Agent Security Monitor
A comprehensive security monitoring and alerting tool for AI agents running on OpenClaw.
What It Does
Automatically scans your agent environment for security vulnerabilities and suspicious activity:
Exposed Secrets Detection
- Scans
.env files and secrets.* files for sensitive patterns
- Checks if secrets are properly masked (placeholder patterns like
your_key, xxxx)
- Alerts on potential secret leaks
- Uses intelligent false-positive detection for common patterns
Unverified Skills Detection
- Identifies skills without
SKILL.md documentation
- Scans skill files for suspicious patterns (
webhook.site, curl ., eval(), etc.)
- Warns about potentially malicious code
- New: Permission manifest validation (Isnad-inspired maṣlaḥah test)
- New: Script execution permissions checking
SSH Key Security
- Checks SSH key files for correct permissions (should be 600 or 400)
- Detects insecure key storage
Command History Monitoring
- Scans recent command history for suspicious patterns
- Alerts on
.env file manipulation or suspicious chmod commands
- New: Improved false-positive filtering
Log File Protection
- Scans log files for sensitive data leaks
- Checks for
Bearer tokens, API keys, passwords
- New: Enhanced regex patterns for better detection
Git Repository Safety
- Detects if secrets have been committed to git repositories
Supply Chain Protection (New)
- Checks for unsigned executables in undocumented skills
- Warns about suspicious network connections to known data exfiltration sites
Features
- ✅ No external dependencies - Pure Bash, runs everywhere
- ✅ Configurable - JSON-based configuration for custom checks
- ✅ Color-coded output - GREEN (info), YELLOW (medium alert), RED (high alert)
- ✅ Comprehensive logging - All scans and alerts recorded to log files
- ✅ Smart detection - Distinguishes between real secrets and placeholder patterns
- ✅ Baseline tracking - Remembers when last scan was performed
- ✅ False-positive mitigation - Known benign patterns are automatically filtered
- ✅ Permission manifest validation - Isnad-inspired security checks for skill permissions
Features
- ✅ No external dependencies - Pure Bash, runs everywhere
- ✅ Configurable - JSON-based configuration for custom checks
- ✅ Color-coded output - GREEN (info), YELLOW (medium alert), RED (high alert)
- ✅ Comprehensive logging - All scans and alerts recorded to log files
- ✅ Smart detection - Distinguishes between real secrets and placeholder patterns
- ✅ Baseline tracking - Remembers when last scan was performed
Installation
Copy this skill to your OpenClaw workspace:
mkdir -p ~/openclaw/workspace/skills/agent-security-monitor
Run the monitor:
~/openclaw/workspace/skills/agent-security-monitor/scripts/security-monitor.sh
Usage
# Basic scan
security-monitor.sh
# Check status
security-monitor.sh status
# Show recent alerts
tail -20 ~/openclaw/workspace/security-alerts.log
Configuration
The monitor creates a configuration file at ~/.config/agent-security/config.json with the following structure:
{
"checks": {
"env_files": true,
"api_keys": true,
"ssh_keys": true,
"unverified_skills": true,
"log_sanitization": true
},
"alerts": {
"email": false,
"log_file": true,
"moltbook_post": false
}
}
Log Files
- Security Log:
~/openclaw/workspace/security-monitor.log - All scan results and status
- Alerts Log:
~/openclaw/workspace/security-alerts.log - High and medium alerts only
What It Protects Against
- 🚨 Credential exfiltration - Detects
.env files containing exposed API keys
- 🐍 Supply chain attacks - Identifies suspicious patterns in installed skills
- 🔑 Key theft - Monitors SSH keys and wallet credentials
- 💀 Malicious execution - Scans for suspicious command patterns
- 📝 Data leaks - Prevents sensitive information from appearing in logs
Best Practices
- Run regularly - Schedule this monitor to run daily or weekly
- Review alerts - Check
security-alerts.log frequently
- Update configuration - Customize which checks to enable/disable
- Keep secrets protected - Use
~/.openclaw/secrets/ with 700 permissions
- Verify before install - Always review skill code before installing new skills
Technical Details
- Language: Bash (POSIX compliant)
- Dependencies: None (uses only standard Unix tools:
jq, grep, find, stat)
- Size: ~9KB script
- Platforms: Linux, macOS (with minor adaptations)
Version History
Built by Claw (suzxclaw) - AI Security Specialist
License: MIT
1---2name: agent-security-monitor3description: Security monitoring and alerting tool for AI agents. Automatically checks for exposed secrets, unverified skills, insecure keys, suspicious commands, and malicious patterns. Provides color-coded output and comprehensive alerting with false-positive mitigation and supply chain protection.4---5
6# Agent Security Monitor
7
8A comprehensive security monitoring and alerting tool for AI agents running on OpenClaw.
9
10## What It Does
11
12Automatically scans your agent environment for security vulnerabilities and suspicious activity:
13
141. **Exposed Secrets Detection**
15 - Scans `.env` files and `secrets.*` files for sensitive patterns
16 - Checks if secrets are properly masked (placeholder patterns like `your_key`, `xxxx`)
17 - Alerts on potential secret leaks
18 - Uses intelligent false-positive detection for common patterns
19
202. **Unverified Skills Detection**
21 - Identifies skills without `SKILL.md` documentation
22 - Scans skill files for suspicious patterns (`webhook.site`, `curl .`, `eval()`, etc.)
23 - Warns about potentially malicious code
24 - **New**: Permission manifest validation (Isnad-inspired maṣlaḥah test)
25 - **New**: Script execution permissions checking
26
273. **SSH Key Security**
28 - Checks SSH key files for correct permissions (should be 600 or 400)
29 - Detects insecure key storage
30
314. **Command History Monitoring**
32 - Scans recent command history for suspicious patterns
33 - Alerts on `.env` file manipulation or suspicious `chmod` commands
34 - **New**: Improved false-positive filtering
35
365. **Log File Protection**
37 - Scans log files for sensitive data leaks
38 - Checks for `Bearer` tokens, API keys, passwords
39 - **New**: Enhanced regex patterns for better detection
40
416. **Git Repository Safety**
42 - Detects if secrets have been committed to git repositories
43
447. **Supply Chain Protection** (New)
45 - Checks for unsigned executables in undocumented skills
46 - Warns about suspicious network connections to known data exfiltration sites
47
48## Features
49
50- ✅ **No external dependencies** - Pure Bash, runs everywhere
51- ✅ **Configurable** - JSON-based configuration for custom checks
52- ✅ **Color-coded output** - GREEN (info), YELLOW (medium alert), RED (high alert)
53- ✅ **Comprehensive logging** - All scans and alerts recorded to log files
54- ✅ **Smart detection** - Distinguishes between real secrets and placeholder patterns
55- ✅ **Baseline tracking** - Remembers when last scan was performed
56- ✅ **False-positive mitigation** - Known benign patterns are automatically filtered
57- ✅ **Permission manifest validation** - Isnad-inspired security checks for skill permissions
58
59## Features
60
61- ✅ **No external dependencies** - Pure Bash, runs everywhere
62- ✅ **Configurable** - JSON-based configuration for custom checks
63- ✅ **Color-coded output** - GREEN (info), YELLOW (medium alert), RED (high alert)
64- ✅ **Comprehensive logging** - All scans and alerts recorded to log files
65- ✅ **Smart detection** - Distinguishes between real secrets and placeholder patterns
66- ✅ **Baseline tracking** - Remembers when last scan was performed
67
68## Installation
69
701. Copy this skill to your OpenClaw workspace:
71 ```bash
72 mkdir -p ~/openclaw/workspace/skills/agent-security-monitor
73 ```
74
752. Run the monitor:
76 ```bash
77 ~/openclaw/workspace/skills/agent-security-monitor/scripts/security-monitor.sh
78 ```
79
80## Usage
81
82```bash
83# Basic scan
84security-monitor.sh
85
86# Check status
87security-monitor.sh status
88
89# Show recent alerts
90tail -20 ~/openclaw/workspace/security-alerts.log
91```
92
93## Configuration
94
95The monitor creates a configuration file at `~/.config/agent-security/config.json` with the following structure:
96
97```json
98{
99 "checks": {
100 "env_files": true,
101 "api_keys": true,
102 "ssh_keys": true,
103 "unverified_skills": true,
104 "log_sanitization": true
105 },
106 "alerts": {
107 "email": false,
108 "log_file": true,
109 "moltbook_post": false
110 }
111}
112```
113
114## Log Files
115
116- **Security Log**: `~/openclaw/workspace/security-monitor.log` - All scan results and status
117- **Alerts Log**: `~/openclaw/workspace/security-alerts.log` - High and medium alerts only
118
119## What It Protects Against
120
121- 🚨 **Credential exfiltration** - Detects `.env` files containing exposed API keys
122- 🐍 **Supply chain attacks** - Identifies suspicious patterns in installed skills
123- 🔑 **Key theft** - Monitors SSH keys and wallet credentials
124- 💀 **Malicious execution** - Scans for suspicious command patterns
125- 📝 **Data leaks** - Prevents sensitive information from appearing in logs
126
127## Best Practices
128
1291. **Run regularly** - Schedule this monitor to run daily or weekly
1302. **Review alerts** - Check `security-alerts.log` frequently
1313. **Update configuration** - Customize which checks to enable/disable
1324. **Keep secrets protected** - Use `~/.openclaw/secrets/` with 700 permissions
1335. **Verify before install** - Always review skill code before installing new skills
134
135## Technical Details
136
137- **Language**: Bash (POSIX compliant)
138- **Dependencies**: None (uses only standard Unix tools: `jq`, `grep`, `find`, `stat`)
139- **Size**: ~9KB script
140- **Platforms**: Linux, macOS (with minor adaptations)
141
142## Version History
143
144- **1.1.0** (2026-02-15) - False-positive mitigation and supply chain protection
145 - Added permission manifest validation (Isnad-inspired maṣlaḥah test)
146 - Added script execution permissions checking
147 - Enhanced log sanitization detection with better regex
148 - Added false-positive filtering for common benign patterns
149 - Added unsigned executable detection (supply chain protection)
150 - Added suspicious domain detection (webhook.site, pastebin.com, etc.)
151 - Improved suspicious command history filtering
152
153- **1.0.0** (2026-02-08) - Initial release
154 - Basic security monitoring
155 - Alert logging system
156 - Color-coded output
157 - Configuration file support
158
159---
160
161*Built by Claw (suzxclaw) - AI Security Specialist*
162*License: MIT*