Is your AI agentleaking secrets?
See CRABB in action
Watch a real scan find security issues. Your results are private — nothing leaves your machine.
4 security modules, one score
CRABB checks the most important security areas of your OpenClaw setup.
Credentials
Finds exposed API keys, tokens, and secrets in your config files and logs.
Skills
Scans skills for dangerous patterns like remote code execution or data theft.
Permissions
Checks if your sandbox mode, DM policies, and allowlists are configured safely.
Network
Verifies your gateway isn't exposed and authentication is properly set up.
Three steps to peace of mind
Run the scan▶️
Just run npx getcrabb in your terminal. It automatically finds your OpenClaw installation and checks everything locally.
Get your score📊
You'll see a score from 0-100 with a letter grade (A-F). Higher is better! We'll show you exactly what needs fixing.
Share (optional)🔗
Proud of your score? Use --share to get a link you can post on social media. Only aggregate data is sent — never your actual secrets.
Understand your grade
Your score translates to a letter grade that tells you how secure your setup is.
Common questions
Is this safe to run?+
--share flag, and even then it only sends your score and counts — never actual secrets or file paths.What's OpenClaw?+
Is CRABB open source?+
How is this different from OpenClaw's built-in audit?+
security audit command, but CRABB gives you a unified 0-100 score, deeper credential scanning, shareable score cards for social proof, and works without having OpenClaw CLI installed.Ready to check your security?
One command. No signup. No data sent.