OpenClaw Security Audit Tool
English | ไธญๆ | Deutsch | Franรงais | Italiano | ๆฅๆฌ่ช | Espaรฑol
Statistics show: 220,000+ OpenClaw instances are exposed publicly. Many API keys have already been leaked to hacker databases.
| ๐จ Risk | ๐ฅ Consequence | โก Severity |
|---|---|---|
| Gateway exposed to public | Anyone can access your AI assistant | ๐ด Critical |
| Weak or leaked token | API keys stolen, unexpected charges | ๐ Severe |
| Camera/screen accessible | Privacy compromised, screenshots taken | ๐ Severe |
| Full Disk Access granted | All files accessible by AI | ๐ก High Risk |
| IP in leak database | Already targeted by hackers | ๐ก High Risk |
./scripts/quick-check.shOne command checks 5 critical security items:
- ๐ Is Gateway exposed to public network
- ๐ Is Token strength sufficient
- ๐ท Are sensitive commands blocked
- ๐พ Are TCC permissions reasonable
- ๐ Is your IP already leaked
./scripts/interactive-fix.shOne-click fix common problems:
- Rebind Gateway to localhost
- Generate new strong Token
- Add sensitive command blacklist
./scripts/ip-leak-check.sh --allExclusive Feature: Integrated with openclaw.allegro.earth, Censys, and Shodan databases to check if your IP has been leaked
| Advantage | Description |
|---|---|
| ๐ฏ OpenClaw Focused | Designed specifically for OpenClaw, deeper and more precise checks |
| ๐ Privacy-First | Not just system security, but privacy leak risks |
| ๐ IP Leak Detection | The only tool integrated with leak database |
| ๐ง One-Click Fix | Auto-fix issues, no manual intervention needed |
| ๐ History Tracking | Record every audit result, track security trends |
| ๐ค CI/CD Ready | GitHub Actions automation included |
|
|
|
|
| โ Perfect for You | โ Not for You |
|---|---|
| Run OpenClaw / MoltBot / ClawdBot on Mac | Don't use OpenClaw or similar AI assistants |
| Concerned about AI assistant security | OpenClaw runs in completely isolated environment |
| OpenClaw connects to external services (Feishu, Telegram) | Already have a professional security team |
| Mac stores sensitive data (work files, personal photos) | |
| Want regular security checks |
The simplest way: Just ask your AI assistant!
ๅธฎๆๆฃๆฅไธไธ OpenClaw ็ๅฎๅ
จๆง
Claude Code will automatically:
- Clone ClawGears repository
- Run security audit
- Explain results in plain language
- Offer to fix issues
# Install ClawGears skill
clawhub install clawgears-securityauditThen ask OpenClaw:
ๅธฎๆๅไธไธชๅฎๆด็ๅฎๅ
จๅฎก่ฎก
git clone https://github.com/JinHanAI/ClawGears.git
cd ClawGears
./clawgears.sh# Clone the repository
git clone https://github.com/JinHanAI/ClawGears.git
cd ClawGears
# Launch interactive menu
./clawgears.shMenu Preview:
โโโโโโโโโโ โโโ โโโโโโโโ โโโโโโโ โโโโโโโ โโโโโโโโโโโ โโโ
โโโโโโโโโโโ โโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโโ
โโโ โโโ โโโ โโโโโโ โโโ โโโโโโ โโโโโโโโโ โโโโโโโ
โโโ โโโ โโโ โโโโโโ โโโ โโโโโโ โโโโโโโโโ โโโโโ
โโโโโ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโ โโโ
โโโโ โโโโโโโโโโโโโโโโโโโโโโโโ โโโโโโโ โโโโโโโ โโโ โโโ โโโ
OpenClaw Security Audit Tool
Protect Your Mac, Guard Your Privacy
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
What would you like to do?
[1] Quick Security Check (5 critical items, ~5 sec)
[2] Full Security Audit (All checks, detailed report)
[3] Check IP Leak (allegro.earth, Censys, Shodan)
[4] Interactive Fix (Auto-fix security issues)
[5] Generate Report (HTML/JSON format)
[6] System Security (Firewall, FileVault, SIP)
[H] Help & Documentation
[Q] Quit
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Enter your choice [1-6, H, Q]: _
Menu Options:
| Option | Description | Time |
|---|---|---|
[1] Quick Security Check |
5 critical items | ~5 sec |
[2] Full Security Audit |
All checks + detailed report | ~30 sec |
[3] Check IP Leak |
Query allegro.earth, Censys, Shodan | ~10 sec |
[4] Interactive Fix |
Auto-fix security issues | Varies |
[5] Generate Report |
HTML/JSON format | ~5 sec |
[6] System Security |
Firewall, FileVault, SIP | ~5 sec |
========================================
OpenClaw Quick Security Check
========================================
[INFO] Checking OpenClaw configuration...
========================================
Network Exposure Check
========================================
[โ
PASS] Gateway is safely bound (127.0.0.1:18789)
[โ
PASS] No public network exposure detected
========================================
Token Security Check
========================================
[โ
PASS] Token length is sufficient (64 characters)
[โ
PASS] Token configuration is valid
========================================
Command Protection Check
========================================
[โ
PASS] Sensitive commands are blocked:
- screencapture
- camerasnap
- osascript
========================================
Summary
========================================
โ
All checks passed! Your OpenClaw is secure.
========================================
Checking openclaw.allegro.earth
========================================
Your Public IP: 45.xxx.xxx.xxx
[โ
PASS] Your IP is NOT in the exposure database
========================================
Checking Censys Database
========================================
[INFO] Censys is an internet scanning database
Check your IP at:
๐ https://search.censys.io/hosts/45.xxx.xxx.xxx
========================================
Checking Shodan Database
========================================
[INFO] Shodan is another internet scanning database
Check your IP at:
๐ https://www.shodan.io/host/45.xxx.xxx.xxx
========================================
Leak Check Summary
========================================
[โ
PASS] No exposure detected
ClawGears now provides scenario-based risk analysis instead of one-size-fits-all recommendations:
========================================
2. FileVault Encryption Check
========================================
๐ What this check protects:
Prevents data access if your disk is stolen or lost
FileVault Status: FileVault is Off.
โก Real impact based on your scenario:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Usage Scenario โ Risk โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ Mac fixed in secure office โ ๐ข Low โ
โ Frequently carried outside (cafe/travel) โ ๐ Highโ
โ Stores sensitive data (finance/client info) โ ๐ด V.Highโ
โ Needs remote restart control (SSH) โ โช OK โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ก Recommendation:
Level: [Optional] (Decide based on your scenario)
โข If you disabled FileVault for remote control needs, this is reasonable
โข You can compensate the risk with:
- Physical security (keep Mac in safe location)
- Regular backups of important data
========================================
1. Gateway Network Exposure Check
========================================
๐ What this check protects:
Detects if OpenClaw Gateway is exposed to the public internet
Gateway Binding: *:18789 (EXPOSED!)
โก Real impact:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Risk: Anyone on the internet can access your AI โ
โ Impact: API keys stolen, unexpected charges, โ
โ privacy leaked โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ก Recommendation:
Level: [๐ด Must Fix]
Fix this issue? [Y/n]: Y
[INFO] Rebinding Gateway to localhost...
[INFO] Updating configuration...
[INFO] Restarting Gateway service...
[โ
PASS] Gateway is now safely bound to 127.0.0.1
# Quick check (5 critical items)
./scripts/quick-check.sh./scripts/ip-leak-check.sh --all./scripts/generate-report.sh --format html --output ./reports./scripts/interactive-fix.sh| Check | Description |
|---|---|
| Network Exposure | Gateway port binding, Tailscale status |
| Token Security | Length, configuration validation |
| Command Injection Protection | denyCommands configuration |
| TCC Permission Audit | Full Disk Access, Accessibility |
| Process Monitoring | Background services, unknown processes |
| iCloud Sync Check | Documents/Pictures/Desktop |
| Workspace Privacy | Sensitive files, symlinks |
| Network Connection Monitoring | External domain whitelist |
| Log Audit | Anomaly detection |
| System Security | Firewall, FileVault, SIP |
| Feature | Command |
|---|---|
| Fix Gateway Exposure | --bind |
| Generate New Token | --token |
| Add Deny Commands | --deny |
| Restart Gateway | --restart |
| Fix All | --all |
English | ไธญๆ | Deutsch | Franรงais | Italiano
Contributions welcome! Please submit Pull Requests or Issues.
MIT License - See LICENSE
This tool is for security audit purposes only. Please understand the impact before using auto-fix features.
๐ฆ ClawGears
Protect Your Mac, Guard Your Privacy
Made with โค๏ธ by [Victor.Chen(https://github.com/JinHanAI)