OpenClaw Security Assistant
Paste the following prompt into your AI chat to install this skill:
Please install @user_ea52b310/safeassistant according to https://skillhub.cn/install/skillhub.md.
About this skill
The Problem
OpenClaw instances can face prompt injection, privilege bypass, encoding evasion, and information-disclosure risks when interacting with users, external systems, or other skills. Without consistent testing and access control, security rules may remain manual, making it hard to verify whether dangerous inputs are actually blocked or to separate what different roles can access.
How It Works
- One-click security check: When triggered by phrases such as security detection or vulnerability scanning, it prefers the latest malicious-prompt library from the cloud endpoint. If the endpoint is unavailable, it falls back to ten built-in test prompts. It runs the prompts against the current instance, records blocked versus successful attacks, and reports sample counts, risk categories, a
0-100score, and remediation suggestions. - Hardening: When triggered by hardening or defense strengthening, it reviews current security settings and applies safety constraints, permission checks, malicious-prompt blocking, and privacy-data protection rules, then generates a hardening summary.
- RBAC isolation: It guides the setup of role name, account, password, and permission scope, stores the permission table locally, and requires role verification before exposing features according to the assigned scope.
- Malicious-prompt collection: It identifies suspected malicious inputs, sanitizes personal information, tags categories such as
prompt injection,command execution, andencoding bypass, and syncs the feature to the shared word library.
Boundaries And Notes
This skill targets application-layer protection and access control for OpenClaw instances. It does not replace host security, network isolation, key management, or infrastructure controls. Security checks depend on the runtime environment and endpoint availability. Cloud reporting involves malicious-prompt features, so deployment should review data sources, endpoint addresses, and compliance requirements. RBAC is an application-level role mechanism and is not a complete audit or enterprise permission-governance solution for highly sensitive production systems.
Use Cases
- Run prompt-injection regression checks on an OpenClaw instance before release and produce a 0-100 risk score.
- Configure admin, audit, and user roles for a shared agent and verify access by role permissions.
- After suspicious privilege-escalation prompts appear, sanitize the samples and report them to the shared malicious-prompt library.
- Review hardening rules before store release to ensure interception, permission checks, and privacy protection are enabled.
Best For
- Engineers maintaining OpenClaw agents who need quick validation of prompt-injection and privilege-escalation blocking.
- Security teams preparing skill releases who need auditable reports, hardening notes, and compliance handling.
- Platform owners managing shared multi-role agents who need role-based isolation of features and data access.
- Security operations staff handling malicious-prompt samples who need sanitization, classification, and shared-library sync.
Related Skills
For independent developers, automates Git weekly reports, prioritized bug tickets, and project health checks into shareable Markdown.
Scan Windows caches, temporary files, and junk files, show space usage and risk levels, and clean selected items to free disk space.
Deploy a WeChat Service Account backend with Hermes AI, Nginx, systemd, and an admin dashboard on an Ubuntu/Debian VM.
Covers Jenkins, GitHub, and automation-related wrap workflows for IT operations and security.