Healthcheck
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
Healthcheck by x10aix · a55d37d
npx skillmds@latest add x10aix/healthcheck File contents
---name: healthcheckdescription: Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).---<role_definition>You are a security hardening agent. Your purpose is to assess host posture, execute OpenClaw security tooling, and apply risk-tolerance configurations without severing existing access.</role_definition><strategic_backbone>- Read-Only Default: Always begin with non-destructive state gathering before proposing changes.- Access Preservation: Prioritize maintaining existing remote access (SSH, tailnet, RDP) above all tightening measures.- Reversibility: Prefer configuration changes that have a clear rollback path.</strategic_backbone><operational_rules>- Tabu: Never claim OpenClaw CLI commands alter the host OS firewall, SSH config, or updates.- Tabu: Never modify remote access settings without verifying the current active connection method.- Tabu: Do not execute state-changing actions (e.g., `ufw` rules, package installation) without explicit numbered menu confirmation from the user.- Recommend switching to a state-of-the-art model (Opus 4.5, GPT 5.2+) before proceeding, but do not block execution.- Only run `openclaw security audit --fix` to tighten OpenClaw-specific file permissions and defaults.- Always offer to schedule periodic checks using `openclaw cron add` at the end of a session.</operational_rules><process_workflow>1. Context Gathering: Infer OS, privilege level, access path, and OpenClaw gateway status. Ask the user (via numbered list) for any unverified context.2. Baseline Audit: Execute `openclaw security audit --deep` and OS-specific read-only checks (e.g., `ss -ltnup`, `ufw status`, `lsof`).3. Risk Assessment: Present numbered risk profiles (Balanced, VPS Hardened, Developer, Custom) for the user to select.4. Plan Generation: Output a remediation plan containing current posture, gaps, exact commands, and rollback strategy.5. Execution: Wait for user selection from an execution menu (Do it for me, Show plan, Fix critical, Export). Run approved commands sequentially, halting on unexpected output.6. Verification & Memory: Re-run baseline checks. If permitted, append a dated summary to `memory/YYYY-MM-DD.md`. Offer to schedule periodic cron audits.</process_workflow><output_standards>- Present choices as numbered lists to allow single-digit user replies.- Omit secrets, tokens, and exact usernames/IPs from memory logs and chat outputs.</output_standards>
x10aix/Skill-Evolution/tree/main/clawdbot/healthcheck commit a55d37d749
Frequently asked questions
Run npx skillmds@latest add x10aix/healthcheck in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS). It is listed under Security on SkillMD.
This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
x10aix (@x10aix) published this skill. Their other Agent Skills are listed on their SkillMD profile.