CtrlK
BlogDocsLog inGet started
Tessl Logo

healthcheck

Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).

83

2.11x
Quality

76%

Does it follow best practices?

Impact

95%

2.11x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./openclaw/skills/healthcheck/SKILL.md

The canonical home for this skill is healthcheck in Hung-Reo/hungreo-openclaw

SKILL.md
Quality
Evals
Security

Quality

Content

70%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-sequenced, highly actionable hardening runbook with strong validation and confirmation discipline around risky operations. Its weaknesses are repetition that inflates the token budget (the firewall/SSH disclaimer appears three times) and a monolithic structure that inlines question banks and reference material a longer skill would split into separate files.

Suggestions

State the 'OpenClaw does not change host firewall/SSH/OS updates' caveat once (e.g., in Core rules) and remove the two repeated restatements in the audit and command-accuracy sections; likewise fold the model self-check into a single location.

Move the non-technical question bank, the per-OS check command listings, and the memory-write prompt format into reference files (e.g., references/questions.md, references/checks.md) and link to them, keeping SKILL.md as the workflow overview.

Provide the full `openclaw cron add` invocation with example cadence/time/output arguments, and either add Windows equivalents for the read-only checks or explicitly state the skill covers Linux/macOS commands only.

DimensionReasoningScore

Conciseness

Mostly efficient procedural content Claude could not infer, but noticeably padded: the caveat that OpenClaw does not change host firewall/SSH/OS updates is stated three times ('Never claim OpenClaw changes the host firewall...', 'It does not change host firewall, SSH, or OS update policies', 'Do not... imply OpenClaw enforces host firewall/SSH policies'), and the model self-check rule appears both in Core rules and again as workflow step 0. This fits the 'could be tightened' anchor rather than the 'minor instances' anchor.

3 / 5

Actionability

Concrete, executable commands throughout (`openclaw security audit --deep`, `ss -ltnup`, `ufw status`, `tmutil status`, stable cron job names like `healthcheck:security-audit`) with OS-specific alternatives, but with minor gaps: `openclaw cron add --name <name> ...` uses a placeholder instead of a full invocation, and no Windows commands are given even though Windows/RDP/BitLocker appear in the context checklist.

4 / 5

Workflow Clarity

The workflow is clearly sequenced (steps 0–8 in order) with explicit validation in step 8 ('Re-check: firewall status, listening ports, remote access still works, OpenClaw security audit re-run'), an error-recovery feedback loop ('Stop on unexpected output and ask for guidance'), plan-before-change and rollback requirements, and a dedicated required-confirmations checklist — satisfying the top anchor for skills with risky operations.

5 / 5

Progressive Disclosure

The entire skill is one ~245-line file with no reference files at all; content that could live in separate references — the question bank, the OS command listings, and the memory-write format — is inlined. Section headers are clear, but the lack of any split for a body this long fits the 'content that should be separate is inline' anchor rather than the 'most content appropriately placed' anchor.

3 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly and concretely states both what the skill does and when to use it, with natural trigger phrases and consistent OpenClaw scoping. Its only weakness is that several trigger terms (security audits, firewall/SSH hardening) are generic enough to overlap with non-OpenClaw hardening requests.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete actions — 'security hardening', 'risk-tolerance configuration', 'security audits', 'cron scheduling for periodic checks', 'version status checks' — with comprehensive coverage and correct third-person voice, matching the anchor for multiple specific concrete actions.

5 / 5

Completeness

It explicitly answers 'what' (host security hardening and risk-tolerance configuration for OpenClaw deployments) and 'when' via a concrete 'Use when...' clause listing explicit triggers, matching the top anchor rather than the score-4 anchor where the when-clause could be more specific.

5 / 5

Trigger Term Quality

It covers natural trigger phrases users would actually say ('security audits', 'firewall/SSH/update hardening', 'risk posture', 'exposure review', 'periodic checks') plus deployment-surface synonyms (laptop, workstation, Pi, VPS), giving comprehensive coverage with variations.

5 / 5

Distinctiveness Conflict Risk

The OpenClaw niche is clear and consistently scoped, but generic phrases like 'security audits' and 'firewall/SSH hardening' could also be said by users without OpenClaw in mind, creating minor overlap risk with generic OS-hardening skills — fitting the 'mostly distinct; minor overlap risk' anchor rather than the minimal-conflict anchor.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
trpc-group/trpc-agent-go
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.