Overview
- Skill Key
- bristy/trent-openclaw-security
- Author
- bristy
- Source Repo
- openclaw/skills
- Version
- 2.1.0
- Source Path
- skills/bristy/trent-openclaw-security
- Latest Commit SHA
- 06162c5f09dee6f0309073bf5d26e9fc1a393494
Audit your OpenClaw deployment for security risks using Trent AppSec Advisor
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
直接复制以下提示词,发送给你的 AI 助手即可完成安装。
请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 trent-openclaw-security 技能。 若已安装,则直接安装 trent-openclaw-security 技能。
# Trent OpenClaw Security Audit Security audit for your OpenClaw deployment powered by Trent AppSec Advisor. Analyzes your configuration for security risks and identifies chained attack paths where multiple misconfigurations combine to create worse outcomes. ## How It Works This skill uses the `trent-openclaw-audit` CLI command provided by the `trentai-mcp` Python package. The command: 1. Reads `~/.openclaw/` config files (METADATA ONLY — no secrets leave the machine) 2. Redacts detected credentials locally using pattern-based secret detection 3. Sends the sanitized metadata to Trent AppSec Advisor for AI-powered analysis 4. Prints security findings with severity ratings and chained attack path analysis Authentication requires a Trent API key (`TRENT_API_KEY` env var). Keys are generated via `trent-api-key create` (requires one-time browser login). OpenClaw prompts for the key during skill installation. ## Setup 1. Install the skill via ClawHub (this also installs `trent-api-key` and `trent-openclaw-audit` CLIs automatically): ``` clawhub install bristy/trent-openclaw-security ``` 2. OpenClaw will prompt for `TRENT_API_KEY`. If you don't have one yet, generate it on any machine with a browser: ``` trent-api-key create ``` 3. Paste the key when prompted. OpenClaw stores it in the skill config. ## When to Use **Reactive (user asks):** - User asks "Is my setup secure?" or "audit my config" - User asks about specific OpenClaw security concerns - User mentions security hardening or vulnerability scanning **Proactive (offer automatically):** - At the START of a new conversation, if no audit has been run recently, proactively say: "I can check your OpenClaw configuration for security risks. Would you like me to run a quick audit?" - After any change to ~/.openclaw/openclaw.json (config edits, new plugins, new MCP servers), offer: "Your configuration changed. Want me to run a quick security check?" - When the user installs a new plugin or skill,...
capt-marbles
Task Router
capncoconut
Register, communicate, and earn on the x402hub AI agent marketplace. Use when an agent needs to register on x402hub, browse or claim bounties, submit deliverables, send messages to other agents via x402 Relay, check marketplace stats, or manage agent credentials. Triggers on x402hub, agent marketplace, bounty, relay messaging, agent-to-agent communication, or USDC earning.
capevace
Real-time event bus for AI agents. Publish, subscribe, and share live signals across a network of agents with Unix-style simplicity.
captchasco
OpenClaw integration guidance for CAPTCHAS Agent API, including OpenResponses tool schemas and plugin tool registration.
carol-gutianle
name: modelready description: Start using a local or Hugging Face model instantly, directly from chat. metadata: {"openclaw":{"requires":{"bins": "bash", "curl" }, "env": "URL" }}
canbirlik
Controls Wiz smart bulbs (turn on/off, RGB colors, disco mode) via local WiFi.