ClawdStrike by cantinaxyz/clawdstrike
npx skills add https://github.com/cantinaxyz/clawdstrike --skill ClawdStrike审计 OpenClaw 部署中的配置错误和实际攻击路径。生成一份确定性的 OK/VULNERABLE 报告,包含严重性、证据和修复方案。
scripts/collect_verified.sh(无需确认提示)。scripts/collect_verified.sh。scripts/collect_verified.sh --deep。verified-bundle.json。没有此文件不得生成报告。references/report-format.md 中的报告结构。广告位招租
在这里展示您的产品或服务
触达数万 AI 开发者,精准高效
verified-bundle.json 构建报告头(时间戳、模式=已验证、操作系统、OpenClaw 版本、状态目录、配置路径、运行时上下文)。verified-bundle.json 中的证据,评估 references/required-checks.md 中的每一项检查。references/threat-model.md 包含一个简洁的威胁模型。references/evidence-template.md 中的模式输出发现结果表格。verified-bundle.json 中的一个键,并包含一个简短、脱敏的摘录。VULNERABLE (UNVERIFIED) 并请求重新运行。fw.* 输出中确认。如果只有 fw.none 存在,标记为 VULNERABLE (UNVERIFIED) 并请求验证。使用 references/threat-model.md 并保持其简洁且与发现结果一致。
references/required-checks.md(强制性检查清单)references/report-format.md(报告结构)references/gateway.md(网关暴露和认证)references/discovery.md(mDNS 和广域网发现)references/canvas-browser.md(画布主机和浏览器控制)references/network.md(端口和防火墙检查)references/verified-allowlist.md(严格的已验证模式命令列表)references/channels.md(DM/群组策略、访问组、白名单)references/tools.md(沙盒、Web/浏览器工具、提升执行)references/filesystem.md(权限、符号链接、SUID/SGID、同步文件夹)references/supply-chain.md(技能/插件清单和模式扫描)references/config-keys.md(权威配置键映射)references/evidence-template.md(显示哪些证据,对哪些内容脱敏)references/redaction.md(一致的脱敏规则)references/version-risk.md(版本和补丁级别指南)references/threat-model.md(威胁模型模板)每周安装量
311
代码仓库
GitHub 星标
17
首次出现
2026年2月5日
安全审计
安装于
openclaw248
codex185
gemini-cli177
opencode176
github-copilot166
amp155
Audit an OpenClaw deployment for misconfigurations and real-world attack paths. Produce a deterministic OK/VULNERABLE report with severity, evidence, and fixes.
scripts/collect_verified.sh immediately (no consent prompt).scripts/collect_verified.sh in the current working directory.scripts/collect_verified.sh --deep only if the user explicitly requests a local gateway probe.verified-bundle.json. Do not produce a report without it.references/report-format.md for the report structure.verified-bundle.json (timestamp, mode=Verified, OS, OpenClaw version, state dir, config path, runtime context).references/required-checks.md using evidence from verified-bundle.json.references/threat-model.md.references/evidence-template.md.verified-bundle.json key and include a short, redacted excerpt.VULNERABLE (UNVERIFIED) and request a re-run.fw.* output. If only fw.none exists, mark VULNERABLE (UNVERIFIED) and request verification.Use references/threat-model.md and keep it brief and aligned with findings.
references/required-checks.md (mandatory checklist)references/report-format.md (report structure)references/gateway.md (gateway exposure and auth)references/discovery.md (mDNS and wide-area discovery)references/canvas-browser.md (canvas host and browser control)references/network.md (ports and firewall checks)references/verified-allowlist.md (strict Verified-mode command list)references/channels.md (DM/group policies, access groups, allowlists)references/tools.md (sandbox, web/browser tools, elevated exec)Weekly Installs
311
Repository
GitHub Stars
17
First Seen
Feb 5, 2026
Security Audits
Gen Agent Trust HubFailSocketPassSnykWarn
Installed on
openclaw248
codex185
gemini-cli177
opencode176
github-copilot166
amp155
Azure Data Explorer (Kusto) 查询技能:KQL数据分析、日志遥测与时间序列处理
100,500 周安装
references/filesystem.md (permissions, symlinks, SUID/SGID, synced folders)references/supply-chain.md (skills/plugins inventory and pattern scan)references/config-keys.md (authoritative config key map)references/evidence-template.md (what evidence to show, what to redact)references/redaction.md (consistent redaction rules)references/version-risk.md (version and patch-level guidance)references/threat-model.md (threat model template)