1password
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app…
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running
$ npx -y skills add the-open-agent/openagent --skill healthcheck --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/healthcheckContext preview
The summary Claude sees to decide when to auto-load this skill.
Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running
name: healthcheck description: Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
Assess and harden the host running OpenClaw, then align it to a user-defined risk tolerance without breaking access. Use OpenClaw security tooling as a first-class signal, but treat OS hardening as a separate, explicit set of steps.
Before starting, check the current model. If it is below state-of-the-art (e.g., Opus 4.5, GPT 5.2+), recommend switching. Do not block execution.
Try to infer 1–5 from the environment before asking. Prefer simple, non-technical questions if you need confirmation.
Determine (in order):
1. OS and version (Linux/macOS/Windows), container vs host. 2. Privilege level (root/admin vs user). 3. Access path (local console, SSH, RDP, tailnet). 4. Network exposure (public IP, reverse proxy, tunnel). 5. OpenClaw gateway status and bind address. 6. Backup system and status (e.g., Time Machine, system images, snapshots). 7. Deployment context (local mac app, headless gateway host, remote gateway, container/CI). 8. Disk encryption status (FileVault/LUKS/BitLocker). 9. OS automatic security updates status. Note: these are not blocking items, but are highly recommended, especially if OpenClaw can access sensitive data. 10. Usage mode for a personal assistant with full access (local workstation vs headless/remote vs other).
First ask once for permission to run read-only checks. If granted, run them by default and only ask questions for items you cannot infer or verify. Do not ask for information already visible in runtime or command output. Keep the permission ask as a single sentence, and list follow-up info needed as an unordered list (not numbered) unless you are presenting selectable choices.
If you must ask, use non-technical prompts:
Examples:
Only ask for the risk profile after system context is known.
If the user grants read-only permission, run the OS-appropriate checks by default. If not, offer them (numbered). Examples:
1. OS: `uname -a`, `sw_vers`, `cat /etc/os-release`. 2. Listening ports:
3. Firewall status:
4. Backups (macOS): `tmutil status` (if Time Machine is used).
As part of the default read-only checks, run `openclaw security audit --deep`. Only offer alternatives if the user requests them:
1. `openclaw security audit` (faster, non-probing) 2. `openclaw security audit --json` (structured output)
Offer to apply OpenClaw safe defaults (numbered):
1. `openclaw security audit --fix`
Be explicit that `--fix` only tightens OpenClaw defaults and file permissions. It does not change host firewall, SSH, or OS update policies.
If browser control is enabled, recommend that 2FA be enabled on all important accounts, with hardware keys preferred and SMS not sufficient.
As part of the default read-only checks, run `openclaw update status`.
Report the current channel and whether an update is available.
Ask the user to pick or confirm a risk posture and any required open services/ports (numbered choices below). Do not pigeonhole into fixed profiles; if the user prefers, capture requirements instead of choosing a profile. Offer suggested profiles as optional defaults (numbered). Note that most users pick Home/Workstation Balanced:
1. Home/Workstation Balanced (most common): firewall on with reasonable defaults, remote access restricted to LAN or tailnet. 2. VPS Hardened: deny-by-default inbound firewall, minimal open ports, key-only SSH, no root login, automatic security updates. 3. Developer Convenience: more local services allowed, explicit exposure warnings, still audited. 4. Custom: user-defined constraints (services, exposure, update cadence, access methods).
Provide a plan that includes:
⚡️next-generation personal AI assistant powered by LLM, RAG and agent loops, supporting computer-use, browser-use and coding agent, demo: https://demo.openagentai.org
Repo: the-open-agent/openagent
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app…
Manage Apple Notes via the `memo` CLI on macOS (create, view, edit, delete, search, move, and…
Manage Apple Reminders via remindctl CLI (list, add, edit, complete, delete). Supports lists,…
Monitor blogs and RSS/Atom feeds for updates using the blogwatcher CLI.