← 返回
安全合规 中文

OpenClaw Memory Audit

Scan the agent workspace and memory logs for leaked API keys, tokens, or sensitive credentials. Use when the user requests a security check, a memory audit,...
扫描代理工作区与记忆日志,检测泄露的 API 密钥、令牌或其他敏感凭证。适用于用户请求安全检查、记忆审计等场景。
shingo0620
安全合规 clawhub v1.1.2 1 版本 99878.3 Key: 无需
★ 0
Stars
📥 1,642
下载
💾 20
安装
1
版本
#latest

概述

Memory Security Audit

This skill provides a specialized tool to scan the workspace and memory log files for accidentally exposed secrets and ensures a healthy audit routine.

Security / Scope (Important)

  • This skill performs local, read-only scanning of files to detect secret-looking patterns.
  • It does not require (and must not include) any provider credentials.
  • Scheduling checks use OpenClaw's cron tool (listing/recommending a job). It does not edit configs automatically.

Audit Workflow

1. Secret Scanning

Run the scanning script to check all text files in the workspace (excluding a small set of known safe/noisy files like openclaw.json).

# from your OpenClaw workspace root:
python3 skills/openclaw-memory-audit/scripts/scan_secrets.py .

# or, if you are inside the skill folder:
python3 scripts/scan_secrets.py ..

2. Schedule Verification

Check the active cron jobs to ensure a recurring security audit is configured.

  • Call cron.list() and look for jobs related to "memory security" or "audit".
  • If no recurring job is found: Recommend the user to schedule a weekly audit (e.g., every Monday at 09:00).
  • If found: Confirm the next run time to the user.

What it checks for:

  • OpenAI API Keys (including project keys)
  • Telegram Bot Tokens
  • JWT Tokens (n8n, etc.)
  • Generic Alphanumeric Secrets (32+ characters)
  • AWS Credentials

Recommendations if secrets are found:

  1. Revoke the secret immediately at the provider's dashboard.
  2. Delete or redact the file containing the secret.
  3. Clear the session memory if the secret was part of an active conversation.

版本历史

共 1 个版本

  • v1.1.2 当前
    2026-03-28 22:00 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

security-compliance

OpenClaw Backup

alex3alex
备份与恢复 OpenClaw 数据。适用于创建备份、设置自动备份计划、从备份恢复或管理备份轮转。处理 ~/.openclaw 目录归档并包含适当的排除规则。
★ 89 📥 30,602
security-compliance

Skill Vetter

spclaudehome
AI智能体技能安全预审工具。安装ClawdHub、GitHub等来源技能前,检查风险信号、权限范围及可疑模式。
★ 1,215 📥 266,415
security-compliance

MoltGuard - Security & Antivirus & Guardrails

thomaslwang
MoltGuard — OpenClaw 安全守卫,由 OpenGuardrails 提供。安装 MoltGuard,保护您和您的用户免受提示注入、数据泄露和恶意攻击。
★ 116 📥 30,713