{"_id":"@cochatai/openclaw-carapace","_rev":"3-d40f2c8b7ed87c36893f300af0a25400","name":"@cochatai/openclaw-carapace","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@cochatai/openclaw-carapace","version":"0.1.0","keywords":["openclaw","security","audit","hardening","ai-safety","cli"],"author":{"name":"CoChat","email":"security@cochat.ai"},"license":"MIT","_id":"@cochatai/openclaw-carapace@0.1.0","maintainers":[{"name":"cochat","email":"marcel@cochat.ai"}],"homepage":"https://github.com/cochatai/openclaw-carapace","bugs":{"url":"https://github.com/cochatai/openclaw-carapace/issues"},"bin":{"openclaw-carapace":"dist/cli.js"},"dist":{"shasum":"dae69caa64fc205900c15e136cc62c59a4abdc7c","tarball":"https://registry.npmjs.org/@cochatai/openclaw-carapace/-/openclaw-carapace-0.1.0.tgz","fileCount":86,"integrity":"sha512-bL5hpO7TOmRqHEvscQRBYCFpg8CpRUNhXKdP2Qz1P1jR91cFYtn/qWUu1OUgMS2EAQhKTFQBVHVGqR5tJ2lQXw==","signatures":[{"sig":"MEYCIQC+6EhE0lMN1R4/ixSFxX1izEJ4gU68a2WXLEmuHIaYSAIhAOW/ULCWLPUsk6ZP2BocKkf1XFj4eL2lEjZH488acx7m","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":193702},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"b8e92883ec6dd4eb04cc5ce909497a25a33c6b2e","scripts":{"dev":"tsc --watch","lint":"eslint src/","test":"node --experimental-vm-modules node_modules/.bin/vitest run","build":"tsc","start":"node dist/cli.js","test:watch":"node --experimental-vm-modules node_modules/.bin/vitest","postinstall":"node dist/postinstall.js"},"_npmUser":{"name":"cochat","email":"marcel@cochat.ai"},"repository":{"url":"git+https://github.com/cochatai/openclaw-carapace.git","type":"git"},"_npmVersion":"10.9.4","description":"Security auditor and hardening tool for OpenClaw gateways","directories":{},"_nodeVersion":"22.21.1","dependencies":{"yaml":"^2.4.0","chalk":"^5.3.0","commander":"^12.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/openclaw-carapace_0.1.0_1772411385310_0.9084630421768971","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@cochatai/openclaw-carapace","version":"0.2.0","keywords":["openclaw","security","audit","hardening","ai-safety","cli"],"author":{"name":"CoChat","email":"security@cochat.ai"},"license":"MIT","_id":"@cochatai/openclaw-carapace@0.2.0","maintainers":[{"name":"cochat","email":"marcel@cochat.ai"}],"homepage":"https://github.com/cochatai/openclaw-carapace","bugs":{"url":"https://github.com/cochatai/openclaw-carapace/issues"},"bin":{"openclaw-carapace":"dist/cli.js"},"dist":{"shasum":"e55ac0a3426ac795c406fb5d8556b34921a5df82","tarball":"https://registry.npmjs.org/@cochatai/openclaw-carapace/-/openclaw-carapace-0.2.0.tgz","fileCount":86,"integrity":"sha512-om9q7z7fXA5Pht9u6riM9KwHBMyIKZxDy9mRPXaNZLaYFE9gI7FoyYRwHAaNdLDvahMz7k0qhdV6atFqU8lczg==","signatures":[{"sig":"MEUCIQCuNiowSClHlKoLXAyV11NpuS6c2LzbzUIe+KAaazXydQIgZeEcl11MNA5uvATwrBlWxreOdy+8EfXKcqBABxmuqJI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":208084},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"be2788d45e6025a8a546e2c1ef962a3c89366de7","scripts":{"dev":"tsc --watch","lint":"eslint src/","test":"node --experimental-vm-modules node_modules/.bin/vitest run","build":"tsc","start":"node dist/cli.js","test:watch":"node --experimental-vm-modules node_modules/.bin/vitest","postinstall":"node dist/postinstall.js"},"_npmUser":{"name":"cochat","email":"marcel@cochat.ai"},"repository":{"url":"git+https://github.com/cochatai/openclaw-carapace.git","type":"git"},"_npmVersion":"10.9.4","description":"Security auditor and hardening tool for OpenClaw gateways","directories":{},"_nodeVersion":"22.21.1","dependencies":{"yaml":"^2.4.0","chalk":"^5.3.0","commander":"^12.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/openclaw-carapace_0.2.0_1772414847429_0.7866313618298018","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@cochatai/openclaw-carapace","version":"0.2.1","description":"Security auditor and hardening tool for OpenClaw gateways","type":"module","main":"dist/index.js","types":"dist/index.d.ts","bin":{"openclaw-carapace":"dist/cli.js"},"scripts":{"build":"tsc","dev":"tsc --watch","lint":"eslint src/","test":"node --experimental-vm-modules node_modules/.bin/vitest run","test:watch":"node --experimental-vm-modules node_modules/.bin/vitest","start":"node dist/cli.js","postinstall":"node -e \"const p='dist/postinstall.js';require('fs').existsSync(p)&&require('child_process').execSync('node '+p,{stdio:'inherit'})\""},"keywords":["openclaw","security","audit","hardening","ai-safety","cli"],"author":{"name":"CoChat","email":"security@cochat.ai"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/cochatai/openclaw-carapace.git"},"homepage":"https://github.com/cochatai/openclaw-carapace","bugs":{"url":"https://github.com/cochatai/openclaw-carapace/issues"},"dependencies":{"chalk":"^5.3.0","commander":"^12.0.0","yaml":"^2.4.0"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.5.0","vitest":"^2.0.0"},"engines":{"node":">=18.0.0"},"_id":"@cochatai/openclaw-carapace@0.2.1","gitHead":"11fd89877504e37a120bf4ac13020e29c8ce66fc","_nodeVersion":"22.21.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-npRUjxIYC5HF8USwQInebe8X7ts6dY7t+BIU7XvMUZBGyOFjl3gwzs7KJ1bdXlIYwpi568yEejg9UwbncYlzvQ==","shasum":"ce7507e6e4e6da43a8ea8b8b5d8ee83525ab270d","tarball":"https://registry.npmjs.org/@cochatai/openclaw-carapace/-/openclaw-carapace-0.2.1.tgz","fileCount":86,"unpackedSize":208568,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICpXa99kmNoW0cQVzVYqYngT9XPKWau/vOgJa48H7QD5AiBMk5qyzk6eTEPIlUmVDQDdfjC5bS4qHXH+F2XkWgSZ/w=="}]},"_npmUser":{"name":"cochat","email":"marcel@cochat.ai"},"directories":{},"maintainers":[{"name":"cochat","email":"marcel@cochat.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/openclaw-carapace_0.2.1_1772420955867_0.7570526547281191"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-02T00:29:45.209Z","modified":"2026-03-02T03:09:16.179Z","0.1.0":"2026-03-02T00:29:45.466Z","0.2.0":"2026-03-02T01:27:27.578Z","0.2.1":"2026-03-02T03:09:16.010Z"},"bugs":{"url":"https://github.com/cochatai/openclaw-carapace/issues"},"author":{"name":"CoChat","email":"security@cochat.ai"},"license":"MIT","homepage":"https://github.com/cochatai/openclaw-carapace","keywords":["openclaw","security","audit","hardening","ai-safety","cli"],"repository":{"type":"git","url":"git+https://github.com/cochatai/openclaw-carapace.git"},"description":"Security auditor and hardening tool for OpenClaw gateways","maintainers":[{"name":"cochat","email":"marcel@cochat.ai"}],"readme":"<div align=\"center\">\n<img width=\"100\" alt=\"carapace-logo\" src=\"https://github.com/user-attachments/assets/75d23a40-7384-4d04-8620-7b8e65e2a2c3\" />\n<h1>Carapace For OpenClaw</h1>\nThe openclaw Security Advisor for <a href=\"https://openclaw.ai\">OpenClaw gateways</a>.\n\nBuilt by [CoChat](https://cochat.ai).\n</div>\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/@cochatai/openclaw-carapace\"><img src=\"https://img.shields.io/npm/v/@cochatai/openclaw-carapace?style=for-the-badge&color=d63031&label=npm\" alt=\"npm version\"></a>\n  <img src=\"https://img.shields.io/badge/rules-24-d63031?style=for-the-badge\" alt=\"24 audit rules\">\n  <img src=\"https://img.shields.io/badge/CVEs-225+-8b0000?style=for-the-badge\" alt=\"225+ advisories\">\n  <img src=\"https://img.shields.io/badge/license-MIT-blue?style=for-the-badge\" alt=\"MIT License\">\n</p>\n\n<p align=\"center\">\n  <img src=\"https://img.shields.io/badge/critical-8_rules-8b0000?style=flat-square\" alt=\"8 critical rules\">\n  <img src=\"https://img.shields.io/badge/high-7_rules-d63031?style=flat-square\" alt=\"7 high rules\">\n  <img src=\"https://img.shields.io/badge/medium-8_rules-e17055?style=flat-square\" alt=\"8 medium rules\">\n  <img src=\"https://img.shields.io/badge/low-1_rule-27ae60?style=flat-square\" alt=\"1 low rule\">\n  <img src=\"https://img.shields.io/badge/skill_checks-6-8e44ad?style=flat-square\" alt=\"6 skill checks\">\n  <img src=\"https://img.shields.io/badge/node-%3E%3D18-brightgreen?style=flat-square\" alt=\"Node.js >= 18\">\n</p>\n\n\n---\n\nRun one command. See exactly what's wrong with your gateway and how to fix it.\n![openclaw](https://github.com/user-attachments/assets/79f98f97-c1de-4de8-8f40-926a458bacc5)\n\n```\n$ openclaw-carapace audit\n\n  🦞 ┌─────────────────────┐ 🦞\n  🦞 │   O P E N C L A W   │ 🦞\n  🦞 │   C A R A P A C E   │ 🦞\n  🦞 └─────────────────────┘ 🦞\n\n   Config:  /Users/dev/.openclaw/openclaw.json\n   Rules:   106 evaluated\n\n   ─────────────────────────────────────────────\n\n   Grade D  30/100  [██████░░░░░░░░░░░░░░]\n\n   🦞 Walking around without a shell. Fix this.\n\n   8 findings (4 critical)\n   ↑ 55 pts recoverable via auto-fix\n\n   ─────────────────────────────────────────────\n\n   CRITICAL (4)\n\n   ▸ Gateway authentication disabled                      -25pts\n     No authentication is configured on the gateway.\n     → Set gateway.auth.mode to 'token' with a strong random token.\n\n   ▸ Sandboxing disabled — exec runs on host              -25pts  ✓ fixable\n     Sandbox mode is 'off' and exec tools are not denied.\n     → Set agents.defaults.sandbox.mode to 'non-main'.\n\n   ▸ Gateway tool not denied — agent can modify config    -25pts  ✓ fixable\n     A prompt injection can undo ALL security hardening.\n     → Add 'gateway' to tools.deny.\n\n   ▸ Elevated mode enabled                                -25pts  ✓ fixable\n     Elevated exec bypasses sandboxing and runs on host.\n     → Set tools.elevated.enabled to false.\n\n   HIGH (2)\n\n   ▸ Filesystem not restricted to workspace               -10pts  ✓ fixable\n     Filesystem tools can access ~/.openclaw/ and credentials.\n     → Set tools.fs.workspaceOnly to true.\n\n   ▸ Tool loop detection disabled                         -10pts  ✓ fixable\n     A stuck agent can execute the same tool call repeatedly.\n     → Set tools.loopDetection.enabled to true.\n\n   MEDIUM (2)\n\n   ▸ Auth credential is short (< 32 chars)                -5pts\n     Short credentials are easier to brute-force.\n     → Use a random token of at least 32 characters.\n\n   ▸ mDNS full mode — broadcasting sensitive info         -5pts   ✓ fixable\n     Broadcasts install paths and SSH availability on LAN.\n     → Set discovery.mdns.mode to 'minimal' or 'off'.\n\n   ─────────────────────────────────────────────\n\n   Run with --format json for machine-readable output\n   Run with --format sarif for GitHub Code Scanning\n```\n\nCarapace tells you what's wrong, why it matters, and exactly what to change. Most findings can be auto-fixed.\n\n## 📦 Install\n\n```bash\nnpm install -g @cochatai/openclaw-carapace\n```\n\nRequires Node.js 18+. That's it.\n\n## 🔍 What It Checks\n\n**Your config** -- 24 rules catch misconfigurations in authentication, sandboxing, tool permissions, exec approvals, filesystem restrictions, DM policies, and more. Each finding explains the risk and tells you the fix.\n\n**Known vulnerabilities** -- Carapace fetches 80+ CVEs and advisories from [jgamblin/OpenClawCVEs](https://github.com/jgamblin/OpenClawCVEs) (updated hourly) and checks them against your gateway version. Works offline too.\n\n**Third-party skills** -- Scan any skill directory for hardcoded secrets, shell execution, network exfiltration, obfuscation, and known-malicious authors.\n\n## 🚀 Usage\n\n```bash\n# Audit your gateway (auto-discovers ~/.openclaw/openclaw.json)\nopenclaw-carapace audit\n\n# Point to a specific config\nopenclaw-carapace audit --config ./openclaw.json\n\n# Scan a skill before installing it\nopenclaw-carapace skill scan ./some-skill/ --author \"skill-author\"\n\n# See what hardening profiles are available\nopenclaw-carapace profiles list\n\n# Output SARIF for GitHub Code Scanning\nopenclaw-carapace audit --format sarif > results.sarif\n```\n\n## 📊 Scoring\n\nYour gateway gets a score out of 100. Findings deduct points based on severity:\n\n| Severity | Points | Example                                   |\n| -------- | ------ | ----------------------------------------- |\n| Critical | -25    | No authentication, sandboxing off         |\n| High     | -10    | No exec approval, filesystem unrestricted |\n| Medium   | -5     | Log redaction off, short auth token       |\n| Low      | -2     | Web fetch enabled                         |\n\n**Grades:** A (90+), B (75-89), C (50-74), D (25-49), F (below 25)\n\nOne critical finding drops you from A to B. The score makes risk visible at a glance.\n\n## 🤝 Contributing\n\nWe'd love your help. Whether it's a new audit rule, a better description for an existing finding, a blocklist update, or a bug fix -- contributions of any size are welcome.\n\n```bash\ngit clone https://github.com/cochatai/openclaw-carapace.git\ncd openclaw-carapace\nnpm install\nnpm run build\nnode dist/cli.js audit --help\n```\n\n**Ways to contribute:**\n\n- Report a security misconfiguration we're not catching -- [open an issue](https://github.com/cochatai/openclaw-carapace/issues)\n- Add a new audit rule -- just create a YAML file in `rules/` (see [Writing Custom Rules](#writing-custom-rules) below)\n- Report a malicious skill or author -- add to `skills/blocklist/`\n- Improve finding descriptions -- clarity helps everyone\n- Add tests, fix bugs, improve docs\n\n---\n\n# 📖 Reference\n\nEverything below is detailed reference material. You don't need to read it to use Carapace -- the output tells you what to do. But it's here when you need it.\n\n## ⌨️ CLI Reference\n\n### `audit`\n\n```\nopenclaw-carapace audit [options]\n```\n\n| Option                     | Description                                    | Default       |\n| -------------------------- | ---------------------------------------------- | ------------- |\n| `-c, --config <path>`      | Path to `openclaw.json`                        | Auto-discover |\n| `-f, --format <fmt>`       | Output: `text`, `json`, `sarif`                | `text`        |\n| `-s, --min-severity <sev>` | Filter: `critical`, `high`, `medium`, `low`    | `low`         |\n| `--rules-dir <path>`       | Custom rules directory                         | Built-in      |\n| `--no-vulns`               | Skip CVE/vulnerability checks                  |               |\n| `--offline`                | Don't fetch live advisories (use cache/static) |               |\n\n### `skill scan`\n\n```\nopenclaw-carapace skill scan <path> [options]\n```\n\n| Option               | Description                        | Default |\n| -------------------- | ---------------------------------- | ------- |\n| `-f, --format <fmt>` | Output: `text`, `json`             | `text`  |\n| `--author <author>`  | Skill author (for blocklist check) |         |\n| `--name <name>`      | Skill name (for blocklist check)   |         |\n\n### `skill blocklist`\n\n```\nopenclaw-carapace skill blocklist [--format text|json]\n```\n\n### `profiles list` / `profiles show <id>`\n\n```\nopenclaw-carapace profiles list\nopenclaw-carapace profiles show locked_down --format json\n```\n\n### `patterns`\n\n```\nopenclaw-carapace patterns [--format text|json]\n```\n\n### `rules`\n\n```\nopenclaw-carapace rules [--format text|json] [--offline]\n```\n\n### Exit Codes\n\n| Code | Meaning                               |\n| ---- | ------------------------------------- |\n| `0`  | Clean -- no high or critical findings |\n| `1`  | High severity finding detected        |\n| `2`  | Critical severity finding detected    |\n| `3`  | Skill matches the blocklist           |\n\n## 🛡️ Config Audit Rules\n\n24 rules organized by severity. Rules with a CWE mapping indicate which vulnerability class they mitigate.\n\n### Critical (8 rules)\n\n| Rule ID                      | Title                                              | CWE                                | Auto-fix |\n| ---------------------------- | -------------------------------------------------- | ---------------------------------- | -------- |\n| `gateway.no_auth`            | Gateway authentication disabled                    | CWE-306                            |          |\n| `gateway.bind_no_auth`       | Gateway exposed without authentication             | CWE-306                            |          |\n| `dm_policy_open`             | Open DM policy -- anyone can message the bot       | CWE-306, CWE-345, CWE-285, CWE-863 | Y        |\n| `tools.profile_full`         | All tools unrestricted                             | CWE-78, CWE-22, CWE-918            | Y        |\n| `elevated.enabled`           | Elevated mode enabled                              | CWE-78, CWE-250, CWE-269           | Y        |\n| `sandbox.mode_off`           | Sandboxing disabled -- exec runs on host           | CWE-78, CWE-250                    | Y        |\n| `tools.gateway_tool_enabled` | Gateway tool not denied -- agent can modify config | CWE-918, CWE-284                   | Y        |\n| `dangerous_flags`            | Dangerous flag enabled                             |                                    | Y        |\n\n### High (7 rules)\n\n| Rule ID                           | Title                                            | CWE             | Auto-fix |\n| --------------------------------- | ------------------------------------------------ | --------------- | -------- |\n| `exec.host_sandbox_no_sandbox`    | exec.host='sandbox' but sandbox is off           | CWE-78, CWE-250 | Y        |\n| `firewall.inactive`               | Tool Firewall inactive                           | CWE-78, CWE-284 | Y        |\n| `fs.not_workspace_only`           | Filesystem tools not restricted to workspace     | CWE-22, CWE-200 | Y        |\n| `exec.security_full`              | Exec runs all commands without approval          | CWE-78, CWE-77  | Y        |\n| `channels.open_groups_with_tools` | Open groups with runtime tools enabled           |                 |          |\n| `tools.no_loop_detection`         | Tool loop detection disabled                     |                 | Y        |\n| `tools.cron_tool_enabled`         | Cron tool available -- persistent scheduled jobs |                 | Y        |\n\n### Medium (8 rules)\n\n| Rule ID                          | Title                                         | Auto-fix |\n| -------------------------------- | --------------------------------------------- | -------- |\n| `config_includes_present`        | Config includes detected                      |          |\n| `custom_provider_external`       | External model provider detected              |          |\n| `apply_patch.not_workspace_only` | apply_patch can write outside workspace       | Y        |\n| `browser.enabled_no_sandbox`     | Browser control enabled without sandboxing    | Y        |\n| `auth.token_short`               | Gateway auth credential is short (< 32 chars) |          |\n| `plugins.no_allowlist`           | Plugins without explicit allowlist            |          |\n| `logging.redact_off`             | Log redaction disabled                        | Y        |\n| `discovery.mdns_full`            | mDNS full mode -- broadcasting sensitive info | Y        |\n\n### Low (1 rule)\n\n| Rule ID                   | Title                          |\n| ------------------------- | ------------------------------ |\n| `tools.web_fetch_enabled` | Web fetch/search tools enabled |\n\n## 🐛 Vulnerability Scanning\n\nCarapace fetches live advisory data from [jgamblin/OpenClawCVEs](https://github.com/jgamblin/OpenClawCVEs), a community-maintained repository updated hourly via GitHub Actions. This currently tracks **80+ advisories** with GHSA IDs, CVE IDs, CVSS scores, affected version ranges, and fixed versions.\n\nEach advisory becomes a version check that fires when your `gateway.version` is below the fix version. Carapace catches new vulnerabilities automatically as they're disclosed.\n\n**Postinstall fetch:** When you `npm install`, Carapace automatically fetches the latest advisory data so the first `audit` run has CVE coverage immediately.\n\n**Cache:** Advisory data is cached to `~/.openclaw-carapace/cache/` for 1 hour. Subsequent runs within that window don't hit the network.\n\n**Offline mode:** `--offline` skips network fetches and uses cached data. If no cache exists, Carapace will warn you and skip vulnerability checks.\n\n## 🔒 Hardening Profiles\n\nPre-built configuration patches that fix multiple findings at once.\n\n| Profile          | Description                                                                                                                                                        |\n| ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |\n| `locked_down`    | Maximum security. Denies all runtime, filesystem, and control-plane tools. Forces sandboxing for all sessions. For messaging-only bots exposed to untrusted users. |\n| `coding_safe`    | Balanced security for coding agents. Keeps exec and filesystem tools but restricts them to the workspace. Denies control-plane tools. Enables exec approvals.      |\n| `messaging_safe` | Messaging tools only. Denies all runtime, filesystem, and automation tools.                                                                                        |\n| `dm_hardened`    | Locks all channel DM policies to `pairing` and isolates sessions per channel+peer. Does not change tool settings.                                                  |\n\nUse `openclaw-carapace profiles show <id> --format json` to see the exact config patch.\n\n## 🧱 Exec Firewall Patterns\n\nCarapace ships pattern definitions used by [CoChat's](https://cochat.ai) runtime exec firewall. The CLI doesn't run a firewall itself — it just lets you inspect the bundled patterns via `openclaw-carapace patterns`.\n\n**Dangerous (auto-deny, 20 patterns)** -- Destructive file ops (`rm -rf /`), credential theft (`cat ~/.ssh/`), remote code exec (`curl | sh`), system modification (`chmod 777`), network recon (`nmap`).\n\n**Suspicious (flag for review, 13 patterns)** -- HTTP requests (`curl`, `wget`), package installation (`pip install`, `npm install -g`), privilege escalation (`sudo`), container operations (`docker`), environment access (`printenv`, `history`).\n\nThese patterns are safety rails, not security boundaries — regex-based interception can be bypassed by a determined adversary.\n\n## 🕵️ Skill Scanning\n\n### Static Analysis (6 rule categories)\n\n| Rule                            | What it detects                                 | CWE      |\n| ------------------------------- | ----------------------------------------------- | -------- |\n| `skill.hardcoded_secrets`       | API keys, tokens, credentials in source code    | CWE-798  |\n| `skill.command_execution`       | Shell exec, eval, subprocess, child_process     | CWE-78   |\n| `skill.network_exfiltration`    | fetch, axios, http.request, WebSocket, etc.     | CWE-200  |\n| `skill.filesystem_access`       | References to ~/.ssh, ~/.aws, /etc/passwd, etc. | CWE-22   |\n| `skill.obfuscation`             | base64 decode, fromCharCode, hex escapes        | CWE-506  |\n| `skill.suspicious_dependencies` | Typosquatted packages, postinstall scripts      | CWE-1357 |\n\n### Blocklist\n\nKnown-malicious indicators from published security research:\n\n- **ClawHavoc campaign** -- 335+ malicious skills on ClawHub delivering Atomic macOS Stealer (AMOS).\n- **Known malicious authors** -- Aggregated from Snyk ToxicSkills (2025), Bitdefender AI supply-chain research (2026), and community reports.\n\nChecks author name, skill name, file SHA-256 hashes, C2 IP addresses, and known malicious domains.\n\n## ⚙️ SARIF / CI Integration\n\nCarapace outputs [OASIS SARIF 2.1.0](https://docs.oasis-open.org/sarif/sarif/v2.1.0/sarif-v2.1.0.html) for GitHub Code Scanning, VS Code SARIF Viewer, and other tools.\n\n### GitHub Actions\n\n```yaml\nname: OpenClaw Security Audit\non: [push, pull_request]\n\njobs:\n  audit:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n\n      - name: Audit OpenClaw config\n        run: npx @cochatai/openclaw-carapace audit --format sarif > openclaw-carapace.sarif\n\n      - name: Upload SARIF\n        uses: github/codeql-action/upload-sarif@v3\n        if: always()\n        with:\n          sarif_file: openclaw-carapace.sarif\n```\n\n## 💻 Programmatic Usage\n\n```typescript\nimport {\n  loadRules,\n  fetchAdvisoryRules,\n  evaluateRules,\n  buildAuditResult,\n  readConfig,\n  reportText,\n} from \"@cochatai/openclaw-carapace\";\n\nconst { config, path } = readConfig(\"./openclaw.json\");\n\nconst configRules = loadRules();\nconst vulnRules = await fetchAdvisoryRules();\nconst allRules = [...configRules, ...vulnRules];\n\nconst findings = evaluateRules(allRules, config);\nconst result = buildAuditResult(findings, allRules.length, path);\n\nconsole.log(reportText(result));\n```\n\n### Custom Check Hooks\n\n```typescript\nimport { registerCustomCheck } from \"@cochatai/openclaw-carapace\";\n\nregisterCustomCheck(\"my_org_policy\", (config) => {\n  const findings = [];\n  if (!config.myOrg?.approvedProvider) {\n    findings.push({\n      id: \"my_org.no_approved_provider\",\n      severity: \"high\",\n      title: \"Organization-approved provider not configured\",\n      description: \"...\",\n      recommendation: \"...\",\n      config_path: \"myOrg.approvedProvider\",\n      auto_fixable: false,\n      points: 10,\n    });\n  }\n  return findings;\n});\n```\n\n### Skill Scanning API\n\n```typescript\nimport {\n  scanSkill,\n  loadSkillRules,\n  loadSkillBlocklist,\n  reportSkillScan,\n} from \"@cochatai/openclaw-carapace\";\n\nconst result = scanSkill(\"./my-skill\", loadSkillRules(), loadSkillBlocklist(), {\n  author: \"some-author\",\n  name: \"my-skill\",\n});\n\nconsole.log(reportSkillScan(result));\n```\n\n## ✏️ Writing Custom Rules\n\nRules are YAML files. Drop them in a directory, pass `--rules-dir`, and Carapace picks them up.\n\n```yaml\nid: my_custom_rule\nseverity: high\ntitle: \"My custom security check\"\ndescription: \"Checks that my-setting is properly configured.\"\nrecommendation: \"Set my-setting to 'secure'.\"\nconfig_path: my.setting\nauto_fixable: true\nfix:\n  my:\n    setting: secure\ncheck:\n  type: value_equals\n  path: my.setting\n  value: secure\n```\n\n### Available Check Types\n\n| Type                | Description                                                     |\n| ------------------- | --------------------------------------------------------------- |\n| `value_equals`      | Fires when config value != expected (or == with `invert: true`) |\n| `value_in_set`      | Fires when value not in allowed set                             |\n| `value_not_in_list` | Fires when a value is absent from a config array                |\n| `truthy`            | Fires when value is truthy (or falsy with `invert: true`)       |\n| `key_exists`        | Fires when key exists (or doesn't with `invert: true`)          |\n| `string_length`     | Fires when string length is outside `min`/`max` bounds          |\n| `string_match`      | Fires when string matches (or doesn't) a regex pattern          |\n| `cross_field`       | Fires when ALL conditions across multiple config paths are true |\n| `iterate_map`       | Iterates a config map, applying a sub-check to each entry       |\n| `scan_keys`         | Scans config keys matching a regex pattern                      |\n| `url_check`         | Validates URLs in a config map against trusted domains          |\n| `version_compare`   | Compares a semver string (`lt`, `le`, `eq`, `ge`, `gt`)         |\n| `custom`            | Delegates to a registered TypeScript function                   |\n\n## 📄 License\n\n[MIT](./LICENSE) -- Copyright (c) 2026 CoChat\n","readmeFilename":"README.md"}