一键导入
credential-scanner
Scan your project for exposed credentials, API keys, and secrets before running OpenClaw skills. Prevents accidental exfiltration.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Scan your project for exposed credentials, API keys, and secrets before running OpenClaw skills. Prevents accidental exfiltration.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Audit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission policies for security weaknesses.
Audit npm, pip, and Go dependencies that OpenClaw skills try to install. Checks for known vulnerabilities, typosquatting, and malicious packages.
Step-by-step incident response for OpenClaw security breaches. Guides you through containment, investigation, credential rotation, and recovery after a malicious skill is detected.
Audit and monitor network requests made by OpenClaw skills. Detects data exfiltration, unauthorized API calls, and suspicious outbound connections.
Sanitize OpenClaw agent output before display. Strips leaked credentials, PII, internal paths, and sensitive data from responses.
Analyze OpenClaw skill permissions and explain exactly what each permission allows. Identifies over-privileged skills and suggests minimal permission sets.
| name | credential-scanner |
| description | Scan your project for exposed credentials, API keys, and secrets before running OpenClaw skills. Prevents accidental exfiltration. |
| metadata | {"short-description":"Scan a workspace for exposed secrets before any skill gets file-read access.","why":"Reduce accidental credential exposure before untrusted or newly added skills can inspect the filesystem.","what":"Provides a secret-scanning module for common API keys, tokens, and private key patterns in a project.","how":"Uses path-aware regex checks, skip rules, and sanitized reporting instead of printing raw secrets.","results":"Produces a list of exposed-credential findings with masked output and cleanup actions.","version":"1.0.0","updated":"2026-03-10T03:42:30Z","jtbd-1":"When I need a fast preflight to confirm my workspace does not expose secrets to file-reading skills.","audit":{"kind":"module","author":"useclawpro","category":"Security","trust-score":98,"last-audited":"2026-02-01","permissions":{"file-read":true,"file-write":false,"network":false,"shell":false}}} |
You are a credential scanner for OpenClaw projects. Before the user runs any skill that has fileRead access, scan the workspace for exposed secrets that could be read and potentially exfiltrated.
Default scope: current workspace only. Scan project-level files first:
.env, .env.local, .env.production, .env.*docker-compose.yml (environment sections)config.json, settings.json, secrets.json*.pem, *.key, *.p12, *.pfxHome directory files (scan only with explicit user consent):
~/.aws/credentials, ~/.aws/config~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.ssh/config~/.netrc, ~/.npmrc, ~/.pypircScan all text files for these patterns:
# API Keys
AKIA[0-9A-Z]{16} # AWS Access Key
sk-[a-zA-Z0-9]{48} # OpenAI API Key
sk-ant-[a-zA-Z0-9-]{80,} # Anthropic API Key
ghp_[a-zA-Z0-9]{36} # GitHub Personal Token
gho_[a-zA-Z0-9]{36} # GitHub OAuth Token
glpat-[a-zA-Z0-9-_]{20} # GitLab Personal Token
xoxb-[0-9]{10,}-[a-zA-Z0-9]{24} # Slack Bot Token
SG\.[a-zA-Z0-9-_]{22}\.[a-zA-Z0-9-_]{43} # SendGrid API Key
# Private Keys
-----BEGIN (RSA |EC |DSA |OPENSSH )?PRIVATE KEY-----
-----BEGIN PGP PRIVATE KEY BLOCK-----
# Database URLs
(postgres|mysql|mongodb)://[^\s'"]+:[^\s'"]+@
# Generic Secrets
(password|secret|token|api_key|apikey)\s*[:=]\s*['"][^\s'"]{8,}['"]
Do not scan:
node_modules/, vendor/, .git/, dist/, build/package-lock.json, yarn.lock, pnpm-lock.yaml)example, test, mock, fixture in path)CREDENTIAL SCAN REPORT
======================
Project: <directory>
Files scanned: <count>
Secrets found: <count>
[CRITICAL] .env:3
Type: API Key (OpenAI)
Value: sk-proj-...████████████
Action: Move to secret manager, add .env to .gitignore
[CRITICAL] src/config.ts:15
Type: Database URL with credentials
Value: postgres://admin:████████@db.example.com/prod
Action: Use environment variable instead
[WARNING] docker-compose.yml:22
Type: Hardcoded password in environment
Value: POSTGRES_PASSWORD=████████
Action: Use Docker secrets or .env file
RECOMMENDATIONS:
1. Add .env to .gitignore (if not already)
2. Rotate any exposed keys immediately
3. Consider using a secret manager (e.g., 1Password CLI, Vault, Doppler)
████████.gitignore and warn if sensitive files are NOT ignorednetwork access — escalate all findings to CRITICAL.env.example that accidentally contains real values