MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

openclaw-security-hardening

openclaw-security-hardening is an engineering AI skill with a core value of Harden OpenClaw self-hosted environments with baseline host controls, auth tightening, secret handling, network segmentation, and safe update/rollback workflows. It helps developers solve real-world problems in the engineering domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Harden OpenClaw self-hosted environments with baseline host controls, auth tightening, secret handling, network segmentation, and safe update/rollback workflows.

Last verified on: 2026-10-06

Quick Facts

Category engineering
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level Low
mkdir -p ./skills/openclaw-security-hardening && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/openclaw-security-hardening/SKILL.md -o ./skills/openclaw-security-hardening/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

When to Use


- Provisioning, hardening, or operating the infrastructure described in this skill within an authorized environment.



# OpenClaw Security Hardening


Use this skill to reduce exposure in self-hosted OpenClaw deployments before opening access to teammates or external networks.


Build a Threat Model First


Map the highest-risk assets and paths:


- Admin/API endpoints for OpenClaw

- Provider API keys and model credentials

- Prompt/response logs containing sensitive business data

- Host-level access (SSH, local admin accounts, remote desktop)


Prioritize controls that reduce credential theft, remote code execution blast radius, and data exfiltration.


Apply Baseline Host Hardening


1. Keep OS and package dependencies patched on a regular cadence.

2. Run OpenClaw as a dedicated non-admin user account.

3. Enable full-disk encryption and secure boot features where available.

4. Remove unnecessary services and block inbound ports by default.

5. Lock down remote admin (key-only SSH, no password login, limited source CIDRs).


Example Linux baseline checks:


bash
id openclaw
sudo ss -tulpn
sudo ufw status verbose
sudo systemctl --failed

Harden Application Runtime


- Bind OpenClaw to localhost or private VLAN by default.

- Place a reverse proxy in front of OpenClaw for TLS, auth, and rate limits.

- Enforce authentication on every non-health endpoint.

- Disable debug/dev modes in persistent environments.

- Restrict outbound egress to only required providers (LLM API, telemetry sink, package mirror).


Example reverse proxy controls to enforce:


- TLS 1.2+ only

- strict transport security header

- request body size limits

- request timeout and upstream timeout guardrails

- per-IP and per-token rate limiting


Protect Secrets and Tokens


- Store secrets in a vault or platform secret manager, not committed `.env` files.

- Rotate provider and admin tokens on a fixed interval and after any incident.

- Scope tokens minimally (least privilege, per-service keys).

- Scan repos and deployment artifacts for leaked credentials before release.


Rotation checklist:


1. Generate replacement key.

2. Update runtime secret store.

3. Restart or reload OpenClaw.

4. Validate request success with new key.

5. Revoke old key.


Segment Network Access


Use layered access patterns:


- **Tier 1 (private):** OpenClaw service port reachable only from app/proxy subnet.

- **Tier 2 (operator):** Admin plane reachable only from VPN/Tailscale/WireGuard.

- **Tier 3 (public):** Expose only hardened reverse proxy with strict ACLs.


Do not publish raw OpenClaw service ports directly to the internet.


Add Detection and Recovery Paths


- Centralize auth, error, and audit logs.

- Alert on brute-force attempts, token failures, and unusual outbound traffic.

- Capture immutable backup snapshots of configs and prompt data retention settings.

- Test rollback and restore procedures every release cycle.


Minimum operational runbook:


- service restart path

- key revocation path

- incident isolation path (network block + token disable)

- known-good rollback version


Validation Checklist


- All sensitive endpoints require auth and are unreachable without VPN or gateway policy.

- Secrets are absent from repo history and plaintext shared directories.

- Host firewall default deny is active for inbound traffic.

- TLS termination and rate limits are active at ingress.

- Rollback drill can restore service within target RTO.


Related Skills


- openclaw-local-mac-mini (`openclaw-local-mac-mini`) - Local OpenClaw hosting setup

- multi-tenant-llm-hosting (`multi-tenant-llm-hosting`) - Multi-tenant AI isolation patterns

- zero-trust (`zero-trust`) - Private access and identity-aware network controls


When to Use


- You are provisioning, configuring, or troubleshooting the infrastructure component covered by this skill (servers, storage, databases, networking, cloud, local AI).


Limitations


- Infrastructure commands can disrupt services: confirm tar

🎯 Best For

  • Security auditors
  • DevSecOps teams
  • Compliance officers
  • Claude users
  • AI users

💡 Use Cases

  • Auditing dependencies for known CVEs
  • Scanning API endpoints for auth gaps
  • Using openclaw-security-hardening in daily workflow
  • Automating repetitive engineering tasks

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply openclaw-security-hardening to Your Work

    Provide context for your task — paste source material, describe your audience, or share existing work to guide the AI.

  4. 4

    Review and Refine

    Edit the AI output for accuracy, tone, and completeness. Add human insight where the AI lacks context.

❓ Frequently Asked Questions

Can this replace a dedicated SAST tool?

AI-based security review is complementary to SAST tools. Use it as a first-pass filter, not a replacement.

How do I install openclaw-security-hardening?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/openclaw-security-hardening/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Only scanning surface-level issues

Deep security review requires understanding your app architecture, not just regex patterns.

Not reading the full skill

Skills contain important context and edge cases beyond the quick start.

🔗 Related Skills