← 返回
安全合规 中文

Firm Advanced Security Pack

Advanced security audit pack covering secrets lifecycle, path canonicalization, exec plan freeze, hook routing, config includes, prototype pollution, safeBin...
高级安全审计套件,涵盖密钥生命周期、路径规范化、执行计划冻结、钩子路由、配置包含、原型污染、safeBin...
romainsantoli-web
安全合规 clawhub v1.0.0 1 版本 100000 Key: 无需
★ 0
Stars
📥 568
下载
💾 11
安装
1
版本
#latest

概述

firm-advanced-security-pack

> ⚠️ Contenu généré par IA — validation humaine requise avant utilisation.

Purpose

Deep security auditing for OpenClaw configurations — covers external secrets lifecycle,

channel path canonicalization, execution plan freeze validation, hook session routing,

$include directive guards, prototype pollution detection, safeBins profile enforcement,

and group policy default audit.

Tools (8)

ToolDescriptionSeverity
-----------------------------
openclaw_secrets_lifecycle_checkExternal Secrets lifecycle auditCRITICAL
openclaw_channel_auth_canon_checkChannel path canonicalizationCRITICAL
openclaw_exec_approval_freeze_checkExec plan freeze validationCRITICAL
openclaw_hook_session_routing_checkHook session routing auditHIGH
openclaw_config_include_check$include directive guardsHIGH
openclaw_config_prototype_checkPrototype pollution detectionHIGH
openclaw_safe_bins_profile_checksafeBins profile enforcementHIGH
openclaw_group_policy_default_checkGroup policy default auditHIGH

Usage

skills:
  - firm-advanced-security-pack

# Run full advanced security audit:
openclaw_secrets_lifecycle_check config_path=/path/to/config.json
openclaw_config_prototype_check config_path=/path/to/config.json
openclaw_safe_bins_profile_check config_path=/path/to/config.json

Requirements

  • mcp-openclaw-extensions >= 3.0.0

版本历史

共 1 个版本

  • v1.0.0 当前
    2026-03-30 08:11 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

security-compliance

OpenClaw Backup

alex3alex
备份与恢复 OpenClaw 数据。适用于创建备份、设置自动备份计划、从备份恢复或管理备份轮转。处理 ~/.openclaw 目录归档并包含适当的排除规则。
★ 89 📥 30,600
security-compliance

Skill Vetter

spclaudehome
AI智能体技能安全预审工具。安装ClawdHub、GitHub等来源技能前,检查风险信号、权限范围及可疑模式。
★ 1,213 📥 266,390
ai-intelligence

Firm Orchestration

romainsantoli-web
用于OpenClaw的金字塔式多智能体编排:通过sessions_send等机制将CEO智能体的目标逐级路由至部门、服务和员工。
★ 0 📥 879