check_agent_security
Scan AI agent installations for security vulnerabilities in configuration and skills. Identify issues like API key exposure, malicious patterns, and permission flaws to improve security posture before deployment.
Instructions
Scan an AI agent installation for security issues. Checks agent configuration (gateway binding, authentication, sandbox, API keys in plaintext, DM policy, tool permissions, SSRF protection, file permissions, log redaction) and installed skills for malicious patterns (reverse shells, credential theft, prompt injection, toxic data flows). Returns findings with severity levels and fix hints. Use when auditing an agent's security posture or before deploying an agent to production.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| agent_dir | No | Path to agent config directory. Defaults to ~/.openclaw if not specified. | |
| scan_skills | No | Include skill scanning for malicious patterns (default: true) | |
| verify_pins | No | Verify pinned skills for rug pull detection (default: false) | |
| policy | No | Scan policy preset (default: balanced) |