返回顶部
b

baseline-kit

Generate safer OpenClaw configuration baselines and audit existing config files for exposure, missing controls, and secret hygiene issues.

作者: admin | 来源: ClawHub
源自
ClawHub
版本
V 1.0.1
安全检测
已通过
410
下载量
0
收藏
概述
安装方式
版本历史

baseline-kit

# Baseline Kit Generate profile-based OpenClaw configuration JSON and audit an existing config before rollout. ## When to use - You need a starting profile for `development`, `team`, `enterprise`, or `airgapped`. - You want an offline audit for `gateway.bind`, auth rate limits, allowed skill sources, audit logging, backups, or secret-like values. - You need a reviewable JSON artifact without contacting external services. ## Commands ```bash node {baseDir}/bin/baseline-kit.js generate --profile enterprise --out ./openclaw.secure.json node {baseDir}/bin/baseline-kit.js generate --profile development --out ./openclaw.dev.json node {baseDir}/bin/baseline-kit.js audit --config ~/.openclaw/openclaw.json --format table node {baseDir}/bin/baseline-kit.js audit --config ./openclaw.secure.json --format json ``` ## Profiles | Profile | Focus | | --- | --- | | `development` | Faster local iteration with lighter rate limits and shorter retention | | `team` | Shared team defaults with moderate auth protection and audit logging | | `enterprise` | Tighter auth windows, longer retention, and recovery guidance | | `airgapped` | Loopback-only and local-mirror oriented settings | ## Audit checks - `NET_EXPOSURE`: whether `gateway.bind` is loopback-only - `AUTH_RATE_LIMIT`: whether auth rate limiting is configured completely - `SOURCE_RESTRICTION`: whether allowed skill sources are too broad - `AUDIT_LOGGING`: whether audit logging is enabled - `BACKUP_HINT`: whether backup settings are present - `SECRET_HYGIENE`: whether the config tree contains plaintext secret-like values ## Output - Each finding includes a severity, evidence path, recommendation, and compliance tag set. - Compliance tags currently map to `SOC2`, `ISO27001`, and `NIST CSF`. ## Boundaries - This tool audits JSON structure only. It does not enforce runtime policy. - Generated profiles are safer defaults, not a complete configuration management system.

标签

skill ai

通过对话安装

该技能支持在以下平台通过对话安装:

OpenClaw WorkBuddy QClaw Kimi Claude

方式一:安装 SkillHub 和技能

帮我安装 SkillHub 和 baseline-kit-1776298515 技能

方式二:设置 SkillHub 为优先技能安装源

设置 SkillHub 为我的优先技能安装源,然后帮我安装 baseline-kit-1776298515 技能

通过命令行安装

skillhub install baseline-kit-1776298515

下载 Zip 包

⬇ 下载 baseline-kit v1.0.1

文件大小: 11.55 KB | 发布时间: 2026-4-16 17:47

v1.0.1 最新 2026-4-16 17:47
README and SKILL.md compliance update for OpenClaw / ClawHub alignment.

Archiver·手机版·闲社网·闲社论坛·羊毛社区· 多链控股集团有限公司 · 苏ICP备2025199260号-1

Powered by Discuz! X5.0   © 2024-2025 闲社网·线报更新论坛·羊毛分享社区·http://xianshe.com

p2p_official_large
返回顶部