One short Python script. It reads your own OpenClaw config and installed skills, then tells you if the gateway can be reached from your network, what the heartbeat costs you while idle, and whether any skill matches ones publicly reported as malicious. It changes nothing and sends nothing anywhere.
Reads gateway.bind and the auth mode, then tests whether the gateway port answers on your own network address, from your own machine.
Shows how many full agent turns run a day while you do nothing, and whether isolatedSession and lightContext are on.
Flags skill names from the reported ClawHavoc list and SKILL.md files that pipe downloads into a shell or point at the reported server.
Download it (246 lines, Python 3.8+, nothing to install) and read it first. It's meant to be read.
curl -O https://jzzystudios.com/hearth/check/openclaw-check.pyCheck it's the file we published. The SHA-256 should be:
4ebd722ae05622defd939c2cc416b30ca710b5e655203eed79fda69b6acf5de6Run it as your normal user, on the machine where OpenClaw runs. Set OPENCLAW_CONFIG_PATH first if your config isn't at ~/.openclaw/openclaw.json.
python3 openclaw-check.pyReal output (a few long lines shortened) from a test machine we set up to fail: gateway on the LAN with auth off, a 15-minute heartbeat, a skill named like a reported typosquat, and a skill whose "prerequisites" pipe a download from the reported server into a shell.
$ python3 openclaw-check.py OpenClaw self-check 1.0 (3 Oct 2026): read-only, this computer only 1. Gateway exposure warn gateway.bind is "lan": other devices can reach the gateway. BAD gateway.auth.mode is "none": no token on the gateway BAD the gateway answers on your network address 192.168.0.113:18999 2. Heartbeat (idle cost) info heartbeat every 15m: about 96 full agent turns a day, even when you do nothing warn isolatedSession/lightContext not both on: up to ~288M input tokens a month while idle 3. Installed skills info 4 skill folder(s) found BAD clawhubb: name matches a skill reported as malicious (ClawHavoc) BAD yt-helper: SKILL.md contains: address 91.92.242.30 (reported ClawHavoc server); downloads a script and runs it in a shell ok 2 skill(s) with no reported name and none of the known patterns Result: 4 serious, 2 to look at.
It isn't the full list. Koi Security found 341 malicious skills out of 2,857 on ClawHub; the script checks the example names published in the report plus the delivery tricks it describes. A clean result means none of those, not "safe". Only install skills whose SKILL.md you've read.
It can't see your router. It tests your gateway from your own machine. If you've forwarded the port, it's on the internet whatever this says.
It never scans anyone else. The only connections it makes are to your own computer's addresses.
Sources, checked 3 Oct 2026: OpenClaw gateway config (bind defaults to loopback; non-loopback binds require auth; port 18789) · OpenClaw heartbeat (every 30m by default; ~100K tokens per run with full history vs ~2-5K isolated) · OpenClaw skill locations · The Hacker News, 2 Feb 2026 (Koi Security: 341 malicious skills, example names, 91.92.242.30, glot.io, webhook.site).
Hearth is a private AI agent that runs on a small model on your own computer. Its web panel only listens on your machine, it has no heartbeat bill, and every risky command waits for your yes. See Hearth, or price your heartbeat, or see how small local models score.