---
name: startup-checker
description: "Security configuration audit at gateway startup"
metadata: { "openclaw": { "emoji": "🏥", "events": ["gateway:startup"] } }
---
# Startup Checker

Runs a comprehensive security configuration audit when the OpenClaw gateway starts, scoring your deployment against best practices.

## Checks Performed

| Check | Config Path | Pass Condition | Severity |
|-------|------------|---------------|----------|
| Auth mode | `gateway.auth.mode` | Not `none` | FAIL |
| Auth credential | `gateway.auth.token` / `.password` | Present when required | FAIL |
| Network binding | `gateway.bind` | Not `lan` or `custom` | WARN |
| Sandbox | `agents.defaults.sandbox.mode` | Enabled | WARN |
| Rate limiting | `gateway.auth.rateLimit.maxAttempts` | Configured | WARN |
| Internal hooks | `hooks.internal.enabled` | Enabled | WARN |
| Exec approval | `approvals.exec.enabled` | Enabled | WARN |

## Scoring

- **100** — All checks pass
- **≥80** — Minor warnings, generally secure
- **<60** — Critical issues requiring immediate attention

## Output

On startup, a formatted security report is pushed as a message to the session.
