TopRank Skills

Home / Claw Skills / Git / GitHub / openclaw-action
Official OpenClaw rules 90%

openclaw-action

GitHub Action for automated security scanning of agent workspaces. Detects exposed secrets, prompt/shell injection, and data exfiltration patterns in PRs and commits.

Stars

0

Installs

0

Status

ACTIVE

Visibility

PUBLIC

安装方式

直接复制以下提示词,发送给你的 AI 助手即可完成安装。

请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 openclaw-action 技能。 若已安装,则直接安装 openclaw-action 技能。

Overview

Skill Key
atlaspa/openclaw-action
Author
atlaspa
Source Repo
openclaw/skills
Version
-
Source Path
skills/atlaspa/openclaw-action
Latest Commit SHA
7b0ddbd26c782dc0a2edced26923b7472baadd1c

Extracted Content

SKILL.md excerpt

# OpenClaw Security Action

GitHub Action that scans agent skills for security issues on every PR.

## What It Scans

| Scanner | What It Catches |
|---------|-----------------|
| **sentry** | API keys, tokens, passwords, credentials in code |
| **bastion** | Prompt injection markers, shell injection patterns |
| **egress** | Suspicious network calls, data exfiltration patterns |

## Quick Start

Add to `.github/workflows/security.yml`:

```yaml
name: Security Scan
on:
  pull_request:
    paths:
      - 'skills/**'
      - '.openclaw/**'
  push:
    branches: [main]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: AtlasPA/openclaw-action@v1
        with:
          workspace: '.'
          fail-on-findings: 'true'
```

## Inputs

| Input | Default | Description |
|-------|---------|-------------|
| `workspace` | `.` | Path to scan |
| `fail-on-findings` | `true` | Fail the check if issues found |
| `scan-secrets` | `true` | Enable secret scanning |
| `scan-injection` | `true` | Enable injection scanning |
| `scan-egress` | `true` | Enable egress scanning |

## Outputs

| Output | Description |
|--------|-------------|
| `findings-count` | Total number of issues found |
| `has-critical` | `true` if critical/high severity issues |

## Philosophy

This action **detects and alerts only**. It will:
- Flag security issues in PR checks
- Annotate specific lines with findings
- Generate a summary report

It will NOT:
- Automatically modify your code
- Quarantine or delete files
- Make any changes to your repository

For automated remediation, see [OpenClaw Pro](https://github.com/sponsors/AtlasPA).

## Requirements

- Python 3.8+ (auto-installed by action)
- No external dependencies

README excerpt

# OpenClaw Security Action

GitHub Action for automated security scanning of agent workspaces. Catches secrets, injection attacks, and exfiltration patterns before they land in your repo.

## Why This Exists

Agent skill marketplaces have a supply chain security problem. Since January 2026, 341+ malicious skills have been identified on ClawHub and similar registries — trojanized utilities with reverse shells, credential stealers, and silent data exfiltration.

This action brings the [OpenClaw Security Suite](https://github.com/AtlasPA/openclaw-security) into your CI pipeline, scanning skills before they can cause damage.

## Quick Start

```yaml
# .github/workflows/security.yml
name: Security Scan
on:
  pull_request:
    paths:
      - 'skills/**'
      - '.openclaw/**'
  push:
    branches: [main]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: AtlasPA/openclaw-action@v1
```

That's it. PRs touching your skills directory will now be scanned.

## What It Catches

### Secret Exposure (sentry)
- API keys (AWS, GCP, GitHub, Stripe, OpenAI, etc.)
- Hardcoded passwords and tokens
- Private keys and certificates
- High-entropy strings that look like credentials

### Injection Attacks (bastion)
- Prompt injection markers (`[SYSTEM]`, `<|im_start|>`)
- Shell injection patterns (`eval()`, `exec()`, `subprocess` with `shell=True`)
- Unicode homoglyphs and directional overrides
- Hidden instructions in HTML comments

### Data Exfiltration (egress)
- Suspicious `requests.post()` and `urllib` calls
- Hardcoded IP addresses and short-lived domains
- Credential-to-network data flows
- DNS exfiltration patterns

## Configuration

### Inputs

| Input | Default | Description |
|-------|---------|-------------|
| `workspace` | `.` | Path to scan (repository root by default) |
| `fail-on-findings` | `true` | Fail the check if any security issues are found |
| `scan-secrets` | `true` | Run secret/credential scanning |
| `scan-injectio...

Related Claw Skills

heyixuan2

bambu-studio-ai

★ 41

Bambu Lab 3D printer control and automation. Activate when user mentions: printer status, 3D printing, slice, analyze model, generate 3D, AMS filament, print monitor, Bambu Lab, or any 3D printing task. Full pipeline: search → generate → analyze → colorize → preview → open BS → user slice → print → monitor. Supports all 9 Bambu Lab printers (A1 Mini, A1, P1S, P2S, X1C, X1E, H2C, H2S, H2D).

capt-marbles

geo-optimization

★ 1

Generative Engine Optimization (GEO) for AI search visibility. Optimize content to appear in ChatGPT, Perplexity, Claude, and Google AI Overviews. Use when optimizing websites, pages, or content for LLM discoverability and citation.

carlulsoe

parakeet-stt

★ 0

Local speech-to-text with NVIDIA Parakeet TDT 0.6B v3 (ONNX on CPU). 30x faster than Whisper, 25 languages, auto-detection, OpenAI-compatible API. Use when transcribing audio files, converting speech to text, or processing voice recordings locally without cloud APIs.

carlzhao007

feishu-process-feedback

★ 0

飞书消息自动处理与进度反馈技能。安装后后台运行,监听飞书任务消息并自动创建独立进程处理。 在处理前后发送实时进度反馈(任务确认、进度百分比、完成通知)。 支持任务类型识别、智能解析、错误重试、并发控制、状态持久化。 使用场景:飞书自动化工作流、任务进度追踪、批量任务处理、需要实时反馈的场景。

cartoonitunes

bottyfans

★ 0

BottyFans agent skill for autonomous creator monetization. Lets AI agents register, build a profile, publish posts (public, subscriber-only, or pay-to-unlock), upload media, accept USDC subscriptions and tips on Base, send and receive DMs, track earnings, and appear on the creator leaderboard. Use this skill when an agent needs to monetize content, interact with fans, manage a creator profile, handle payments in USDC, or operate as an autonomous creator on the BottyFans platform.

camopel

arxivkb

★ 0

Local arXiv paper manager with semantic search. Crawls arXiv categories, downloads PDFs, chunks content, and indexes with FAISS + Ollama embeddings. No cloud API keys required — everything runs locally.