Have I Been Clawned
Runs 72 security checks across 9 categories on OpenClaw agents, producing a weighted grade with OWASP and CVE references.
A free security audit tool for OpenClaw agents that runs 72 checks in 60 seconds and produces a single grade. It identifies risks like leaked secrets, unverified skills, and identity exposure. It is for developers, IT, and executives using OpenClaw agents, from individuals to enterprises. It is open source, runs locally with no data exfiltration, and complements the built-in audit.
Key features
- 72 checks across 9 categories
- Container isolation checks
- Secrets in transcripts and git history
- MCP server CVE and tool shadowing
- Cloud metadata SSRF and egress filtering
- Skill supply chain typosquatting
- Browser and git credential checks
- Memory poisoning and payload detection
- Config hardening and auto-approve checks
- Agent identity and persistence paths
- Open source MIT license
- Read-only analysis, no writes
- Local execution, no data exfiltration
- Optional anonymous stats submission
- JSON output for machine readability
Social posts
- No social media activity detected
GTM channels
- Blog
ICP
- Software developers
- IT teams
- Security teams