OpenClaw Action
Overview
Set up CI security scanning for agent workspaces and skill repositories. Use this when a project needs pull request checks for exposed secrets, prompt injection markers, suspicious shell usage, or data exfiltration patterns in agent files.
What to Scan
skills/**, .claude/**, .codex/**, .openclaw/**, .agents/**, and other agent workspace folders.
- Scripts, hooks, install files, and generated instructions bundled with skills.
- Workflow files that grant network, token, or write permissions.
GitHub Actions Pattern
name: Agent Security Scan
on:
pull_request:
paths:
- 'skills/**'
- '.claude/**'
- '.codex/**'
- '.openclaw/**'
push:
branches: [main]
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Scan agent workspace
run: python scripts/scan-agent-workspace.py .
Findings to Flag
- API keys, private keys, tokens, passwords, and wallet material.
- Instructions that try to bypass higher-priority rules or reveal secrets.
- Shell snippets that download and execute remote code without verification.
- Unexpected network calls, webhooks, or upload commands.
- Broad file deletion, credential harvesting, or persistence mechanisms.
Operating Principles
The scan should detect and annotate risks without modifying repository files. Fail CI for high-confidence critical findings and emit a readable summary for lower-confidence warnings.
Source Notes
Adapted from the SkillsMP openclaw-action skill, selected because it is a highly starred security automation skill focused on agent workspace supply-chain risk.
1---2name: openclaw-action3description: OpenClaw Action4---56# OpenClaw Action78## Overview9Set up CI security scanning for agent workspaces and skill repositories. Use this when a project needs pull request checks for exposed secrets, prompt injection markers, suspicious shell usage, or data exfiltration patterns in agent files.1011## What to Scan12- `skills/**`, `.claude/**`, `.codex/**`, `.openclaw/**`, `.agents/**`, and other agent workspace folders.13- Scripts, hooks, install files, and generated instructions bundled with skills.14- Workflow files that grant network, token, or write permissions.1516## GitHub Actions Pattern17```yaml18name: Agent Security Scan19on:20 pull_request:21 paths:22 - 'skills/**'23 - '.claude/**'24 - '.codex/**'25 - '.openclaw/**'26 push:27 branches: [main]2829jobs:30 scan:31 runs-on: ubuntu-latest32 steps:33 - uses: actions/checkout@v434 - name: Scan agent workspace35 run: python scripts/scan-agent-workspace.py .36```3738## Findings to Flag39- API keys, private keys, tokens, passwords, and wallet material.40- Instructions that try to bypass higher-priority rules or reveal secrets.41- Shell snippets that download and execute remote code without verification.42- Unexpected network calls, webhooks, or upload commands.43- Broad file deletion, credential harvesting, or persistence mechanisms.4445## Operating Principles46The scan should detect and annotate risks without modifying repository files. Fail CI for high-confidence critical findings and emit a readable summary for lower-confidence warnings.4748## Source Notes49Adapted from the SkillsMP `openclaw-action` skill, selected because it is a highly starred security automation skill focused on agent workspace supply-chain risk.