Overview
- Skill Key
- clawdssen/security-hardening
- Author
- The Agent Ledger
- Source Repo
- openclaw/skills
- Version
- 1.0.0
- Source Path
- skills/clawdssen/security-hardening
- Latest Commit SHA
- a4606173e5377524c715a510230d34c91bc5110f
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
直接复制以下提示词,发送给你的 AI 助手即可完成安装。
请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 security-hardening 技能。 若已安装,则直接安装 security-hardening 技能。
# Security Hardening — by The Agent Ledger > **Just deliver this skill to your agent.** One paste, and your agent knows how to audit your workspace for leaked secrets, harden configs, and defend against prompt injection — no coding, no security expertise required. Your agent reads the instructions and handles the rest. A security audit and hardening skill for AI agents. Ensures your workspace doesn't leak secrets, your configs resist prompt injection, and your agent operates with defense-in-depth principles. **Version:** 1.0.0 **License:** CC-BY-NC-4.0 **More:** [theagentledger.com](https://www.theagentledger.com) --- ## What This Skill Does When triggered, the agent performs a comprehensive security audit and applies hardening measures: 1. **Credential Scan** — Detect leaked API keys, tokens, passwords in workspace files 2. **Privacy Audit** — Find personal information (names, emails, addresses) that shouldn't be in shared files 3. **Config Hardening** — Add security standing orders to AGENTS.md, SOUL.md, etc. 4. **Prompt Injection Defense** — Review agent instructions for injection vulnerabilities 5. **File Permission Review** — Identify overly permissive file sharing or public exposure 6. **Remediation Report** — Actionable summary with severity ratings --- ## Quick Start Tell your agent: > "Run a security audit on my workspace" Or trigger via heartbeat/cron for periodic checks. --- ## Setup ### Step 1: Understand the Audit Scope The audit covers all files in your agent's workspace directory. It does NOT: - Access files outside the workspace - Make network requests - Modify files without confirmation - Send any data externally ### Step 2: Run the Initial Audit Ask your agent to perform each check below. Review findings before applying fixes. --- ## Audit Checks ### Check 1: Credential Scan Scan all workspace files for patterns matching: | Pattern | Examples | |---------|----------| | API keys | `sk-...`, `AKIA...`, `ghp_...`, `xoxb-...` | |...
heyixuan2
Bambu Lab 3D printer control and automation. Activate when user mentions: printer status, 3D printing, slice, analyze model, generate 3D, AMS filament, print monitor, Bambu Lab, or any 3D printing task. Full pipeline: search → generate → analyze → colorize → preview → open BS → user slice → print → monitor. Supports all 9 Bambu Lab printers (A1 Mini, A1, P1S, P2S, X1C, X1E, H2C, H2S, H2D).
human-pages-ai
Search and hire real humans for tasks — photography, delivery, research, and more
zseven-w
Reusable skill templates for OpenClaw AI agents. Templates for API integration, data processing, web scraping, CLI tools, and file processing.
capt-marbles
Generative Engine Optimization (GEO) for AI search visibility. Optimize content to appear in ChatGPT, Perplexity, Claude, and Google AI Overviews. Use when optimizing websites, pages, or content for LLM discoverability and citation.
cchacons
The job marketplace where bots hire bots. Post FREE or paid $WAGE jobs, with on-chain escrow, faucet rewards, referrals, judge staking, task inbox, smart matching, checkpoints, oversight, webhooks, onboarding, and human owner dashboard.
cchacons
The job marketplace where bots hire bots. Post FREE or paid $WAGE jobs, with on-chain escrow, faucet rewards, referrals, judge staking, task inbox, smart matching, checkpoints, oversight, webhooks, onboarding, and human owner dashboard.