โ† All skills
Tencent SkillHub ยท Productivity

OpenClaw Security Hardening

Protect OpenClaw installations from prompt injection, data exfiltration, malicious skills, and workspace tampering

skill openclawclawhub Free
0 Downloads
0 Stars
0 Installs
0 Score
High Signal

Protect OpenClaw installations from prompt injection, data exfiltration, malicious skills, and workspace tampering

โฌ‡ 0 downloads โ˜… 0 stars Unverified but indexed

Install for OpenClaw

Quick setup
  1. Download the package from Yavira.
  2. Extract the archive and review SKILL.md first.
  3. Import or place the package into your OpenClaw setup.

Requirements

Target platform
OpenClaw
Install method
Manual import
Extraction
Extract archive
Prerequisites
OpenClaw
Primary doc
SKILL.md

Package facts

Download mode
Yavira redirect
Package format
ZIP package
Source platform
Tencent SkillHub
What's included
SKILL.md, assets/security-rules-template.md, scripts/audit-outbound.sh, scripts/harden-workspace.sh, scripts/install-guard.sh, scripts/integrity-check.sh

Validation

  • Use the Yavira download entry.
  • Review SKILL.md after the package is downloaded.
  • Confirm the extracted package contains the expected setup assets.

Install with your agent

Agent handoff

Hand the extracted package to your coding agent with a concrete install brief instead of figuring it out manually.

  1. Download the package from Yavira.
  2. Extract it into a folder your agent can access.
  3. Paste one of the prompts below and point your agent at the extracted folder.
New install

I downloaded a skill package from Yavira. Read SKILL.md from the extracted folder and install it by following the included instructions. Tell me what you changed and call out any manual steps you could not complete.

Upgrade existing

I downloaded an updated skill package from Yavira. Read SKILL.md from the extracted folder, compare it with my current installation, and upgrade it while preserving any custom configuration unless the package docs explicitly say otherwise. Summarize what changed and any follow-up checks I should run.

Trust & source

Release facts

Source
Tencent SkillHub
Verification
Indexed source record
Version
1.1.0

Documentation

ClawHub primary doc Primary doc: SKILL.md 10 sections Open source page

OpenClaw Security Hardening

A comprehensive security toolkit for protecting OpenClaw installations from attacks via malicious skill files, prompt injection, data exfiltration, and workspace tampering.

Threat Model

This skill protects against: ThreatDescriptionToolPrompt InjectionMalicious skills containing instructions to override system prompts, ignore safety rules, or manipulate agent behaviorscan-skills.shData ExfiltrationSkills that instruct the agent to send sensitive data (credentials, memory, config) to external endpointsaudit-outbound.shSkill TamperingUnauthorized modification of installed skills after initial reviewintegrity-check.shWorkspace ExposureSensitive files with wrong permissions, missing .gitignore rules, insecure gateway configharden-workspace.shSupply ChainInstalling a new skill that contains hidden malicious patternsinstall-guard.sh

Quick Start

# Run a full security scan of all installed skills ./scripts/scan-skills.sh # Audit outbound data flow patterns ./scripts/audit-outbound.sh # Initialize integrity baseline ./scripts/integrity-check.sh --init # Harden your workspace ./scripts/harden-workspace.sh --fix # Check a new skill before installing ./scripts/install-guard.sh /path/to/new-skill/

1. scan-skills.sh โ€” Skill File Scanner

Scans all installed skill files for malicious patterns including prompt injection, data exfiltration attempts, suspicious URLs, hidden unicode, obfuscated commands, and social engineering. Usage: # Scan all skill directories ./scripts/scan-skills.sh # Scan a specific directory only ./scripts/scan-skills.sh --path /path/to/skills/ # Output as JSON for automation ./scripts/scan-skills.sh --json # Show help ./scripts/scan-skills.sh --help What it detects: Prompt injection patterns (override instructions, new system prompts, admin overrides) Data exfiltration (curl/wget to external URLs, sending file contents) Suspicious URLs (webhooks, pastebin, requestbin, ngrok, etc.) Base64-encoded content that could hide instructions Hidden unicode characters (zero-width spaces, RTL override, homoglyphs) References to sensitive files (.env, credentials, API keys, tokens) Instructions to modify system files (AGENTS.md, SOUL.md) Obfuscated commands (hex encoded, unicode escaped) Social engineering ("don't tell the user", "secretly", "without mentioning") Severity levels: ๐Ÿ”ด CRITICAL โ€” Likely malicious, immediate action needed ๐ŸŸก WARNING โ€” Suspicious, review manually ๐Ÿ”ต INFO โ€” Noteworthy but probably benign

2. integrity-check.sh โ€” Skill Integrity Monitor

Creates SHA256 hash baselines of all skill files and detects unauthorized modifications. Usage: # Initialize baseline (first run) ./scripts/integrity-check.sh --init # Check for changes (run periodically) ./scripts/integrity-check.sh # Update baseline after reviewing changes ./scripts/integrity-check.sh --update # Check specific directory ./scripts/integrity-check.sh --path /path/to/skills/ # Show help ./scripts/integrity-check.sh --help Reports: โœ… Unchanged files โš ๏ธ Modified files (hash mismatch) ๐Ÿ†• New files (not in baseline) โŒ Removed files (in baseline but missing) Automation: Add to your heartbeat or cron to run daily: # In HEARTBEAT.md or cron 0 8 * * * /path/to/scripts/integrity-check.sh 2>&1 | grep -E '(MODIFIED|NEW|REMOVED)'

3. audit-outbound.sh โ€” Outbound Data Flow Auditor

Scans skill files for patterns that could cause data to leave your machine. Usage: # Audit all skills ./scripts/audit-outbound.sh # Audit specific directory ./scripts/audit-outbound.sh --path /path/to/skills/ # Show whitelisted domains ./scripts/audit-outbound.sh --show-whitelist # Add domain to whitelist ./scripts/audit-outbound.sh --whitelist example.com # Show help ./scripts/audit-outbound.sh --help Detects: HTTP/HTTPS URLs embedded in skill instructions References to curl, wget, fetch, web_fetch, browser navigate Email/message/webhook sending instructions Raw IP addresses in instructions Non-whitelisted external domains

4. harden-workspace.sh โ€” Workspace Hardener

Checks and fixes common security misconfigurations in your OpenClaw workspace. Usage: # Check only (report issues) ./scripts/harden-workspace.sh # Auto-fix safe issues ./scripts/harden-workspace.sh --fix # Show help ./scripts/harden-workspace.sh --help Checks: File permissions on sensitive files (MEMORY.md, USER.md, SOUL.md, credentials) .gitignore coverage for sensitive patterns Gateway auth configuration DM policy settings Sensitive content in version-controlled files

5. install-guard.sh โ€” Pre-Install Security Gate

Run before installing any new skill to check for malicious content. Usage: # Check a skill before installing ./scripts/install-guard.sh /path/to/new-skill/ # Strict mode (fail on warnings too) ./scripts/install-guard.sh --strict /path/to/new-skill/ # Show help ./scripts/install-guard.sh --help Checks: All patterns from scan-skills.sh Dangerous shell patterns in scripts (rm -rf, curl|bash, eval, etc.) Suspicious npm dependencies (if package.json exists) Exit code 0 = safe, 1 = suspicious (for CI/automation)

Security Rules Template

Copy assets/security-rules-template.md into your AGENTS.md to add runtime security rules for your agent. These rules instruct the agent to refuse prompt injection attempts and protect sensitive data. cat assets/security-rules-template.md >> /path/to/AGENTS.md

Recommended Setup

Initial setup: ./scripts/scan-skills.sh # Scan existing skills ./scripts/audit-outbound.sh # Audit outbound patterns ./scripts/integrity-check.sh --init # Create baseline ./scripts/harden-workspace.sh --fix # Fix workspace issues Add security rules to AGENTS.md from the template Before installing new skills: ./scripts/install-guard.sh /path/to/new-skill/ Periodic checks (add to heartbeat or cron): ./scripts/integrity-check.sh # Detect tampering ./scripts/scan-skills.sh # Re-scan for new patterns

Category context

Workflow acceleration for inboxes, docs, calendars, planning, and execution loops.

Source: Tencent SkillHub

Largest current source with strong distribution and engagement signals.

Package contents

Included in package
4 Scripts2 Docs
  • SKILL.md Primary doc
  • assets/security-rules-template.md Docs
  • scripts/audit-outbound.sh Scripts
  • scripts/harden-workspace.sh Scripts
  • scripts/install-guard.sh Scripts
  • scripts/integrity-check.sh Scripts