
Offline, read-only hardening check for a self-hosted OpenClaw install — gateway exposure, auth, CVE-2026-25253. Never prints secrets, makes no network calls.
This script only reads. It fixes nothing and does not guarantee that you are safe. Green output means only that the checks listed below passed—and nothing more.
openclaw-hardening-check.mjs is a small, dependency-free, offline review of an OpenClaw installation. It reads local configuration, package metadata, plugin and skill manifests, file modes, and—on Linux—the running Gateway's entries in /proc. It does not change files, call OpenClaw commands, contact a registry, or make any network request.
gateway.bind is loopback-only, non-loopback, or runtime-dependent. An unset or auto bind inside a detected Docker, Podman, Kubernetes, or Fly container is treated as 0.0.0.0, matching OpenClaw's container default. A running Linux Gateway is checked separately so a command-line or service override cannot hide behind a safe config value.gateway.auth.token and .password. It recognizes ${VAR}, $VAR, secretref-env:VAR, __env__:VAR, and structured SecretRefs before measuring a credential. Auth environment evidence comes from the matched Gateway process, gateway.systemd.env, or the state .env, never from the auditor process. Secret values are never printed; the report contains only presence, source class, and length. Published example placeholders and tokens shorter than 24 characters are flagged.2026.1.29 as affected. The vulnerability let a query-string gatewayUrl trigger a WebSocket connection that disclosed the Gateway token. See the NVD entry and the OpenClaw advisory.latest, beta, or main when install provenance is supplied. npm and pnpm do not retain the original requested dist-tag in the installed package, so the script reports “cannot check” instead of guessing when that provenance is absent..env, gateway.systemd.env, discovered auth-profiles.json files, and resolved file SecretRefs for group/world exposure or unexpected ownership.dist-runtime/extensions—separately from items found in state, config-directory, managed, workspace, personal, configured, or npm project locations. Non-bundled items are marked for manual review, never labeled malicious./proc/net/tcp* socket inodes back to Gateway entry-file or binary processes and flags every non-loopback TCP listener they own. A listener on the expected port whose owner cannot be verified produces “cannot check,” not “Gateway is not running.” The check still works from disk when the Gateway is stopped.The paths and defaults follow the official configuration documentation, configuration reference, Gateway exposure runbook, skills documentation, and plugin management documentation.
Copy the script to the machine that runs OpenClaw, then run it as the same OS user:
node openclaw-hardening-check.mjs
OpenClaw's default config is ~/.openclaw/openclaw.json. The script also honors OPENCLAW_CONFIG_PATH, OPENCLAW_STATE_DIR, and OPENCLAW_GATEWAY_PORT.
Optional overrides are available for non-default layouts and reproducible pin checks:
node openclaw-hardening-check.mjs \
--config /srv/openclaw/openclaw.json \
--state-dir /srv/openclaw \
--package-root /opt/openclaw/lib/node_modules/openclaw \
--install-spec 2026.6.10
--install-spec must be the target originally used by the installer or deployment definition. Passing the currently installed version without verifying that provenance does not prove the deployment is pinned.
The checker never emits the secret itself, so the publishable form records only its source and length:
OpenClaw hardening check
Read-only and offline. Secret values are never printed.
Config: ~/.openclaw/openclaw.json
[PASS] Config: loaded ~/.openclaw/openclaw.json without printing its contents.
[PASS] Gateway bind: loopback; configured for local-only access.
[PASS] Gateway authentication: present via Gateway process environment bootstrap, length 48; value was not printed.
[PASS] Listening sockets: OpenClaw TCP listeners are loopback-only: 127.0.0.1:18789, [::1]:18789.
[PASS] CVE-2026-25253: installed package version 2026.6.10 is at or newer than 2026.1.29.
[PASS] Installation pin: exact target 2026.6.10 is recorded for this check.
[WARN] Third-party plugins: 1: example-plugin. Review it yourself; no malware verdict was attempted.
Summary: No security problems found. 1 item flagged for your review; exit code 0.
Secret value: [REDACTED — never present in output].
The summary counts security problems (FAIL), manual-review items (WARN), and incomplete checks (CANNOT CHECK) separately. WARN and CANNOT CHECK results alone do not make the process fail; only a FAIL returns exit code 1.
| Code | Meaning |
|---|---|
0 | No FAIL security problems were found; WARN or CANNOT CHECK results may still be present. |
1 | At least one FAIL security problem needs attention. |
2 | The command line is invalid, or the config could not be found, read, included, or parsed safely. |
/proc. Other platforms receive an explicit “cannot check” result.@latest. Supply trusted deployment provenance with --install-spec.The test suite uses only node:test and temporary directories:
node --test test/openclaw-hardening-check.test.mjs
Ilya Prudnikov — cain-ai.com