You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
焦糖布丁(Caramel Pudding)是一款专用于的OpenClaw AI Gateway安全基线和漏洞检测工具,致力于为OpenClaw生态系统提供全面的安全保障。它采用多维度检测策略,深入分析OpenClaw的各个安全层面,帮助用户快速识别并修复潜在的安全风险。 Caramel Pudding is a professional security baseline scanning tool for OpenClaw AI Gateway, dedicated to providing comprehensive security assurance for the OpenClaw ecosystem. It employs a multi-dimensional detection strategy to deeply analyze various security aspects of OpenClaw, helping users quickly identify and fix potential security risks.
该工具集成了12大核心检测模块,包括配置安全、技能包安全、端口暴露、认证口令、依赖供应链、主机安全、密钥泄露、反代配置、运行时检查、漏洞扫描、安全基线检查和数据泄露防护,覆盖了OpenClaw部署的各个安全维度。通过直观的图形界面和详细的修复建议,焦糖布丁使安全审计变得简单高效,即使是非专业安全人员也能轻松操作。 The tool integrates 12 core detection modules, including configuration security, skills security, port exposure, authentication, dependency supply chain, host security, secrets leakage, proxy configuration, runtime checks, vulnerability scanning, security baseline checking, and data loss prevention, covering all security dimensions of OpenClaw deployment. With its intuitive graphical interface and detailed fix suggestions, Caramel Pudding makes security auditing simple and efficient, even for non-professional security personnel.
焦糖布丁提供全面的安全检测,支持一键自动修复功能,帮助用户快速解决安全问题。同时,它生成美观的插画风格HTML报告,详细展示检测结果和修复建议,方便用户进行安全评估和审计。 Caramel Pudding provides comprehensive security detection and supports one-click automatic repair functionality to help users quickly resolve security issues. Additionally, it generates beautiful illustration-style HTML reports that detail scan results and fix suggestions, facilitating security assessment and auditing.
Beautiful and easy to read, suitable for manual review
JSON Report
Structured scan result data
Suitable for automated processing and integration
The HTML report uses an illustration style design, including complete scan results and fix suggestions, making it easy to quickly understand the system security status.
Lobster Security Guard Feature Reports
For Lobster Security Guard features, you can export separate HTML reports including:
Security audit report
Auto hardening report
Skill scanning report
File integrity check report
Privacy check report
Behavior detection check report
Fix Functionality
For detected security issues, you can:
Select the risk items to fix in the results table (multi-select supported)
Click the "修复选中风险" (Fix Selected Risks) button
View the fix operation details in the pop-up dialog
Click "执行修复" (Execute Fix) to perform the fix
After fixing, the tool will automatically rescan to update the results
Fix Operation Notes:
For low and medium risk issues, the tool will attempt to fix them automatically
For high and critical risk issues, the tool will provide fix suggestions that require manual confirmation
AI-Assisted Audit (Local and cloud models integration planned for future)
焦糖布丁 provides AI-assisted audit functionality to perform deeper analysis of scan results:
Click the "AI 深度审计" (AI Deep Audit) button in the interface
The tool will generate an AI prompt template from the scan results and send it to AI for detailed analysis
AI will provide more detailed security suggestions and fix solutions
You can follow AI's suggestions for further security hardening
Disclaimer
The tool's fix solutions and content are for reference only. The author is not responsible for any direct or indirect consequences and losses caused by the dissemination or use of the information provided by this tool. The user assumes full responsibility.
Built for the OpenClaw AI Gateway ecosystem · Designed with security-first principles
About
焦糖布丁(Caramel Pudding)是一款专为 OpenClaw AI Gateway 打造的安全基线与漏洞检测工具,集成 12 大核心检测模块(配置安全、技能包安全、端口暴露、认证口令、供应链、主机安全、密钥泄露、反代配置、运行时检查、漏洞扫描、安全基线、数据泄露防护)与龙虾安全守卫功能(安全审计、自动加固、技能扫描、文件完整性、隐私检查、行为检测),支持 Ollama 本地模型与云端大模型双模式 AI 深度审计,提供一键自动修复与量化风险评分,生成插画风格 HTML 报告,适用于 AI 网关安全评估、合规审计与 CI/CD 集成。