claw-release
Release automation for Claw skills and website. Guides through version bumping, tagging, and release verification.
Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
$ npx -y skills add prompt-security/clawsec --skill clawsec-nanoclaw --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/clawsec-nanoclawContext preview
The summary Claude sees to decide when to auto-load this skill.
Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
name: clawsec-nanoclaw version: 0.0.10 description: Use when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
Security advisory monitoring that protects your WhatsApp bot from known vulnerabilities in skills and dependencies.
Install with the Vercel Skills CLI for this harness:
npx skills add prompt-security/clawsec --skill clawsec-nanoclaw -a openclaw -y
ClawSec provides MCP tools that check installed skills against a curated feed of security advisories. It prevents installation of vulnerable skills, includes exploitability context for triage, and alerts you to issues in existing ones.
**Core principle:** Check before you install. Monitor what's running.
Use ClawSec tools when:
Do NOT use for:
// Before installing any skill
const safety = await tools.clawsec_check_skill_safety({
skillName: 'new-skill',
skillVersion: '1.0.0' // optional
});
if (!safety.safe) {
// Show user the risks before proceeding
console.warn(`Security issues: ${safety.advisories.map(a => a.id)}`);
}// Check all installed skills (defaults to ~/.claude/skills in the container)
const result = await tools.clawsec_check_advisories({
installRoot: '/home/node/.claude/skills' // optional
});
if (result.matches.some((m) =>
m.advisory.severity === 'critical' || m.advisory.exploitability_score === 'high'
)) {
// Alert user immediately
console.error('Urgent advisories found!');
}// List advisories with filters
const advisories = await tools.clawsec_list_advisories({
severity: 'high', // optional
exploitabilityScore: 'high' // optional
});| Task | Tool | Key Parameter | |------|------|---------------| | Pre-install check | `clawsec_check_skill_safety` | `skillName` | | Audit all skills | `clawsec_check_advisories` | `installRoot` (optional) | | Browse feed | `clawsec_list_advisories` | `severity`, `type`, `exploitabilityScore` (optional) | | Verify package signature | `clawsec_verify_skill_package` | `packagePath` | | Refresh advisory cache | `clawsec_refresh_cache` | (none) | | Check file integrity | `clawsec_check_integrity` | `mode`, `autoRestore` (optional) | | Approve file change | `clawsec_approve_change` | `path` | | View baseline status | `clawsec_integrity_status` | `path` (optional) | | Verify audit log | `clawsec_verify_audit` | (none) |
// ALWAYS check before installing
const safety = await tools.clawsec_check_skill_safety({
skillName: userRequestedSkill
});
if (safety.safe) {
// Proceed with installation
await installSkill(userRequestedSkill);
} else {
// Show user the risks and get confirmation
await showSecurityWarning(safety.advisories);
if (await getUserConfirmation()) {
await installSkill(userRequestedSkill);
}
}// Add to scheduled tasks
schedule_task({
prompt: "Check advisories using clawsec_check_advisories and alert when critical or high-exploitability matches appear",
schedule_type: "cron",
schedule_value: "0 9 * * *" // Daily at 9am
});User: "Are my skills secure?" You: I'll check installed skills for known vulnerabilities. [Use clawsec_check_advisories] Response: ✅ No urgent issues found. - 2 low-severity/low-exploitability advisories - All skills up to date
// DON'T
await installSkill('untrusted-skill');// DO
const safety = await tools.clawsec_check_skill_safety({
skillName: 'untrusted-skill'
});
if (safety.safe) await installSkill('untrusted-skill');// DON'T: Use severity only
if (advisory.severity === 'high') {
notifyNow(advisory);
}// DO: Use exploitability + severity
if (
advisory.exploitability_score === 'high' ||
advisory.severity === 'critical'
) {
notifyNow(advisory);
}// DON'T: Ignore high exploitability in medium severity advisories if (advisory.severity === 'critical') alert();
// DO: Prioritize exploitability and severity together
if (advisory.exploitability_score === 'high' || advisory.severity === 'critical') {
// Alert immediately
}**Feed Source**: https://clawsec.prompt.security/advisories/feed.json
This signed feed is consolidated. NanoClaw receives NVD CVEs, approved community advisories, and provisional GHSA-without-CVE advisories through the same default URL.
**Update Frequency**: Every 6 hours (automatic)
**Signature Verification**: Ed25519 signed feeds **Package Verification Policy**: pinned key only, bounded package/signature paths
**Cache Location**: `/workspace/project/data/clawsec-advisory-cache.json`
See [INSTALL.md](./INSTALL.md) for setup and [docs/](./docs/) for advanced usage.
For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metadata/SBO
A complete security skill suite for OpenClaw, Hermes, PicoClaw and NanoClaw agents (and variants). Protect your SOUL.md (etc') with drift detection, live security recommendations, automated audits, and skill integrity verification. All from one installable suite.
Repo: prompt-security/clawsec
Release automation for Claw skills and website. Guides through version bumping, tagging, and release verification.
ClawHub reputation checker for clawsec-suite. Adds a standalone reputation gate before guarded skill installation.
Security advisory feed package for OpenClaw-related threats and vulnerabilities. The upstream feed is updated daily; local automation is handled by…
Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub…
ClawSec suite manager with embedded advisory-feed monitoring, cryptographic signature verification, approval-gated malicious-skill response, and guided setup…
Harness-neutral community incident reporting for AI agents. Contribute to collective security by reporting threats.