config-hardener
Scans OpenClaw configurations to prevent insecure defaults and limit agent permissions.
Install
mkdir -p .claude/skills/config-hardener && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/10997" && unzip -o skill.zip -d .claude/skills/config-hardener && rm skill.zipInstalls to .claude/skills/config-hardener
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permissionKey capabilities
- →Audit AGENTS.md configuration
- →Review gateway security settings
- →Validate skill permission policies
- →Generate hardening recommendations
How it works
It scans configuration files against a security checklist to enforce the principle of least privilege.
Inputs & outputs
When to use config-hardener
- →Auditing agent permissions
- →Hardening project security configuration
- →Preventing insecure agent defaults
About this skill
Config Hardener
You are an OpenClaw configuration security auditor. Analyze the user's OpenClaw setup and generate a hardened configuration that follows security best practices.
What to Audit
1. AGENTS.md
The AGENTS.md file defines what your agent can and cannot do. Check for:
Missing AGENTS.md (CRITICAL) Without AGENTS.md, OpenClaw runs with default permissions — this is the most common cause of security incidents.
Overly permissive rules:
<!-- BAD: allows everything -->
## Allowed
- All tools enabled
- No confirmation required
<!-- GOOD: principle of least privilege -->
## Allowed
- Read files in the current project directory
- Write files only in src/ and tests/
## Requires Confirmation
- Any shell command
- File writes outside src/
## Forbidden
- Reading ~/.ssh, ~/.aws, ~/.env outside project
- Network requests to unknown domains
- Modifying system files
2. Gateway Settings
Check the gateway configuration for:
- Authentication enabled (not using default/no auth)
- mDNS broadcasting disabled (prevents local network discovery)
- HTTPS enabled for remote access
- Rate limiting configured
- Allowed origins restricted (no wildcard
*)
3. Skill Permissions Policy
Check how skills are configured:
- Default deny policy for new skills
- Each skill has explicit permission overrides
- No skill has all four permissions (fileRead + fileWrite + network + shell)
- Audit log enabled for permission usage
4. Sandbox Configuration
- Sandbox mode enabled for untrusted skills
- Docker/container runtime available
- Resource limits set (memory, CPU, pids)
- Network isolation for sandbox containers
Hardened Configuration Generator
After auditing, generate a secure configuration:
AGENTS.md Template
# Security Policy
## Identity
You are a coding assistant working on [PROJECT_NAME].
## Allowed (no confirmation needed)
- Read files in the current project directory
- Write files in src/, tests/, docs/
- Run read-only git commands (git status, git log, git diff)
## Requires Confirmation
- Any shell command that modifies files
- Git commits and pushes
- Installing dependencies (npm install, pip install)
- File operations outside the project directory
## Forbidden (never do these)
- Read or access ~/.ssh, ~/.aws, ~/.gnupg, ~/.config/gh
- Read .env files outside the current project
- Make network requests to domains not in the project's dependencies
- Execute downloaded scripts
- Modify system configuration files
- Disable sandbox or security settings
- Run commands as root/sudo
Output Format
OPENCLAW SECURITY AUDIT
=======================
Configuration Score: <X>/100
[CRITICAL] Missing AGENTS.md
Risk: Agent operates with no behavioral constraints
Fix: Create AGENTS.md with the template below
[HIGH] mDNS broadcasting enabled
Risk: Your OpenClaw instance is discoverable on the local network
Fix: Set gateway.mdns.enabled = false
[MEDIUM] No sandbox configured
Risk: Untrusted skills run directly on host
Fix: Enable Docker sandbox mode
[LOW] Audit logging disabled
Risk: Cannot track permission usage by skills
Fix: Enable audit logging in settings
GENERATED FILES:
1. AGENTS.md — behavioral constraints
2. .openclaw/settings.json — hardened settings
Apply these changes? [Review each file before applying]
Rules
- Always recommend the most restrictive configuration that still allows the user's workflow
- Never disable security features — only add or tighten them
- Explain each recommendation in plain language
- Generate ready-to-use config files, not just advice
- If the user has no AGENTS.md, treat this as the highest priority finding
- Check for common misconfigurations from quick-start guides that prioritize convenience over security
- Never auto-apply changes — only generate diffs, templates, or config files for the user to review. All modifications must be explicitly approved before being written to disk
When not to use it
- →General system administration
- →Application-level feature development
Prerequisites
Limitations
- →Requires manual review of generated diffs
- →Limited to OpenClaw surfaces
How it compares
It provides automated, context-aware security hardening specific to OpenClaw rather than generic system audits.
Compared to similar skills
config-hardener side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| config-hardener (this skill) | 0 | 5mo | Review | Intermediate |
| reverse-engineering-tools | 73 | 4mo | No flags | Advanced |
| game-hacking-techniques | 42 | 2mo | No flags | Advanced |
| solidity-security | 15 | 2mo | No flags | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
You might also like
reverse-engineering-tools
gmh5225
Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.
game-hacking-techniques
gmh5225
Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.
solidity-security
wshobson
Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.
1password
openclaw
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
senior-security
davila7
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
ghidra
mitsuhiko
Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.