it

    openclaw skills check

    check reports which ready skills are actually visible to the agent's prompt surface, which is the quickest way to catch a skill that installed but did not load.

Commands follow the official OpenClaw documentation. Placeholders such as <owner> are filled in by the search step, because registry references are publisher-scoped.

Version & Updates

Current Version
1.9.4
Last Updated
March 6, 2026

Safety & verification

Needs review
Not yet independently confirmed. Read the SKILL.md before running it on a OpenClaw install you care about.

How OpenClaw screens skills

Since February 2026 ClawHub screens submitted skills with VirusTotal: each bundle is hashed and looked up, new bundles are scanned with Code Insight, and results drive an approve, warn or block decision with daily re-scanning. This materially reduces supply-chain risk but does not eliminate it, and independent research has found that different scanners frequently disagree about the same skill. Read the SKILL.md of anything you install, especially if it requests shell access or credentials.

Review before installing

Read this skill's SKILL.md before installing it, so you know what commands it runs and which credentials it reads.

Recommended

Running on a VPS?

Deploy OpenClaw, Hermes, or PicoClaw on Bluehost with the right template for the job.

Related Skills in Security