A CLI tool that scans a running OpenClaw instance for known CVEs, exposed endpoints, and misconfigured permissions before it reaches production
OpenClaw accumulated 138 CVEs in 63 days during early 2026 and Cisco publicly labeled it a security nightmare. Over 135,000 instances are running exposed on the internet with 63% having no authentication. Despite this, most self-hosters have no automated way to check whether their specific version and configuration is vulnerable. This tool reads the local OpenClaw version, queries the jgamblin/OpenClawCVEs tracker, scans for exposed ports and missing auth, and outputs a pass/fail report with specific remediation steps.
Demand Breakdown
Social Proof 3 sources
Gap Assessment
3 tools exist (jgamblin/OpenClawCVEs, NemoClaw by NVIDIA, NanoClaw) but gaps remain: No automated scanning of local installs, no remediation guidance, no skill auditing; Enterprise-only, requires NVIDIA infrastructure, not a lightweight self-hosted scanner.
Features3 agent-ready prompts
Competitive LandscapeFREE
| Product | Does | Missing |
|---|---|---|
| jgamblin/OpenClawCVEs | Tracks and lists all OpenClaw CVEs in a GitHub repo | No automated scanning of local installs, no remediation guidance, no skill auditing |
| NemoClaw by NVIDIA | Enterprise security wrapper with kernel-level sandboxing and policy engine | Enterprise-only, requires NVIDIA infrastructure, not a lightweight self-hosted scanner |
| NanoClaw | Minimal 700-line alternative with Docker isolation per agent | Replacement, not a scanner for existing OpenClaw installs. Does not help current OpenClaw users. |
Sign in to unlock full access.