Overview
- Skill Key
- fletcherfrimpong/cyber-security-engineer
- Author
- fletcherfrimpong
- Source Repo
- openclaw/skills
- Version
- -
- Source Path
- skills/fletcherfrimpong/cyber-security-engineer
- Latest Commit SHA
- f6c529dbc2465f533f2b2964ca355a9c0ac78e3c
Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle timeout controls, port + egress monitoring, and ISO 27001/NIST-aligned compliance reporting with mitigations.
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
直接复制以下提示词,发送给你的 AI 助手即可完成安装。
请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 cyber-security-engineer 技能。 若已安装,则直接安装 cyber-security-engineer 技能。
# Cyber Security Engineer ## Requirements **Env vars (optional, but documented):** - `OPENCLAW_REQUIRE_POLICY_FILES` - `OPENCLAW_REQUIRE_SESSION_ID` - `OPENCLAW_TASK_SESSION_ID` - `OPENCLAW_APPROVAL_TOKEN` - `OPENCLAW_UNTRUSTED_SOURCE` - `OPENCLAW_VIOLATION_NOTIFY_CMD` - `OPENCLAW_VIOLATION_NOTIFY_ALLOWLIST` **Tools:** `python3` and one of `lsof`, `ss`, or `netstat` for port/egress checks. **Policy files (admin reviewed):** - `~/.openclaw/security/approved_ports.json` - `~/.openclaw/security/command-policy.json` - `~/.openclaw/security/egress_allowlist.json` - `~/.openclaw/security/prompt-policy.json` Implement these controls in every security-sensitive task: 1. Keep default execution in normal (non-root) mode. 2. Request explicit user approval before any elevated command. 3. Scope elevation to the minimum command set required for the active task. 4. Drop elevated state immediately after the privileged command completes. 5. Expire elevated state after 30 idle minutes and require re-approval. 6. Monitor listening network ports and flag insecure or unapproved exposure. 7. Monitor outbound connections and flag destinations not in the egress allowlist. 8. If no approved baseline exists, generate one with `python3 scripts/generate_approved_ports.py`, then review and prune. 9. Benchmark controls against ISO 27001 and NIST and report violations with mitigations. ## Non-Goals (Web Browsing) - Do not use web browsing / web search as part of this skill. Keep assessments and recommendations based on local host/OpenClaw state and the bundled references in this skill. ## Files To Use - `references/least-privilege-policy.md` - `references/port-monitoring-policy.md` - `references/compliance-controls-map.json` - `references/approved_ports.template.json` - `references/command-policy.template.json` - `references/prompt-policy.template.json` - `references/egress-allowlist.template.json` - `scripts/preflight_check.py` - `scripts/root_session_guard.py` - `scripts/audit_logger....
edholofy
University for AI agents. 92 courses, 4400+ scenarios, any model via OpenRouter. Auto-training loops generate per-model SKILL.md documents. Works with Claude Code, OpenClaw, Cursor, Windsurf. No fine-tuning required.
lethehades
macOS WPS Office workflow helper skill for safer document preparation, conversion, export, and compatibility guidance
capt-marbles
Web scraping and crawling with Firecrawl API. Fetch webpage content as markdown, take screenshots, extract structured data, search the web, and crawl documentation sites. Use when the user needs to scrape a URL, get current web info, capture a screenshot, extract specific data from pages, or crawl docs for a framework/library.
caqlayan
Tweet Processor Skill
carev01
Full-text search across structured Markdown documentation archives using SQLite FTS5. Use when you need to search large collections of Markdown articles that are separated by "---" delimiters and contain source URLs (marked with "*Source:" pattern). Provides fast BM25-ranked search with automatic source URL extraction for citations. Ideal for research, documentation lookups, and knowledge base exploration. Requires indexing documentation first with `docs.py index`.
camelsprout
DuckDB CLI specialist for SQL analysis, data processing and file conversion. Use for SQL queries, CSV/Parquet/JSON analysis, database queries, or data conversion. Triggers on "duckdb", "sql", "query", "data analysis", "parquet", "convert data".