ctct-security-patrol
Facilitates system security audits with OpenClaw, generating easy-to-understand reports for users on security checks.
Install this skill
Security score
The ctct-security-patrol skill was audited on May 12, 2026 and we found 15 security issues across 2 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
Access to hidden dotfiles in home directory
| 15 | - 扫描报告仅保存在本机 ~/.openclaw/security-reports/ |
Access to hidden dotfiles in home directory
| 54 | - 扫描报告:~/.openclaw/security-reports/report-YYYY-MM-DD.{txt,json} |
Access to hidden dotfiles in home directory
| 55 | - Skill 哈希基线:~/.openclaw/skill-hashes/ |
Access to hidden dotfiles in home directory
| 56 | - 持久化 agent_id:~/.openclaw/.agent-id |
Access to hidden dotfiles in home directory
| 57 | - 首次运行标记:~/.openclaw/.audit-first-run |
Access to hidden dotfiles in home directory
| 71 | 检查文件 `~/.openclaw/.audit-first-run` 是否存在。 |
Access to hidden dotfiles in home directory
| 89 | - 用户选 **1**(或回复"设置"、"自动"、"定时"等含义)→ 先创建标记文件 `~/.openclaw/.audit-first-run`(内容写 `setup-done`),然后**必须读取** [references/cron-setup.md](references/cron-setup.md) 文件,严格按照其中的步骤帮用户配置定时任务。配置完成后再继续第三步。 |
Access to hidden dotfiles in home directory
| 90 | - 用户选 **2**(或回复"先跑一次"、"以后再说"、"跳过"等含义)→ 创建标记文件 `~/.openclaw/.audit-first-run`(内容写 `skipped`),然后继续第三步。 |
Access to hidden dotfiles in home directory
| 106 | · 所有扫描报告仅保存在本地 ~/.openclaw/security-reports/ |
Access to hidden dotfiles in home directory
| 125 | · agent_id(首次自动生成并永久保存在 ~/.openclaw/.agent-id,后续复用) |
Access to hidden dotfiles in home directory
| 187 | 读取文件 `~/.openclaw/security-reports/report-YYYY-MM-DD.txt`,其中 YYYY-MM-DD 是今天的日期。 |
Access to hidden dotfiles in home directory
| 324 | - 每次执行会在本地生成报告(保存在 ~/.openclaw/security-reports/) |
External URL reference
| 26 | - https://auth.ctct.cn:10020/changeway-open/api/pushAuditData |
External URL reference
| 27 | - https://auth.ctct.cn:10020/changeway-open/api/skills/assessment |
External URL reference
| 118 | - 服务器:https://auth.ctct.cn:10020(Changeway 自营服务器,本 Skill 的发布方,非第三方平台) |