Free tool · read-only · your machine only

Check your OpenClaw in ten seconds.

One short Python script. It reads your own OpenClaw config and installed skills, then tells you if the gateway can be reached from your network, what the heartbeat costs you while idle, and whether any skill matches ones publicly reported as malicious. It changes nothing and sends nothing anywhere.

01

Gateway exposure

Reads gateway.bind and the auth mode, then tests whether the gateway port answers on your own network address, from your own machine.

02

Heartbeat cost

Shows how many full agent turns run a day while you do nothing, and whether isolatedSession and lightContext are on.

03

Skills

Flags skill names from the reported ClawHavoc list and SKILL.md files that pipe downloads into a shell or point at the reported server.

Run it

Read it, then run it.

01

Download it (246 lines, Python 3.8+, nothing to install) and read it first. It's meant to be read.

curl -O https://jzzystudios.com/hearth/check/openclaw-check.py
02

Check it's the file we published. The SHA-256 should be:

4ebd722ae05622defd939c2cc416b30ca710b5e655203eed79fda69b6acf5de6
03

Run it as your normal user, on the machine where OpenClaw runs. Set OPENCLAW_CONFIG_PATH first if your config isn't at ~/.openclaw/openclaw.json.

python3 openclaw-check.py
What it looks like

A deliberately bad setup.

Real output (a few long lines shortened) from a test machine we set up to fail: gateway on the LAN with auth off, a 15-minute heartbeat, a skill named like a reported typosquat, and a skill whose "prerequisites" pipe a download from the reported server into a shell.

$ python3 openclaw-check.py
OpenClaw self-check 1.0 (3 Oct 2026): read-only, this computer only

1. Gateway exposure
  warn  gateway.bind is "lan": other devices can reach the gateway.
   BAD  gateway.auth.mode is "none": no token on the gateway
   BAD  the gateway answers on your network address 192.168.0.113:18999

2. Heartbeat (idle cost)
  info  heartbeat every 15m: about 96 full agent turns a day, even when you do nothing
  warn  isolatedSession/lightContext not both on: up to ~288M input tokens a month while idle

3. Installed skills
  info  4 skill folder(s) found
   BAD  clawhubb: name matches a skill reported as malicious (ClawHavoc)
   BAD  yt-helper: SKILL.md contains: address 91.92.242.30 (reported ClawHavoc server);
        downloads a script and runs it in a shell
    ok  2 skill(s) with no reported name and none of the known patterns

Result: 4 serious, 2 to look at.
Honest limits

What it can't tell you.

It isn't the full list. Koi Security found 341 malicious skills out of 2,857 on ClawHub; the script checks the example names published in the report plus the delivery tricks it describes. A clean result means none of those, not "safe". Only install skills whose SKILL.md you've read.

It can't see your router. It tests your gateway from your own machine. If you've forwarded the port, it's on the internet whatever this says.

It never scans anyone else. The only connections it makes are to your own computer's addresses.

Sources, checked 3 Oct 2026: OpenClaw gateway config (bind defaults to loopback; non-loopback binds require auth; port 18789) · OpenClaw heartbeat (every 30m by default; ~100K tokens per run with full history vs ~2-5K isolated) · OpenClaw skill locations · The Hacker News, 2 Feb 2026 (Koi Security: 341 malicious skills, example names, 91.92.242.30, glot.io, webhook.site).

Why we made this

An agent that doesn't need checking.

Hearth is a private AI agent that runs on a small model on your own computer. Its web panel only listens on your machine, it has no heartbeat bill, and every risky command waits for your yes. See Hearth, or price your heartbeat, or see how small local models score.