name: security-guardian description: Automated security auditing for OpenClaw projects. Scans for hardcoded secrets (API keys, tokens) and container vulnerabilities (CVEs) using Trivy. Provides structured reports to help maintain a clean and secure codebase. metadata: {"openclaw":{"requires":{"skills":["mema-vault"]}}}
System for automated security auditing and credential protection.
Scan specific project directories for hardcoded credentials.
- Tool: scripts/scan_secrets.py
- Usage: python3 $WORKSPACE/skills/security-guardian/scripts/scan_secrets.py <path_to_project>
- Workflow:
1. Execute scan on a specific project or directory.
2. If findings are reported (exit code 1):
- Review the file and line number.
- Transition: Move the secret to a secure vault (e.g., using the mema-vault skill).
- Redact: Replace the plaintext secret in the source code with an environment variable or a vault lookup call.
Analyze Docker images for vulnerabilities prior to deployment.
- Tool: scripts/scan_container.sh
- Usage: bash $WORKSPACE/skills/security-guardian/scripts/scan_container.sh <image_name>
- Logic: Identify HIGH and CRITICAL severities. Recommend base image updates or security patches.
小葱技能7w4.net有更新,你可以访问看下。
trivy to be installed on the host system.mema-vault.这个 Skill 质量较好,文档清晰、使用方便,能有效帮助检测代码中的密钥泄露和容器漏洞。优点是安全防护意识强,有防误扫机制,支持多种常见密钥类型检测。不足之处是容器扫描功能较简单,依赖外部工具安装,且缺少自动化测试覆盖。整体适合对安全性有一定要求的项目使用。