PromptsOpenClaw

Specific purposeNightly at 3:30am · your repo

Nightly security review of this codebase

Use case

A local assistant that can read your mail is only as safe as the code around it. At 3:30am, when the other heavy jobs are quiet, OpenClaw reads the repo and sends a numbered list of weaknesses. You ask for a number when you want the evidence, and you say fix it when you want the change.

What to connect

The OpenClaw workspace repo, Telegram, and optionally the Cursor agent CLI if you want the read to happen there. The summary still comes back through OpenClaw.

Setup

  1. Set REPO PATH to the workspace this assistant is allowed to read.
  2. Schedule the run at 3:30am local time so it does not overlap the business council.
  3. If Cursor's agent CLI is installed and authenticated, set USE_CURSOR to yes. Otherwise the review stays inside OpenClaw.
  4. Send the report to the [SECURITY] Telegram topic.
  5. Run it once by hand and confirm the findings name files, and that none of them include a payload or a step-by-step attack.

Edit before you send: The repo path, whether Cursor's agent CLI is used, the clock time, and the Telegram topic.

Prompt to paste into OpenClaw

Save this as a skill named security-council. Run every night at [3:30] [TIMEZONE]. Read the codebase at [REPO PATH]. Read recent commits and error logs too. Use the model to read the code. A pattern list is not a substitute for reading. If [USE CURSOR] is yes, you may hand the read to the Cursor agent CLI and then summarize what comes back. If it is not, do the read yourself. Look at this repo from four angles: - Attack surface: what a hostile input could reach. - Protections: whether the checks you already have cover that path. - Sensitive data: whether keys, tokens, mail, or financial notes are handled in a way I would accept. - Practicality: whether a control would hold up on a real day, or only looks strict on paper. Send a numbered report to the [SECURITY] Telegram topic. Each item: what is wrong, why it matters, the file, and the fix. Describe the weakness. Do not include payloads, exploit steps, or proof-of-concept code. If a finding is severe enough that waiting until morning is a bad idea, send that one item as soon as you have it, in the same shape, and still include it in the full report. If I ask for a number, give the evidence: the file, the function, and the fix. If I say fix it, change only that item and show me the diff. If the repo looks fine, say so in one line. Do not manufacture findings.

More OpenClaw prompts

  • Personal CRM from mail and calendar

    A year of email and meetings is a pile of names you cannot search. OpenClaw reads Gmail and Google Calendar, drops newsletters and cold pitches, and keeps a local profile for each person worth remembering. You ask in plain language who you know at a company, or who has gone quiet.

  • Meeting action items with an approval queue

    Meetings end and the promises disappear. OpenClaw waits until a meeting is over, pulls the Fathom transcript, matches the room to your CRM, and sends you each action item to approve. Approved items become Todoist tasks. Things other people owe you stay on a waiting-on list, except people on your own team.

  • Urgent email, only when it can wait no longer

    You do not live in the inbox, including on weekends. OpenClaw checks mail on a timer, ignores senders you have already marked as noise, and pings a Telegram topic only when something needs you now. When you say an alert was wrong, the next check is stricter.

  • Knowledge base you fill from a Telegram topic

    Links you meant to remember are scattered across chats. You drop a URL into one Telegram topic. OpenClaw saves the article, the video transcript, the full post thread, or the PDF, then you ask later in plain language. A new save can point at something you already kept.