Host Healthcheck Skill: Audit & Harden an OpenClaw Host

OpenClaw's official host healthcheck skill. Assesses host risk with read-only checks (SSH/firewall/updates/backups/encryption/gateway exposure), then proposes reversible, staged hardening — confirming access paths before any change.

A host running agents is usually not at risk from "being attacked" — it is at risk from "never being audited". Exposed SSH, missing firewall rules, stalled updates, absent backups, unencrypted disks: every one is a silent time bomb. OpenClaw's official Healthcheck Skill is a systematic audit flow: read-only assessment first, then reversible staged hardening — never change before asking.

Core principles: assess first, harden later, keep changes reversible

  • Confirm the access path before changing anything: if SSH/firewall/remote access is not confirmed to work, do not touch it — guarantee "you can still get in" before "make it safer"

  • Prefer reversible steps: every hardening step ships with rollback notes; slow beats disconnected

  • No overclaiming: the skill never claims to manage the OS firewall/SSH/updates, and only recommends when identity is unknown

  • Secrets discipline: never prints keys or other sensitive material

The audit flow

First, infer context: OS/version, container vs host, privilege level, access path (local/SSH/RDP/tailnet), network exposure (public IP/reverse proxy/tunnel/LAN), OpenClaw gateway status and bind, backup status, disk encryption, automatic security updates, usage mode. Ask only for missing facts, in plain language.

Then request permission once to run read-only checks and run a set of standard commands (SSH config, open ports, firewall rules, update status, mounts and encryption, backup scripts, gateway listen address). Finally, consolidate a risk list and present numbered hardening options for the user to choose and approve.

Typical use cases

  • New host onboarding: run a healthcheck before deploying an agent — clean up exposed SSH and weak configs first

  • Periodic security reviews: re-scan the attack surface of running servers to catch config drift

  • Post-incident review: after an anomaly, confirm which doors are open and which need closing

How to use & download

OpenClaw users: healthcheck is a built-in skill — trigger in natural language when you want a host security audit. See OpenClaw docs.

Other agent users: follows the standard SKILL.md convention; the whole assess-first, harden-reversibly security flow is reusable. Source: OpenClaw GitHub repo.

Related resources

Ops skills work together: this skill owns host security, GitHub skill (github) owns code and CI, and orchestration (taskflow) schedules recurring audits.