config-encryption-auditor

Installation
SKILL.md

Config Encryption Auditor

What it does

OpenClaw stores configuration in ~/.openclaw/ — API keys, channel tokens, provider credentials. By default, these are plaintext YAML or JSON files readable by any process on your machine.

OpenLobster solved this with AES-GCM encrypted config files. We can't change OpenClaw's config format, but we can audit it — scanning for exposed secrets, flagging unencrypted credential files, and suggesting migrations to environment variables or encrypted vaults.

When to invoke

  • Automatically, every Sunday at 9am (cron)
  • After initial OpenClaw setup
  • Before deploying to shared infrastructure
  • After any config change that adds new API keys

Checks performed

Check Severity What it detects
Related skills
Installs
15
GitHub Stars
61
First Seen
Mar 21, 2026