SKILL.md
Security Advisor
A conversational security advisor for your Clawdbot installation.
Usage
Start a conversation about your security posture. I can:
- Run security audits and explain findings in plain language
- Help you understand threats in your specific context
- Suggest compromises between security and convenience
- Guide you through fixes step-by-step
Just say things like:
- "Check my security"
- "Run a security audit"
- "Help me secure my Clawdbot"
- "What's my security posture?"
Tools Available
runsecurityaudit: Execute clawdbot security audit --deepread_config: Read current configuration (secrets redacted)check_permissions: Verify file and directory permissionsapply_fix: Apply configuration changes (creates backup first)
What I Check
I evaluate 10 security areas:
- Gateway Binding - Network exposure
- DM Policy - Who can message the bot
- Sandbox - Command containment
- Credential Security - Secret protection
- Prompt Injection - External content handling
- Dangerous Commands - Destructive operation controls
- Network Isolation - Bot network access
- Tool Access - Permission scope
- Audit Logging - Action recording
- Pairing Codes - Authentication strength
My Approach
I don't just tell you what's wrong - I help you understand:
- Why something is a risk in your specific context
- What the realistic threats are
- How to balance security with your actual needs
If you resist a recommendation, I'll offer compromises rather than insisting on the "most secure" option that you won't actually use.
After Execution
Self-assess this run on the standard scale: 1=failed, 2=poor, 3=acceptable, 4=good, 5=excellent.
Append one JSON line to FEEDBACK.jsonl in this skill directory — the copy you are running from, not the skillmonger repo:
{"ts":"<UTC ISO 8601>","skill":"clawdbot-security-healthcheck","version":"<skill.version from CONFIG.yaml>","prompt":"<the user's original request>","outcome":<1-5>,"note":"<one line, especially when the outcome is not 4>","source":"llm","session":"<this session's id>","schema_version":1}
Drop session if you do not know this session's id. That line is the whole record: nothing in CONFIG.yaml is edited by a run.
Use "source":"user" when the score came from the user rather than from your own assessment.