aaronjager92/openclaw-self-guard/SKILL.md
# OpenClaw Self Guard - Security Vulnerability Monitor Monitors OpenClaw for known security vulnerabilities by checking multiple threat intelligence sources. ## Features - **Version Detection**: Automatically detects local OpenClaw version - **CVE Monitoring**: Checks NVD, GitHub Security Advisories for OpenClaw-related CVEs - **Smart Alerting**: Outputs vulnerability details + remediation if found - **Silent Mode**: Runs silently if no vulnerabilities found - **Auto Cron**: Installs daily cr
npx skillsauth add openclaw/skills aaronjager92/openclaw-self-guardInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Monitors OpenClaw for known security vulnerabilities by checking multiple threat intelligence sources.
| Source | URL | Description |
|--------|-----|-------------|
| NVD | services.nvd.nist.gov | NIST National Vulnerability Database |
| GitHub Advisories | api.github.com/advisories | GitHub Security Advisory Database |
/openclaw 安全检查
/openclaw-self-guard check
/openclaw-self-guard version
Installed automatically during skill setup:
To customize delivery channel, edit ~/.openclaw/cron/jobs.json after installation:
"delivery": {
"mode": "announce",
"channel": "feishu" // or "telegram", etc.
}
When vulnerabilities found:
# 🔒 OpenClaw 安全漏洞报告
**检查时间**: 2026-03-31
**本地版本**: x.x.x
**检测到漏洞**: X 个
## 漏洞详情
| CVE ID | 严重性 | 描述 | 受影响版本 | 补救方案 |
When no vulnerabilities:
✅ OpenClaw v{x.x.x} - 未检测到安全漏洞
openclaw-self-guard/
├── SKILL.md
├── scripts/
│ ├── check_vulns.py # Main vulnerability check
│ ├── fetch_nvd.py # Fetch CVE from NVD
│ ├── fetch_github.py # Fetch from GitHub
│ ├── get_version.py # Get local version
│ └── setup_cron.sh # Cron auto-installation
└── references/
└── requirements.txt
requests, beautifulsoup4, lxmltools
Use when the user wants to connect to, test, or use the McDonalds service at mcp.mcd.cn, including checking authentication, probing MCP endpoints, listing tools, or calling McDonalds MCP tools through a reusable local CLI.
development
Web scraping platform — Twitter/X data, Vinted marketplace, and general web scraping API
development
SlowMist AI Agent Security Review — comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version)
data-ai
去除中文文本中的 AI 写作痕迹,使其读起来自然。基于维基百科 AI 写作特征指南,检测 24 种 AI 模式。触发词:humanizer-cn、去除 AI 痕迹、去除 AI 写作痕迹、中文文本人性化。