Cathryn Open-Sources Ops Toolkit for Keeping OpenClaw Running
Cathryn releases openclaw-ops, a set of open-source scripts that repair gateway issues, watch and restart the gateway, check configuration health, scan for security gaps, and audit third-party ClawHub skills.
Original post · 1 min read
tired of babysitting your OpenClaw?
I just open-sourced my ops layer. It fixes the gateway, exec approvals, broken crons, stuck sessions, channel issues, and security gaps.
• heal.sh — one-shot fix for the most common gateway issues (auth, exec approvals, crons, stuck sessions)
• watchdog.sh — runs every 5 min, restarts gateway if down, escalates after 3 failures
• watchdog-install.sh — installs the watchdog as a macOS LaunchAgent so it survives reboots
• check-update.sh — detects version changes, explains what config broke and why; --fix to auto-apply
• health-check.sh — declarative URL/process checks for gateway-adjacent services and workers
• security-scan.sh — config hardening score (0–100), drift detection, credential scan
• skill-audit.sh — static audit for third-party ClawHub skills before you install them
basically everything I built for myself since January to stop me from tearing my hair out 💀
link below 🫶
Cathryn @cathrynlavery🦞 Openclaw update fix
If your agents are hitting exec approval walls after the latest update, the fix is three settings:
In exec-approvals.json defaults:
- security: "full"
- ask: "off"
- askFallback: "full"
In openclaw.json:
- tools.exec.security: "full"
- tools.exec.strictInlineEval: "false"
Then restart gateway.
The allowlist wildcard * alone isn't enough. There's a second policy layer that gates complex commands independently.