Firm Advanced Security Pack
/install firm-advanced-security-pack
firm-advanced-security-pack
⚠️ Contenu généré par IA — validation humaine requise avant utilisation.
Purpose
Deep security auditing for OpenClaw configurations — covers external secrets lifecycle,
channel path canonicalization, execution plan freeze validation, hook session routing,
$include directive guards, prototype pollution detection, safeBins profile enforcement,
and group policy default audit.
Tools (8)
| Tool | Description | Severity |
|---|---|---|
openclaw_secrets_lifecycle_check |
External Secrets lifecycle audit | CRITICAL |
openclaw_channel_auth_canon_check |
Channel path canonicalization | CRITICAL |
openclaw_exec_approval_freeze_check |
Exec plan freeze validation | CRITICAL |
openclaw_hook_session_routing_check |
Hook session routing audit | HIGH |
openclaw_config_include_check |
$include directive guards |
HIGH |
openclaw_config_prototype_check |
Prototype pollution detection | HIGH |
openclaw_safe_bins_profile_check |
safeBins profile enforcement | HIGH |
openclaw_group_policy_default_check |
Group policy default audit | HIGH |
Usage
skills:
- firm-advanced-security-pack
# Run full advanced security audit:
openclaw_secrets_lifecycle_check config_path=/path/to/config.json
openclaw_config_prototype_check config_path=/path/to/config.json
openclaw_safe_bins_profile_check config_path=/path/to/config.json
Requirements
mcp-openclaw-extensions >= 3.0.0
- Make sure OpenClaw is installed (local or Docker)
- Run the install command in chat:
/install firm-advanced-security-pack - After installation, invoke the skill by name or use
/firm-advanced-security-pack - Provide required inputs per the skill's parameter spec and get structured output
What is Firm Advanced Security Pack?
Advanced security audit pack covering secrets lifecycle, path canonicalization, exec plan freeze, hook routing, config includes, prototype pollution, safeBin... It is an AI Agent Skill for Claude Code / OpenClaw, with 347 downloads so far.
How do I install Firm Advanced Security Pack?
Run "/install firm-advanced-security-pack" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.
Is Firm Advanced Security Pack free?
Yes, Firm Advanced Security Pack is completely free (open-source). You can download, install and use it at no cost.
Which platforms does Firm Advanced Security Pack support?
Firm Advanced Security Pack is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).
Who created Firm Advanced Security Pack?
It is built and maintained by romainsantoli-web (@romainsantoli-web); the current version is v1.0.0.