healthcheck skillA
healthcheck is agent-read markdown (skill) from trpc-group/trpc-agent-go: Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS)..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# OpenClaw Host Hardening ## Overview Assess and harden the host running OpenClaw, then align it to a user-defined risk tolerance without breaking access. Use OpenClaw security tooling as a first-class signal, but treat OS hardening as a separate, explicit set of steps. ## Core rules - Recommend running this skill with a state-of-the-art model (e.g., Opus 4.5, GPT 5.2+). The agent should self-check the current model and suggest switching if below that level; do not block execution. - Require explicit approval before any state-changing action. - Do not modify remote access settings without confirming how the user connects. - Prefer reversible, staged changes with a rollback plan. - Never claim OpenClaw changes the host firewall, SSH, or OS updates; it does not. - If role/identity is unknown, provide recommendations only. - Formatting: every set of user choices must be numbered so the user can reply with a single digit. - System-level backups are recommended; try to verify status. ## Workflow (follow in order) ### 0) Model self-check (non-blocking) …
Read the whole file at its exact version.
How to install
mdr add trpc-group/trpc-agent-go/healthcheck@git:20260304.8ebbeaemdr add trpc-group/trpc-agent-go/healthcheck@sha256:adba53ffae3924e4Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_naykitbj2nv4n5ka)
1 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (10538 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
trpc-group/trpc-agent-go · 1,821 stars · license Apache-2.0 · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_naykitbj2nv4n5ka GET https://markdownregistry.com/api/v1/resolve?ref=trpc-group/trpc-agent-go/healthcheck GET https://markdownregistry.com/api/v1/blob/adba53ffae3924e411b0e73737ed9f0917b79cd5a7e64f0f9d03600126a07085
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
More from trpc-group/trpc-agent-go
Every file in trpc-group/trpc-agent-go