/install security-network-hardening
Security + Network Hardening
Audit first, then harden with explicit approval. Keep this file short; read the references when needed.
Core rules
- Start read-only unless the user explicitly asks for fixes.
- Require confirmation before any state-changing action.
- Preserve current management access; do not break SSH/RDP/VNC.
- Prefer exact findings over generic advice.
- After workspace edits, commit them.
Read-only baseline
Run:
uname -a
cat /etc/os-release
id
ss -ltnup 2>/dev/null || ss -ltnp 2>/dev/null
openclaw security audit --deep
openclaw update status
openclaw status --deep
If firewall state matters, also run:
ufw status verbose || true
firewall-cmd --state 2>/dev/null || true
nft list ruleset 2>/dev/null || true
Priorities
Check for these first:
- elevated wildcard access in
tools.elevated.allowFrom.* - writable credentials directories
- missing gateway auth rate limiting
- broad or unclear listening ports
- metrics endpoints exposed too widely
- ineffective custom
gateway.nodes.denyCommands - workspace skill symlink escapes
Fix patterns
Read these only when relevant:
- UFW/firewall workflow:
references/ufw-playbook.md - OpenClaw config fixes:
references/openclaw-fix-patterns.md
Artifact generation
When the user wants generated files, create:
firewall-rules.mdapply-firewall.shscripts/rollback-firewall.shscripts/verify-firewall.sh
Safe firewall order
- Confirm allowed source subnet/IPs.
- Add SSH rule first if SSH is in use.
- Apply LAN-only and single-host rules.
- Verify from expected clients.
- Re-check
ufw status verboseandss -ltnp.
Verification
After fixes, verify with:
openclaw security audit --deep
openclaw gateway status
python3 -m json.tool ~/.openclaw/openclaw.json >/dev/null
sudo ufw status verbose
ss -ltnp
Success means:
- no critical audit findings
- no warning audit findings when practical
- gateway reachable
- required ports reachable only from approved sources
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install security-network-hardening - 安装完成后,直接呼叫该 Skill 的名称或使用
/security-network-hardening触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
Security Network Hardening 是什么?
Audit and harden an OpenClaw host and its network exposure. Use for security checks, hardening, firewall setup, network exposure review, metrics endpoint res... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 449 次。
如何安装 Security Network Hardening?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install security-network-hardening」即可一键安装,无需额外配置。
Security Network Hardening 是免费的吗?
是的,Security Network Hardening 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Security Network Hardening 支持哪些平台?
Security Network Hardening 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Security Network Hardening?
由 jimpang8(@jimpang8)开发并维护,当前版本 v1.0.0。