Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
openclaw-hardening-check — Offline, read-only hardening check for a self-hosted OpenClaw install — gateway exposure, auth, CVE-2026-25253. Never prints secrets, makes no network calls. | Kitploit
Tools/GitHubGitHub/cain66666/openclaw-hardening-check
Vulnerability AnalysisConfiguration AuditingNetwork SecurityCloud SecuritySecret DetectionMisconfiguration
GitHubcain66666/openclaw-hardening-check

openclaw-hardening-check

Offline, read-only hardening check for a self-hosted OpenClaw install — gateway exposure, auth, CVE-2026-25253. Never prints secrets, makes no network calls.

View Repository
142 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

This script only reads. It fixes nothing and does not guarantee that you are safe. Green output means only that the checks listed below passed—and nothing more.

OpenClaw hardening check

openclaw-hardening-check.mjs is a small, dependency-free, offline review of an OpenClaw installation. It reads local configuration, package metadata, plugin and skill manifests, file modes, and—on Linux—the running Gateway's entries in /proc. It does not change files, call OpenClaw commands, contact a registry, or make any network request.

What it checks

  • Gateway bind: reports whether gateway.bind is loopback-only, non-loopback, or runtime-dependent. An unset or auto bind inside a detected Docker, Podman, Kubernetes, or Fly container is treated as 0.0.0.0, matching OpenClaw's container default. A running Linux Gateway is checked separately so a command-line or service override cannot hide behind a safe config value.
  • Gateway authentication: models OpenClaw's config-first precedence for plaintext gateway.auth.token and .password. It recognizes ${VAR}, $VAR, secretref-env:VAR, __env__:VAR, and structured SecretRefs before measuring a credential. Auth environment evidence comes from the matched Gateway process, gateway.systemd.env, or the state .env, never from the auditor process. Secret values are never printed; the report contains only presence, source class, and length. Published example placeholders and tokens shorter than 24 characters are flagged.
  • CVE-2026-25253: treats versions before 2026.1.29 as affected. The vulnerability let a query-string gatewayUrl trigger a WebSocket connection that disclosed the Gateway token. See the NVD entry and the OpenClaw advisory.
  • Installation pin: distinguishes an exact version or commit from moving targets such as latest, beta, or main when install provenance is supplied. npm and pnpm do not retain the original requested dist-tag in the installed package, so the script reports “cannot check” instead of guessing when that provenance is absent.
  • Secret-file permissions: checks the config, config includes, .env, gateway.systemd.env, discovered auth-profiles.json files, and resolved file SecretRefs for group/world exposure or unexpected ownership.
  • Skills and plugins: inventories bundled items—including dist-runtime/extensions—separately from items found in state, config-directory, managed, workspace, personal, configured, or npm project locations. Non-bundled items are marked for manual review, never labeled malicious.
  • Listening sockets: on Linux, maps /proc/net/tcp* socket inodes back to Gateway entry-file or binary processes and flags every non-loopback TCP listener they own. A listener on the expected port whose owner cannot be verified produces “cannot check,” not “Gateway is not running.” The check still works from disk when the Gateway is stopped.
  • Control UI hardening: flags dangerous device-auth, insecure-auth, and Host-header-origin overrides. It also warns when non-loopback shared-secret auth has no configured rate limit.

The paths and defaults follow the official configuration documentation, configuration reference, Gateway exposure runbook, skills documentation, and plugin management documentation.

Run it

Copy the script to the machine that runs OpenClaw, then run it as the same OS user:

node openclaw-hardening-check.mjs

OpenClaw's default config is ~/.openclaw/openclaw.json. The script also honors OPENCLAW_CONFIG_PATH, OPENCLAW_STATE_DIR, and OPENCLAW_GATEWAY_PORT.

Optional overrides are available for non-default layouts and reproducible pin checks:

node openclaw-hardening-check.mjs \
  --config /srv/openclaw/openclaw.json \
  --state-dir /srv/openclaw \
  --package-root /opt/openclaw/lib/node_modules/openclaw \
  --install-spec 2026.6.10

--install-spec must be the target originally used by the installer or deployment definition. Passing the currently installed version without verifying that provenance does not prove the deployment is pinned.

Example output

The checker never emits the secret itself, so the publishable form records only its source and length:

OpenClaw hardening check
Read-only and offline. Secret values are never printed.
Config: ~/.openclaw/openclaw.json

[PASS] Config: loaded ~/.openclaw/openclaw.json without printing its contents.
[PASS] Gateway bind: loopback; configured for local-only access.
[PASS] Gateway authentication: present via Gateway process environment bootstrap, length 48; value was not printed.
[PASS] Listening sockets: OpenClaw TCP listeners are loopback-only: 127.0.0.1:18789, [::1]:18789.
[PASS] CVE-2026-25253: installed package version 2026.6.10 is at or newer than 2026.1.29.
[PASS] Installation pin: exact target 2026.6.10 is recorded for this check.
[WARN] Third-party plugins: 1: example-plugin. Review it yourself; no malware verdict was attempted.

Summary: No security problems found. 1 item flagged for your review; exit code 0.

Secret value: [REDACTED — never present in output].

Exit codes

The summary counts security problems (FAIL), manual-review items (WARN), and incomplete checks (CANNOT CHECK) separately. WARN and CANNOT CHECK results alone do not make the process fail; only a FAIL returns exit code 1.

CodeMeaning
0No FAIL security problems were found; WARN or CANNOT CHECK results may still be present.
1At least one FAIL security problem needs attention.
2The command line is invalid, or the config could not be found, read, included, or parsed safely.

Deliberate limitations

  • This is a local configuration and process-state check, not a remote exposure scanner. It makes no network connections, even to localhost.
  • Run it in the same host/container context and as the same OS user as the Gateway. The auditor's own token/password environment is deliberately ignored.
  • If the Gateway is stopped and no credential is found in config or the known environment files, authentication is reported as “cannot check”: another service environment source may provide it only when the Gateway starts.
  • Socket ownership inspection currently requires Linux /proc. Other platforms receive an explicit “cannot check” result.
  • A reverse proxy, container port publication, Tailscale configuration outside OpenClaw, firewall rule, or cloud load balancer can expose a loopback-looking deployment. Review those layers separately.
  • Package files prove the installed version but normally cannot prove whether a package manager originally resolved @latest. Supply trusted deployment provenance with --install-spec.
  • Third-party inventory is a prompt for human review, not a reputation or malware scan.

Tests

The test suite uses only node:test and temporary directories:

node --test test/openclaw-hardening-check.test.mjs

Author

Ilya Prudnikov — cain-ai.com

License

MIT

Download Tool