Security toolkit for OpenClaw – scanner, hardened configs, guides
Malicious OpenClaw skill scanner, but the market for hardening OpenClaw specifically is tiny.
Security scanner for AI coding agent configs — detects RCE hooks, invisible Unicode, credential exfiltration, and prompt injection in CLAUDE.md, settings.json, and .cursor/rules
Catches invisible Unicode tricks and RCE hooks in CLAUDE.md files.
DevSecOps engineers and teams using Claude Code or Cursor
Gitleaks · TruffleHog · Semgrep
Malicious OpenClaw skill scanner, but the market for hardening OpenClaw specifically is tiny.
LLM-on-LLM scanning catches obfuscation and semantic attacks before skills execute.
Hash-chained audit logs caught Claude Code attempting to inject staging endpoints into production config.
Makes agent configs first-class with 229 domain-specific rules, autofix, and LSP support — so a tiny syntax mistake stops being a silent failure. The cross-editor plugins and GitHub Action are the standout moves: lint in your IDE and enforce checks in CI. I want a clearer map of which rules target which toolchains, but the breadth of integrations is impressive.
Formal verification guarantees for agent skills replace heuristic scanning's 'no findings ≠ no risk' caveat.
Secures OpenClaw skills, but the ecosystem might not sustain the moat.